<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2013-05-24" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="High" seq="2012-0001" published="2012-01-10" name="CVE-2012-0001" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly load structured exception handling tables, which allows context-dependent attackers to bypass the SafeSEH security feature by leveraging a Visual C++ .NET 2003 application, aka "Windows Kernel SafeSEH Bypass Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-010A.html" source="CERT">TA12-010A</ref>
      <ref url="http://www.securitytracker.com/id?1026493" source="SECTRACK">1026493</ref>
      <ref url="http://www.securityfocus.com/bid/51296" source="BID">51296</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-001" source="MS" adv="1">MS12-001</ref>
      <ref url="http://secunia.com/advisories/47356" source="SECUNIA">47356</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14758" source="OVAL">oval:org.mitre.oval:def:14758</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00016.html" source="SUSE">openSUSE-SU-2012:0917</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp1:x32"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:professional_x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0002" published="2012-03-13" name="CVE-2012-0002" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."</descript>
      <descript source="nvd">Per: http://technet.microsoft.com/en-us/security/bulletin/ms12-020

"By default, the Remote Desktop Protocol is not enabled on any Windows operating system. Systems that do not have RDP enabled are not at risk. Note that on Windows XP and Windows Server 2003, Remote Assistance can enable RDP."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-073A.html" source="CERT">TA12-073A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-020" source="MS" patch="1" adv="1">MS12-020</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14623" source="OVAL">oval:org.mitre.oval:def:14623</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x86"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0003" published="2012-01-10" name="CVE-2012-0003" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-010A.html" source="CERT">TA12-010A</ref>
      <ref url="http://www.securitytracker.com/id?1026492" source="SECTRACK">1026492</ref>
      <ref url="http://www.securityfocus.com/bid/51292" source="BID">51292</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-004" source="MS">MS12-004</ref>
      <ref url="http://secunia.com/advisories/47485" source="SECUNIA">47485</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14337" source="OVAL">oval:org.mitre.oval:def:14337</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp1:x32"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:professional_x64"/>
        <vers num="" edition="sp3"/>
        <vers num="2005" edition="sp3"/>
        <vers num="2005" edition="sp3:media_center"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0004" published="2012-01-10" name="CVE-2012-0004" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, related to Quartz.dll, Qdvd.dll, closed captioning, and the Line21 DirectShow filter, aka "DirectShow Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-010A.html" source="CERT">TA12-010A</ref>
      <ref url="http://www.securitytracker.com/id?1026492" source="SECTRACK">1026492</ref>
      <ref url="http://www.securityfocus.com/bid/51295" source="BID">51295</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-004" source="MS" adv="1">MS12-004</ref>
      <ref url="http://secunia.com/advisories/47485" source="SECUNIA">47485</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14832" source="OVAL">oval:org.mitre.oval:def:14832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp1:x32"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
        <vers num="2005" edition="sp3"/>
        <vers num="2005" edition="sp3:media_center"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0005" published="2012-01-10" name="CVE-2012-0005" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean system locale is used, can access uninitialized memory during the processing of Unicode characters, which allows local users to gain privileges via a crafted application, aka "CSRSS Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-010A.html" source="CERT">TA12-010A</ref>
      <ref url="http://www.securitytracker.com/id?1026495" source="SECTRACK">1026495</ref>
      <ref url="http://www.securityfocus.com/bid/51270" source="BID">51270</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-003" source="MS" adv="1">MS12-003</ref>
      <ref url="http://secunia.com/advisories/47479" source="SECUNIA">47479</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14879" source="OVAL">oval:org.mitre.oval:def:14879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:professional_x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0006" published="2012-03-13" name="CVE-2012-0006" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-073A.html" source="CERT">TA12-073A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-017" source="MS" patch="1" adv="1">MS12-017</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15098" source="OVAL">oval:org.mitre.oval:def:15098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0007" published="2012-01-10" name="CVE-2012-0007" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML input, aka "AntiXSS Library Bypass Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-010A.html" source="CERT">TA12-010A</ref>
      <ref url="http://www.securitytracker.com/id?1026499" source="SECTRACK">1026499</ref>
      <ref url="http://www.securityfocus.com/bid/51291" source="BID">51291</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-007" source="MS" adv="1">MS12-007</ref>
      <ref url="http://secunia.com/advisories/47516" source="SECUNIA">47516</ref>
      <ref url="http://secunia.com/advisories/47483" source="SECUNIA">47483</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14314" source="OVAL">oval:org.mitre.oval:def:14314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="anti-cross_site_scripting_library">
        <vers num="3.1"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0008" published="2012-03-13" name="CVE-2012-0008" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1 allows local users to gain privileges via a Trojan horse add-in in an unspecified directory, aka "Visual Studio Add-In Vulnerability."</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426: Untrusted Search Path'
</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://technet.microsoft.com/en-us/security/bulletin/ms12-021

'An attacker could then place a specially crafted add-in in the path used by Visual Studio. When Visual Studio is started by an administrator, the specially crafted add-in would be loaded with the same privileges as the administrator.'

'The vulnerability could not be exploited remotely or by anonymous users.'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-073A.html" source="CERT">TA12-073A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-021" source="MS" patch="1" adv="1">MS12-021</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15081" source="OVAL">oval:org.mitre.oval:def:15081</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_studio">
        <vers num="2008" edition="sp1"/>
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0009" published="2012-01-10" name="CVE-2012-0009" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the Windows Object Packager configuration in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse executable file in the current working directory, as demonstrated by a directory that contains a file with an embedded packaged object, aka "Object Packager Insecure Executable Launching Vulnerability."</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://technet.microsoft.com/en-us/security/bulletin/ms12-002

'The vulnerability could allow remote code execution if a user opens a legitimate file with an embedded packaged object that is located in the same network directory as a specially crafted executable file.'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-010A.html" source="CERT">TA12-010A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-002" source="MS" patch="1" adv="1">MS12-002</ref>
      <ref url="http://www.securitytracker.com/id?1026494" source="SECTRACK">1026494</ref>
      <ref url="http://www.securityfocus.com/bid/51297" source="BID">51297</ref>
      <ref url="http://secunia.com/advisories/45189" source="SECUNIA">45189</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14393" source="OVAL">oval:org.mitre.oval:def:14393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:professional_x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0010" published="2012-02-14" name="CVE-2012-0010" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 9 does not properly perform copy-and-paste operations, which allows user-assisted remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Copy and Paste Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-010" source="MS" patch="1" adv="1">MS12-010</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14835" source="OVAL">oval:org.mitre.oval:def:14835</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0011" published="2012-02-14" name="CVE-2012-0011" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "HTML Layout Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-010" source="MS" patch="1" adv="1">MS12-010</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14310" source="OVAL">oval:org.mitre.oval:def:14310</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0012" published="2012-02-14" name="CVE-2012-0012" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string objects, which allows remote attackers to read data from arbitrary process-memory locations via a crafted web site, aka "Null Byte Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-010" source="MS" patch="1" adv="1">MS12-010</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14870" source="OVAL">oval:org.mitre.oval:def:14870</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0013" published="2012-01-10" name="CVE-2012-0013" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-010A.html" source="CERT">TA12-010A</ref>
      <ref url="http://www.securitytracker.com/id?1026497" source="SECTRACK">1026497</ref>
      <ref url="http://www.securityfocus.com/bid/51284" source="BID">51284</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-005" source="MS" adv="1">MS12-005</ref>
      <ref url="http://secunia.com/advisories/47480" source="SECUNIA">47480</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14197" source="OVAL">oval:org.mitre.oval:def:14197</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp1:x32"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:professional_x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0014" published="2012-02-14" name="CVE-2012-0014" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-016" source="MS" patch="1" adv="1">MS12-016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13972" source="OVAL">oval:org.mitre.oval:def:13972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="2.0" edition="sp2"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
      </prod>
      <prod vendor="microsoft" name="silverlight">
        <vers num="4.0.50524.00"/>
        <vers num="4.0.50826.0"/>
        <vers num="4.0.50917.0"/>
        <vers num="4.0.51204.0"/>
        <vers num="4.0.60129.0"/>
        <vers num="4.0.60310.0"/>
        <vers num="4.0.603310.0"/>
        <vers num="4.0.60531.0"/>
        <vers num="4.0.60831.0"/>
        <vers num="4.1.10111"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0015" published="2012-02-14" name="CVE-2012-0015" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Heap Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-016" source="MS" patch="1" adv="1">MS12-016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14513" source="OVAL">oval:org.mitre.oval:def:14513</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="2.0" edition="sp2"/>
        <vers num="3.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0016" published="2012-03-13" name="CVE-2012-0016" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .xpr or .DESIGN file, aka "Expression Design Insecure Library Loading Vulnerability."</descript>
      <descript source="nvd">Per:  http://cwe.mitre.org/data/definitions/426.html

'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://technet.microsoft.com/en-us/security/bulletin/ms12-022

'This is a remote code execution vulnerability.'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-073A.html" source="CERT">TA12-073A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-022" source="MS" patch="1" adv="1">MS12-022</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14973" source="OVAL">oval:org.mitre.oval:def:14973</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="expression_design">
        <vers num="-" edition="sp1"/>
        <vers num="2"/>
        <vers num="3"/>
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0017" published="2012-02-14" name="CVE-2012-0017" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-011" source="MS" patch="1" adv="1">MS12-011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14637" source="OVAL">oval:org.mitre.oval:def:14637</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_foundation">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0018" published="2012-05-08" name="CVE-2012-0018" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "VSD File Format Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securitytracker.com/id?1027042" source="SECTRACK">1027042</ref>
      <ref url="http://www.securityfocus.com/bid/53328" source="BID">53328</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-031" source="MS" adv="1">MS12-031</ref>
      <ref url="http://secunia.com/advisories/49113" source="SECUNIA">49113</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15606" source="OVAL">oval:org.mitre.oval:def:15606</ref>
      <ref url="http://osvdb.org/81731" source="OSVDB">81731</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio_viewer">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0019" published="2012-02-14" name="CVE-2012-0019" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0020, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-015" source="MS" patch="1" adv="1">MS12-015</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14347" source="OVAL">oval:org.mitre.oval:def:14347</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio_viewer">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0020" published="2012-02-14" name="CVE-2012-0020" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-015" source="MS" patch="1" adv="1">MS12-015</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14965" source="OVAL">oval:org.mitre.oval:def:14965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio_viewer">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0021" published="2012-01-27" name="CVE-2012-0021" modified="2012-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://issues.apache.org/bugzilla/show_bug.cgi?id=52256" source="CONFIRM" patch="1">https://issues.apache.org/bugzilla/show_bug.cgi?id=52256</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1227292" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1227292</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=785065" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=785065</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html</ref>
      <ref url="http://support.apple.com/kb/HT5501" source="CONFIRM">http://support.apple.com/kb/HT5501</ref>
      <ref url="http://secunia.com/advisories/48551" source="SECUNIA">48551</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html" source="APPLE">APPLE-SA-2012-09-19-2</ref>
      <ref url="http://httpd.apache.org/security/vulnerabilities_22.html" source="CONFIRM" adv="1">http://httpd.apache.org/security/vulnerabilities_22.html</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041" source="HP">SSRT100877</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041" source="HP">HPSBMU02786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.2.17"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0022" published="2012-01-18" name="CVE-2012-0022" modified="2013-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72425" source="XF">apache-tomcat-parameter-dos(72425)</ref>
      <ref url="http://www.securityfocus.com/bid/51447" source="BID">51447</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2401" source="DEBIAN">DSA-2401</ref>
      <ref url="http://tomcat.apache.org/security-7.html" source="CONFIRM" adv="1">http://tomcat.apache.org/security-7.html</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM" adv="1">http://tomcat.apache.org/security-6.html</ref>
      <ref url="http://tomcat.apache.org/security-5.html" source="CONFIRM" adv="1">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://secunia.com/advisories/50863" source="SECUNIA">50863</ref>
      <ref url="http://secunia.com/advisories/48791" source="SECUNIA">48791</ref>
      <ref url="http://secunia.com/advisories/48790" source="SECUNIA">48790</ref>
      <ref url="http://secunia.com/advisories/48213" source="SECUNIA">48213</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1331.html" source="REDHAT">RHSA-2012:1331</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0345.html" source="REDHAT">RHSA-2012:0345</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=132871655717248&amp;w=2" source="HP">HPSBUX02741</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-01/0112.html" source="BUGTRAQ">20120117 [SECURITY] CVE-2012-0022 Apache Tomcat Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers num="5.5.28"/>
        <vers num="5.5.29"/>
        <vers num="5.5.3"/>
        <vers num="5.5.30"/>
        <vers num="5.5.31"/>
        <vers num="5.5.32"/>
        <vers num="5.5.33"/>
        <vers num="5.5.34"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.10"/>
        <vers num="6.0.11"/>
        <vers num="6.0.12"/>
        <vers num="6.0.13"/>
        <vers num="6.0.14"/>
        <vers num="6.0.15"/>
        <vers num="6.0.16"/>
        <vers num="6.0.17"/>
        <vers num="6.0.18"/>
        <vers num="6.0.19"/>
        <vers num="6.0.2"/>
        <vers num="6.0.20"/>
        <vers num="6.0.24"/>
        <vers num="6.0.26"/>
        <vers num="6.0.27"/>
        <vers num="6.0.28"/>
        <vers num="6.0.29"/>
        <vers num="6.0.3"/>
        <vers num="6.0.30"/>
        <vers num="6.0.31"/>
        <vers num="6.0.32"/>
        <vers num="6.0.33"/>
        <vers num="6.0.4"/>
        <vers num="6.0.5"/>
        <vers num="6.0.6"/>
        <vers num="6.0.7"/>
        <vers num="6.0.8"/>
        <vers num="6.0.9"/>
        <vers num="7.0.0" edition="beta"/>
        <vers num="7.0.1"/>
        <vers num="7.0.10"/>
        <vers num="7.0.11"/>
        <vers num="7.0.12"/>
        <vers num="7.0.13"/>
        <vers num="7.0.14"/>
        <vers num="7.0.15"/>
        <vers num="7.0.16"/>
        <vers num="7.0.17"/>
        <vers num="7.0.18"/>
        <vers num="7.0.19"/>
        <vers num="7.0.2"/>
        <vers num="7.0.20"/>
        <vers num="7.0.21"/>
        <vers num="7.0.22"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8"/>
        <vers num="7.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0023" published="2012-10-30" name="CVE-2012-0023" modified="2012-11-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TiVo (TY) file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.videolan.org/security/sa1108.html" source="CONFIRM" patch="1" adv="1">http://www.videolan.org/security/sa1108.html</ref>
      <ref url="http://git.videolan.org/?p=vlc.git;a=commit;h=7d282fac1cc455b5a5eca2bb56375efcbf879b06" source="CONFIRM" patch="1">http://git.videolan.org/?p=vlc.git;a=commit;h=7d282fac1cc455b5a5eca2bb56375efcbf879b06</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/71916" source="XF">vlcmediaplayer-getchunkheader-code-exec(71916)</ref>
      <ref url="http://www.osvdb.org/77975" source="OSVDB">77975</ref>
      <ref url="http://securitytracker.com/id?1026449" source="SECTRACK">1026449</ref>
      <ref url="http://secunia.com/advisories/47325" source="SECUNIA" adv="1">47325</ref>
    </refs>
    <vuln_soft>
      <prod vendor="videolan" name="vlc_media_player">
        <vers num="0.9.0"/>
        <vers num="0.9.1"/>
        <vers num="0.9.10"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.8a"/>
        <vers num="0.9.9"/>
        <vers num="0.9.9a"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.10.1"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.4.1"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.6.1"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0024" published="2012-01-07" name="CVE-2012-0024" modified="2012-01-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://samiam.org/blog/20111229.html" source="CONFIRM" patch="1">http://samiam.org/blog/20111229.html</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=771428" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=771428</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/03/6" source="MLIST">[oss-security] 20120103 CVE request: maradns hash table collision cpu dos</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/03/13" source="MLIST">[oss-security] 20120103 Re: CVE request: maradns hash table collision cpu dos</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maradns" name="maradns">
        <vers num="0.0.01"/>
        <vers num="0.0.02"/>
        <vers num="0.0.03"/>
        <vers num="0.0.04"/>
        <vers num="0.0.05"/>
        <vers num="0.0.06"/>
        <vers num="0.0.07"/>
        <vers num="0.0.08"/>
        <vers num="0.1.00"/>
        <vers num="0.1.01"/>
        <vers num="0.1.02"/>
        <vers num="0.1.03"/>
        <vers num="0.1.04"/>
        <vers num="0.1.05"/>
        <vers num="0.1.06"/>
        <vers num="0.1.07"/>
        <vers num="0.1.08"/>
        <vers num="0.1.09"/>
        <vers num="0.1.10"/>
        <vers num="0.1.11"/>
        <vers num="0.1.12"/>
        <vers num="0.1.13"/>
        <vers num="0.1.14"/>
        <vers num="0.1.15"/>
        <vers num="0.1.16"/>
        <vers num="0.1.17"/>
        <vers num="0.1.18"/>
        <vers num="0.1.19"/>
        <vers num="0.1.20"/>
        <vers num="0.1.21"/>
        <vers num="0.1.22"/>
        <vers num="0.1.23"/>
        <vers num="0.1.24"/>
        <vers num="0.1.25"/>
        <vers num="0.1.26"/>
        <vers num="0.1.27"/>
        <vers num="0.1.28"/>
        <vers num="0.1.29"/>
        <vers num="0.1.30"/>
        <vers num="0.1.31"/>
        <vers num="0.1.32"/>
        <vers num="0.1.33"/>
        <vers num="0.1.34"/>
        <vers num="0.1.35"/>
        <vers num="0.1.36"/>
        <vers num="0.1.37"/>
        <vers num="0.1.38"/>
        <vers num="0.1.39"/>
        <vers num="0.1.40"/>
        <vers num="0.2.00"/>
        <vers num="0.2.01"/>
        <vers num="0.2.02"/>
        <vers num="0.2.03"/>
        <vers num="0.2.04"/>
        <vers num="0.2.05"/>
        <vers num="0.2.06"/>
        <vers num="0.2.07"/>
        <vers num="0.2.08"/>
        <vers num="0.2.09"/>
        <vers num="0.2.10"/>
        <vers num="0.3.00"/>
        <vers num="0.3.01"/>
        <vers num="0.3.02"/>
        <vers num="0.3.03"/>
        <vers num="0.3.04"/>
        <vers num="0.3.05"/>
        <vers num="0.3.06"/>
        <vers num="0.4.00"/>
        <vers num="0.4.01"/>
        <vers num="0.4.02"/>
        <vers num="0.4.03"/>
        <vers num="0.4.04"/>
        <vers num="0.5.00"/>
        <vers num="0.5.01"/>
        <vers num="0.5.02"/>
        <vers num="0.5.03"/>
        <vers num="0.5.04"/>
        <vers num="0.5.05"/>
        <vers num="0.5.06"/>
        <vers num="0.5.07"/>
        <vers num="0.5.08"/>
        <vers num="0.5.09"/>
        <vers num="0.5.10"/>
        <vers num="0.5.11"/>
        <vers num="0.5.12"/>
        <vers num="0.5.13"/>
        <vers num="0.5.14"/>
        <vers num="0.5.15"/>
        <vers num="0.5.16"/>
        <vers num="0.5.17"/>
        <vers num="0.5.18"/>
        <vers num="0.5.19"/>
        <vers num="0.5.20"/>
        <vers num="0.5.21"/>
        <vers num="0.5.22"/>
        <vers num="0.5.23"/>
        <vers num="0.5.24"/>
        <vers num="0.5.25"/>
        <vers num="0.5.26"/>
        <vers num="0.5.27"/>
        <vers num="0.5.28"/>
        <vers num="0.5.29"/>
        <vers num="0.5.30"/>
        <vers num="0.5.31"/>
        <vers num="0.5.32"/>
        <vers num="0.5.33"/>
        <vers num="0.6.00"/>
        <vers num="0.6.01"/>
        <vers num="0.6.02"/>
        <vers num="0.6.03"/>
        <vers num="0.6.04"/>
        <vers num="0.6.05"/>
        <vers num="0.6.06"/>
        <vers num="0.6.07"/>
        <vers num="0.6.08"/>
        <vers num="0.6.09"/>
        <vers num="0.6.10"/>
        <vers num="0.6.11"/>
        <vers num="0.6.12"/>
        <vers num="0.6.13"/>
        <vers num="0.6.14"/>
        <vers num="0.6.15"/>
        <vers num="0.6.16"/>
        <vers num="0.6.17"/>
        <vers num="0.6.18"/>
        <vers num="0.6.19"/>
        <vers num="0.6.20"/>
        <vers num="0.6.21"/>
        <vers num="0.7.00"/>
        <vers num="0.7.01"/>
        <vers num="0.7.02"/>
        <vers num="0.7.03"/>
        <vers num="0.7.04"/>
        <vers num="0.7.05"/>
        <vers num="0.7.06"/>
        <vers num="0.7.07"/>
        <vers num="0.7.08"/>
        <vers num="0.7.09"/>
        <vers num="0.7.10"/>
        <vers num="0.7.11"/>
        <vers num="0.7.12"/>
        <vers num="0.7.13"/>
        <vers num="0.7.14"/>
        <vers num="0.7.15"/>
        <vers num="0.7.16"/>
        <vers num="0.7.17"/>
        <vers num="0.7.18"/>
        <vers num="0.7.19"/>
        <vers num="0.7.20"/>
        <vers num="0.7.21"/>
        <vers num="0.7.22"/>
        <vers num="0.8.00"/>
        <vers num="0.8.01"/>
        <vers num="0.8.02"/>
        <vers num="0.8.03"/>
        <vers num="0.8.04"/>
        <vers num="0.8.05"/>
        <vers num="0.8.06"/>
        <vers num="0.8.07"/>
        <vers num="0.8.08"/>
        <vers num="0.8.09"/>
        <vers num="0.8.10"/>
        <vers num="0.8.11"/>
        <vers num="0.8.12"/>
        <vers num="0.8.13"/>
        <vers num="0.8.14"/>
        <vers num="0.8.15"/>
        <vers num="0.8.16"/>
        <vers num="0.8.17"/>
        <vers num="0.8.18"/>
        <vers num="0.8.19"/>
        <vers num="0.8.20"/>
        <vers num="0.8.21"/>
        <vers num="0.8.22"/>
        <vers num="0.8.23"/>
        <vers num="0.8.24"/>
        <vers num="0.8.25"/>
        <vers num="0.8.26"/>
        <vers num="0.8.27"/>
        <vers num="0.8.28"/>
        <vers num="0.8.29"/>
        <vers num="0.8.30"/>
        <vers num="0.8.31"/>
        <vers num="0.8.32"/>
        <vers num="0.8.33"/>
        <vers num="0.8.34"/>
        <vers num="0.8.35"/>
        <vers num="0.8.99"/>
        <vers num="0.8.99a"/>
        <vers num="0.9.00"/>
        <vers num="0.9.01"/>
        <vers num="0.9.02"/>
        <vers num="0.9.03"/>
        <vers num="0.9.04"/>
        <vers num="0.9.05"/>
        <vers num="0.9.06"/>
        <vers num="0.9.07"/>
        <vers num="0.9.08"/>
        <vers num="0.9.09"/>
        <vers num="0.9.10"/>
        <vers num="0.9.11"/>
        <vers num="0.9.12"/>
        <vers num="0.9.13"/>
        <vers num="0.9.14"/>
        <vers num="0.9.15"/>
        <vers num="0.9.16"/>
        <vers num="0.9.17"/>
        <vers num="0.9.18"/>
        <vers num="0.9.19"/>
        <vers num="0.9.20"/>
        <vers num="0.9.21"/>
        <vers num="0.9.22"/>
        <vers num="0.9.23"/>
        <vers num="0.9.24"/>
        <vers num="0.9.25"/>
        <vers num="0.9.26"/>
        <vers num="0.9.27"/>
        <vers num="0.9.28"/>
        <vers num="0.9.29"/>
        <vers num="0.9.30"/>
        <vers num="0.9.31"/>
        <vers num="0.9.32"/>
        <vers num="0.9.33"/>
        <vers num="0.9.34"/>
        <vers num="0.9.35"/>
        <vers num="0.9.36"/>
        <vers num="0.9.37"/>
        <vers num="0.9.38"/>
        <vers num="0.9.39"/>
        <vers num="0.9.91"/>
        <vers num="0.9.92"/>
        <vers num="1.0.00"/>
        <vers num="1.0.01"/>
        <vers num="1.0.02"/>
        <vers num="1.0.03"/>
        <vers num="1.0.04"/>
        <vers num="1.0.05"/>
        <vers num="1.0.06"/>
        <vers num="1.0.07"/>
        <vers num="1.0.08"/>
        <vers num="1.0.09"/>
        <vers num="1.0.10"/>
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
        <vers num="1.0.13"/>
        <vers num="1.0.14"/>
        <vers num="1.0.15"/>
        <vers num="1.0.16"/>
        <vers num="1.0.17"/>
        <vers num="1.0.18"/>
        <vers num="1.0.19"/>
        <vers num="1.0.20"/>
        <vers num="1.0.21"/>
        <vers num="1.0.22"/>
        <vers num="1.0.23"/>
        <vers num="1.0.24"/>
        <vers num="1.0.25"/>
        <vers num="1.0.26"/>
        <vers num="1.0.27"/>
        <vers num="1.0.28"/>
        <vers num="1.0.29"/>
        <vers num="1.0.30"/>
        <vers num="1.0.31"/>
        <vers num="1.0.32"/>
        <vers num="1.0.33"/>
        <vers num="1.0.34"/>
        <vers num="1.0.35"/>
        <vers num="1.0.36"/>
        <vers num="1.0.37"/>
        <vers num="1.0.38"/>
        <vers num="1.0.39"/>
        <vers num="1.0.40"/>
        <vers num="1.0.41"/>
        <vers num="1.1.01"/>
        <vers num="1.1.02"/>
        <vers num="1.1.04"/>
        <vers num="1.1.05"/>
        <vers num="1.1.06"/>
        <vers num="1.1.07"/>
        <vers num="1.1.08"/>
        <vers num="1.1.09"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.20"/>
        <vers num="1.1.21"/>
        <vers num="1.1.22"/>
        <vers num="1.1.23"/>
        <vers num="1.1.24"/>
        <vers num="1.1.25"/>
        <vers num="1.1.26"/>
        <vers num="1.1.27"/>
        <vers num="1.1.28"/>
        <vers num="1.1.29"/>
        <vers num="1.1.30"/>
        <vers num="1.1.31"/>
        <vers num="1.1.32"/>
        <vers num="1.1.33"/>
        <vers num="1.1.34"/>
        <vers num="1.1.35"/>
        <vers num="1.1.36"/>
        <vers num="1.1.37"/>
        <vers num="1.1.38"/>
        <vers num="1.1.39"/>
        <vers num="1.1.40"/>
        <vers num="1.1.41"/>
        <vers num="1.1.42"/>
        <vers num="1.1.43"/>
        <vers num="1.1.44"/>
        <vers num="1.1.45"/>
        <vers num="1.1.46"/>
        <vers num="1.1.47"/>
        <vers num="1.1.48"/>
        <vers num="1.1.49"/>
        <vers num="1.1.50"/>
        <vers num="1.1.51"/>
        <vers num="1.1.52"/>
        <vers num="1.1.53"/>
        <vers num="1.1.54"/>
        <vers num="1.1.55"/>
        <vers num="1.1.56"/>
        <vers num="1.1.57"/>
        <vers num="1.1.58"/>
        <vers num="1.1.59"/>
        <vers num="1.1.60"/>
        <vers num="1.1.61"/>
        <vers num="1.1.90"/>
        <vers num="1.1.91"/>
        <vers num="1.2.12.01"/>
        <vers num="1.2.12.02"/>
        <vers num="1.2.12.03"/>
        <vers num="1.2.12.04"/>
        <vers num="1.2.12.05"/>
        <vers num="1.2.12.06"/>
        <vers num="1.2.12.07"/>
        <vers num="1.2.12.08"/>
        <vers num="1.2.12.09"/>
        <vers num="1.2.12.10"/>
        <vers num="1.3.01"/>
        <vers num="1.3.02"/>
        <vers num="1.3.03"/>
        <vers num="1.3.04"/>
        <vers num="1.3.05"/>
        <vers num="1.3.06"/>
        <vers num="1.3.07"/>
        <vers num="1.3.07.01"/>
        <vers num="1.3.07.02"/>
        <vers num="1.3.07.03"/>
        <vers num="1.3.07.04"/>
        <vers num="1.3.07.05"/>
        <vers num="1.3.07.06"/>
        <vers num="1.3.07.07"/>
        <vers num="1.3.07.08"/>
        <vers num="1.3.07.09"/>
        <vers num="1.3.07.10"/>
        <vers num="1.3.08"/>
        <vers num="1.3.09"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.3.14"/>
        <vers num="1.4.01"/>
        <vers num="1.4.02"/>
        <vers num="1.4.03"/>
        <vers num="1.4.04"/>
        <vers num="1.4.05"/>
        <vers num="1.4.06"/>
        <vers num="1.4.07"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0025" published="2012-11-02" name="CVE-2012-0025" modified="2012-11-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/71892" source="XF">libfpx-freeallmemory-code-exec(71892)</ref>
      <ref url="http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=31&amp;Itemid=31" source="MISC">http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=31&amp;Itemid=31</ref>
      <ref url="http://www.osvdb.org/77958" source="OSVDB">77958</ref>
      <ref url="http://www.imagemagick.org/download/delegates/libfpx-1.3.1-1.zip" source="CONFIRM">http://www.imagemagick.org/download/delegates/libfpx-1.3.1-1.zip</ref>
      <ref url="http://www.exploit-db.com/exploits/18256" source="EXPLOIT-DB">18256</ref>
      <ref url="http://secunia.com/advisories/47322" source="SECUNIA" adv="1">47322</ref>
      <ref url="http://secunia.com/advisories/47246" source="SECUNIA" adv="1">47246</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irfanview" name="flashpix_plugin">
        <vers num="4.2.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2012-0026" reject="1" published="2012-01-04" name="CVE-2012-0026" modified="2012-01-04">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2012-0287.  Reason: This candidate is a duplicate of CVE-2012-0287.  Notes: All CVE users should reference CVE-2012-0287 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0027" published="2012-01-05" name="CVE-2012-0027" modified="2012-07-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.openssl.org/news/secadv_20120104.txt" source="CONFIRM" adv="1">http://www.openssl.org/news/secadv_20120104.txt</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2012:007" source="MANDRIVA">MDVSA-2012:007</ref>
      <ref url="http://osvdb.org/78191" source="OSVDB">78191</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00017.html" source="SUSE">openSUSE-SU-2012:0083</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041" source="HP">SSRT100877</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041" source="HP">HPSBMU02786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.1c"/>
        <vers num="0.9.2b"/>
        <vers num="0.9.3"/>
        <vers num="0.9.3a"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.5a"/>
        <vers num="0.9.6"/>
        <vers num="0.9.6a"/>
        <vers num="0.9.6b"/>
        <vers num="0.9.6c"/>
        <vers num="0.9.6d"/>
        <vers num="0.9.6e"/>
        <vers num="0.9.6f"/>
        <vers num="0.9.6g"/>
        <vers num="0.9.6h" edition="bogus"/>
        <vers num="0.9.6i"/>
        <vers num="0.9.6j"/>
        <vers num="0.9.6k"/>
        <vers num="0.9.6l"/>
        <vers num="0.9.6m"/>
        <vers num="0.9.7"/>
        <vers num="0.9.7a"/>
        <vers num="0.9.7b"/>
        <vers num="0.9.7c"/>
        <vers num="0.9.7d"/>
        <vers num="0.9.7e"/>
        <vers num="0.9.7f"/>
        <vers num="0.9.7g"/>
        <vers num="0.9.7h"/>
        <vers num="0.9.7i"/>
        <vers num="0.9.7j"/>
        <vers num="0.9.7k"/>
        <vers num="0.9.7l"/>
        <vers num="0.9.7m"/>
        <vers num="0.9.8"/>
        <vers num="0.9.8a"/>
        <vers num="0.9.8b"/>
        <vers num="0.9.8c"/>
        <vers num="0.9.8d"/>
        <vers num="0.9.8e"/>
        <vers num="0.9.8f"/>
        <vers num="0.9.8g"/>
        <vers num="0.9.8h"/>
        <vers num="0.9.8i"/>
        <vers num="0.9.8j"/>
        <vers num="0.9.8k"/>
        <vers num="0.9.8l"/>
        <vers num="0.9.8m"/>
        <vers num="0.9.8n"/>
        <vers num="0.9.8o"/>
        <vers num="0.9.8p"/>
        <vers num="0.9.8q"/>
        <vers num="0.9.8r"/>
        <vers num="0.9.8s"/>
        <vers num="1.0.0" edition="beta1"/>
        <vers num="1.0.0" edition="beta2"/>
        <vers num="1.0.0" edition="beta3"/>
        <vers num="1.0.0" edition="beta4"/>
        <vers num="1.0.0" edition="beta5"/>
        <vers num="1.0.0a"/>
        <vers num="1.0.0b"/>
        <vers num="1.0.0c"/>
        <vers num="1.0.0d"/>
        <vers prev="1" num="1.0.0e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0028" published="2012-06-21" name="CVE-2012-0028" modified="2012-06-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The robust futex implementation in the Linux kernel before 2.6.28 does not properly handle processes that make exec system calls, which allows local users to cause a denial of service or possibly gain privileges by writing to a memory location in a child process.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/8141c7f3e7aee618312fa1c15109e1219de784a7" source="CONFIRM" patch="1">https://github.com/torvalds/linux/commit/8141c7f3e7aee618312fa1c15109e1219de784a7</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8141c7f3e7aee618312fa1c15109e1219de784a7" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8141c7f3e7aee618312fa1c15109e1219de784a7</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=771764" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=771764</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/05/08/1" source="MLIST">[oss-security] 20120508 Re: CVE Request -- kernel: futex: clear robust_list on execve</ref>
      <ref url="http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28" source="CONFIRM">http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.27"/>
        <vers num="2.6.27.1"/>
        <vers num="2.6.27.10"/>
        <vers num="2.6.27.11"/>
        <vers num="2.6.27.12"/>
        <vers num="2.6.27.13"/>
        <vers num="2.6.27.14"/>
        <vers num="2.6.27.15"/>
        <vers num="2.6.27.16"/>
        <vers num="2.6.27.17"/>
        <vers num="2.6.27.18"/>
        <vers num="2.6.27.19"/>
        <vers num="2.6.27.2"/>
        <vers num="2.6.27.20"/>
        <vers num="2.6.27.21"/>
        <vers num="2.6.27.22"/>
        <vers num="2.6.27.23"/>
        <vers num="2.6.27.24"/>
        <vers num="2.6.27.25"/>
        <vers num="2.6.27.26"/>
        <vers num="2.6.27.27"/>
        <vers num="2.6.27.28"/>
        <vers num="2.6.27.29"/>
        <vers num="2.6.27.3"/>
        <vers num="2.6.27.30"/>
        <vers num="2.6.27.31"/>
        <vers num="2.6.27.32"/>
        <vers num="2.6.27.33"/>
        <vers num="2.6.27.34"/>
        <vers num="2.6.27.35"/>
        <vers num="2.6.27.36"/>
        <vers num="2.6.27.37"/>
        <vers num="2.6.27.38"/>
        <vers num="2.6.27.39"/>
        <vers num="2.6.27.4"/>
        <vers num="2.6.27.40"/>
        <vers num="2.6.27.41"/>
        <vers num="2.6.27.42"/>
        <vers num="2.6.27.43"/>
        <vers num="2.6.27.44"/>
        <vers num="2.6.27.45"/>
        <vers num="2.6.27.46"/>
        <vers num="2.6.27.47"/>
        <vers num="2.6.27.48"/>
        <vers num="2.6.27.49"/>
        <vers num="2.6.27.5"/>
        <vers num="2.6.27.50"/>
        <vers num="2.6.27.51"/>
        <vers num="2.6.27.52"/>
        <vers num="2.6.27.53"/>
        <vers num="2.6.27.54"/>
        <vers num="2.6.27.55"/>
        <vers num="2.6.27.56"/>
        <vers num="2.6.27.57"/>
        <vers num="2.6.27.58"/>
        <vers num="2.6.27.59"/>
        <vers num="2.6.27.6"/>
        <vers num="2.6.27.60"/>
        <vers num="2.6.27.61"/>
        <vers prev="1" num="2.6.27.62"/>
        <vers num="2.6.27.7"/>
        <vers num="2.6.27.8"/>
        <vers num="2.6.27.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0029" published="2012-01-27" name="CVE-2012-0029" modified="2013-04-18" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="7.4" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.4" CVSS_base_score="7.4">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=772075" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=772075</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/72656" source="XF">qemu-processtxdesc-bo(72656)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1339-1" source="UBUNTU">USN-1339-1</ref>
      <ref url="http://www.securityfocus.com/bid/51642" source="BID">51642</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2012-0050.html" source="REDHAT">RHSA-2012:0050</ref>
      <ref url="http://secunia.com/advisories/50913" source="SECUNIA">50913</ref>
      <ref url="http://secunia.com/advisories/48318" source="SECUNIA">48318</ref>
      <ref url="http://secunia.com/advisories/47992" source="SECUNIA">47992</ref>
      <ref url="http://secunia.com/advisories/47741" source="SECUNIA" adv="1">47741</ref>
      <ref url="http://secunia.com/advisories/47740" source="SECUNIA" adv="1">47740</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0370.html" source="REDHAT">RHSA-2012:0370</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2012-02/msg00009.html" source="SUSE">openSUSE-SU-2012:0207</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00002.html" source="SUSE">SUSE-SU-2012:1320</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081972.html" source="FEDORA">FEDORA-2012-8604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kvm_group" name="qemu-kvm">
        <vers num="0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0030" published="2012-01-13" name="CVE-2012-0030" modified="2012-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:P)" CVSS_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified project_id URI parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://lists.launchpad.net/openstack/msg06648.html" source="MLIST" patch="1">[openstack] 20120111 [OSSA 2012-001] Tenant bypass by authenticated users using OpenStack API (CVE-2012-0030)</ref>
      <ref url="https://github.com/openstack/nova/commit/3d4ffb64f1e18117240c26809788528979e3bd15#diff-0" source="CONFIRM">https://github.com/openstack/nova/commit/3d4ffb64f1e18117240c26809788528979e3bd15#diff-0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/72296" source="XF">nova-security-bypass(72296)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1326-1" source="UBUNTU">USN-1326-1</ref>
      <ref url="http://www.securityfocus.com/bid/51370" source="BID">51370</ref>
      <ref url="http://secunia.com/advisories/47543" source="SECUNIA" adv="1">47543</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openstack" name="essex">
        <vers num=""/>
      </prod>
      <prod vendor="openstack" name="nova">
        <vers num="2011.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0031" published="2012-01-18" name="CVE-2012-0031" modified="2012-10-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=773744" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=773744</ref>
      <ref url="http://www.securityfocus.com/bid/51407" source="BID">51407</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html</ref>
      <ref url="http://www.halfdog.net/Security/2011/ApacheScoreboardInvalidFreeOnShutdown/" source="MISC">http://www.halfdog.net/Security/2011/ApacheScoreboardInvalidFreeOnShutdown/</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1230065" source="CONFIRM" adv="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1230065</ref>
      <ref url="http://support.apple.com/kb/HT5501" source="CONFIRM">http://support.apple.com/kb/HT5501</ref>
      <ref url="http://secunia.com/advisories/48551" source="SECUNIA">48551</ref>
      <ref url="http://secunia.com/advisories/47410" source="SECUNIA" adv="1">47410</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0128.html" source="REDHAT">RHSA-2012:0128</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=134987041210674&amp;w=2" source="HP">HPSBOV02822</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=134987041210674&amp;w=2" source="HP">SSRT100966</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html" source="SUSE">openSUSE-SU-2012:0314</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html" source="APPLE">APPLE-SA-2012-09-19-2</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041" source="HP">SSRT100877</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041" source="HP">HPSBMU02786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="1.0"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.5"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.9"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.1.1"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.3.14"/>
        <vers num="1.3.15"/>
        <vers num="1.3.16"/>
        <vers num="1.3.17"/>
        <vers num="1.3.18"/>
        <vers num="1.3.19"/>
        <vers num="1.3.2"/>
        <vers num="1.3.20"/>
        <vers num="1.3.22"/>
        <vers num="1.3.23"/>
        <vers num="1.3.24"/>
        <vers num="1.3.25"/>
        <vers num="1.3.26"/>
        <vers num="1.3.27"/>
        <vers num="1.3.28"/>
        <vers num="1.3.29"/>
        <vers num="1.3.3"/>
        <vers num="1.3.30"/>
        <vers num="1.3.31"/>
        <vers num="1.3.32"/>
        <vers num="1.3.33"/>
        <vers num="1.3.34"/>
        <vers num="1.3.35"/>
        <vers num="1.3.36"/>
        <vers num="1.3.37"/>
        <vers num="1.3.38"/>
        <vers num="1.3.39"/>
        <vers num="1.3.4"/>
        <vers num="1.3.41"/>
        <vers num="1.3.42"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.65"/>
        <vers num="1.3.68"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.4.0"/>
        <vers num="1.99"/>
        <vers num="2.0"/>
        <vers num="2.0.28" edition="beta"/>
        <vers num="2.0.32" edition="beta"/>
        <vers num="2.0.34" edition="beta"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.40"/>
        <vers num="2.0.41"/>
        <vers num="2.0.42"/>
        <vers num="2.0.43"/>
        <vers num="2.0.44"/>
        <vers num="2.0.45"/>
        <vers num="2.0.46"/>
        <vers num="2.0.47"/>
        <vers num="2.0.48"/>
        <vers num="2.0.49"/>
        <vers num="2.0.50"/>
        <vers num="2.0.51"/>
        <vers num="2.0.52"/>
        <vers num="2.0.53"/>
        <vers num="2.0.54"/>
        <vers num="2.0.55"/>
        <vers num="2.0.56"/>
        <vers num="2.0.57"/>
        <vers num="2.0.58"/>
        <vers num="2.0.59"/>
        <vers num="2.0.60"/>
        <vers num="2.0.61"/>
        <vers num="2.0.63"/>
        <vers num="2.0.9"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.2"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15"/>
        <vers num="2.2.16"/>
        <vers num="2.2.17"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.2"/>
        <vers num="2.2.20"/>
        <vers prev="1" num="2.2.21"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.6"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0034" published="2013-02-05" name="CVE-2012-0034" modified="2013-02-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.</descript>
      <descript source="nvd">Per http://rhn.redhat.com/errata/RHSA-2013-0192.html "This JBoss Enterprise Application Platform 5.2.0 release serves as a replacement for JBoss Enterprise Application Platform 5.1.2, and includes bug fixes and enhancements." Per http://rhn.redhat.com/errata/RHSA-2013-0196.html "This JBoss Enterprise Web Platform 5.2.0 release serves as a replacement for JBoss Enterprise Web Platform 5.1.2, and includes bug fixes and enhancements." </descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://issues.jboss.org/browse/JBCACHE-1612" source="CONFIRM">https://issues.jboss.org/browse/JBCACHE-1612</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=772835" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=772835</ref>
      <ref url="http://www.securityfocus.com/bid/51392" source="BID">51392</ref>
      <ref url="http://www.osvdb.org/78259" source="OSVDB">78259</ref>
      <ref url="http://secunia.com/advisories/52054" source="SECUNIA" adv="1">52054</ref>
      <ref url="http://secunia.com/advisories/51984" source="SECUNIA" adv="1">51984</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0221.html" source="REDHAT">RHSA-2013:0221</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0197.html" source="REDHAT" adv="1">RHSA-2013:0197</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0196.html" source="REDHAT" adv="1">RHSA-2013:0196</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0195.html" source="REDHAT" adv="1">RHSA-2013:0195</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0193.html" source="REDHAT">RHSA-2013:0193</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0192.html" source="REDHAT" adv="1">RHSA-2013:0192</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0191.html" source="REDHAT">RHSA-2013:0191</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1072.html" source="REDHAT">RHSA-2012:1072</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0108.html" source="REDHAT" adv="1">RHSA-2012:0108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="jboss_enterprise_application_platform">
        <vers num="5.1.2"/>
        <vers num="5.2.0"/>
      </prod>
      <prod vendor="redhat" name="jboss_enterprise_brms_platform">
        <vers prev="1" num="5.3.0"/>
      </prod>
      <prod vendor="redhat" name="jboss_enterprise_web_platform">
        <vers num="5.1.2"/>
        <vers num="5.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0035" published="2012-01-19" nvd_name="CWE-426: Untrusted Search Path" name="CVE-2012-0035" modified="2013-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://openwall.com/lists/oss-security/2012/01/10/2" source="MLIST" patch="1">[oss-security] 20120109 CVE Request: CEDET/Emacs global-ede-mode file loading vulnerability</ref>
      <ref url="http://lists.gnu.org/archive/html/emacs-devel/2012-01/msg00387.html" source="MLIST" patch="1">[emacs-devel] 20120109 Security flaw in EDE; new release plans</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1586-1" source="UBUNTU">USN-1586-1</ref>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_id=28657612" source="MLIST">[cedet-devel] 20120111 CEDET 1.0.1 available online</ref>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_id=28649762" source="MLIST">[cedet-devel] 20120109 Security flaw in EDE</ref>
      <ref url="http://secunia.com/advisories/50801" source="SECUNIA">50801</ref>
      <ref url="http://secunia.com/advisories/47515" source="SECUNIA" adv="1">47515</ref>
      <ref url="http://secunia.com/advisories/47311" source="SECUNIA" adv="1">47311</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/10/4" source="MLIST">[oss-security] 20110109 Re: Re: CVE Request: CEDET/Emacs global-ede-mode file loading vulnerability</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-January/072288.html" source="FEDORA">FEDORA-2012-0494</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-January/072285.html" source="FEDORA">FEDORA-2012-0462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eric_m_ludlam" name="cedet">
        <vers prev="1" num="1.0" edition="beta1"/>
        <vers prev="1" num="1.0" edition="beta2"/>
        <vers prev="1" num="1.0" edition="beta3"/>
        <vers prev="1" num="1.0" edition="pre1"/>
        <vers prev="1" num="1.0" edition="pre2"/>
        <vers prev="1" num="1.0" edition="pre3"/>
        <vers prev="1" num="1.0" edition="pre4"/>
        <vers prev="1" num="1.0" edition="pre6"/>
        <vers prev="1" num="1.0" edition="pre7"/>
      </prod>
      <prod vendor="gnu" name="emacs">
        <vers num="20.0"/>
        <vers num="20.1"/>
        <vers num="20.2"/>
        <vers num="20.3"/>
        <vers num="20.4"/>
        <vers num="20.5"/>
        <vers num="20.6"/>
        <vers num="20.7"/>
        <vers num="21"/>
        <vers num="21.1"/>
        <vers num="21.2"/>
        <vers num="21.2.1"/>
        <vers num="21.3"/>
        <vers num="21.3.1"/>
        <vers num="21.4"/>
        <vers num="22.1"/>
        <vers num="22.2"/>
        <vers num="22.3"/>
        <vers num="23.1"/>
        <vers num="23.2"/>
        <vers prev="1" num="23.3"/>
        <vers num="23.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0036" published="2012-04-13" name="CVE-2012-0036" modified="2012-07-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://curl.haxx.se/curl-url-sanitize.patch" source="CONFIRM" patch="1">http://curl.haxx.se/curl-url-sanitize.patch</ref>
      <ref url="https://github.com/bagder/curl/commit/75ca568fa1c19de4c5358fed246686de8467c238" source="CONFIRM">https://github.com/bagder/curl/commit/75ca568fa1c19de4c5358fed246686de8467c238</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=773457" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=773457</ref>
      <ref url="http://support.apple.com/kb/HT5281" source="CONFIRM">http://support.apple.com/kb/HT5281</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" source="APPLE">APPLE-SA-2012-05-09-1</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041" source="HP">SSRT100877</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041" source="HP">HPSBMU02786</ref>
      <ref url="http://curl.haxx.se/docs/adv_20120124.html" source="CONFIRM" adv="1">http://curl.haxx.se/docs/adv_20120124.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="curl" name="curl">
        <vers num="7.20.0"/>
        <vers num="7.20.1"/>
        <vers num="7.21.0"/>
        <vers num="7.21.1"/>
        <vers num="7.21.2"/>
        <vers num="7.21.3"/>
        <vers num="7.21.4"/>
        <vers num="7.21.5"/>
        <vers num="7.21.6"/>
        <vers num="7.21.7"/>
        <vers num="7.22.0"/>
        <vers num="7.23.0"/>
        <vers num="7.23.1"/>
      </prod>
      <prod vendor="curl" name="libcurl">
        <vers num="7.20.0"/>
        <vers num="7.20.1"/>
        <vers num="7.21.0"/>
        <vers num="7.21.1"/>
        <vers num="7.21.2"/>
        <vers num="7.21.3"/>
        <vers num="7.21.4"/>
        <vers num="7.21.5"/>
        <vers num="7.21.6"/>
        <vers num="7.21.7"/>
        <vers num="7.22.0"/>
        <vers num="7.23.0"/>
        <vers num="7.23.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0037" published="2012-06-16" name="CVE-2012-0037" modified="2013-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://github.com/dajobe/raptor/commit/a676f235309a59d4aa78eeffd2574ae5d341fcb0" source="CONFIRM" patch="1">https://github.com/dajobe/raptor/commit/a676f235309a59d4aa78eeffd2574ae5d341fcb0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74235" source="XF">openoffice-xml-info-disclosure(74235)</ref>
      <ref url="http://www.securitytracker.com/id?1026837" source="SECTRACK">1026837</ref>
      <ref url="http://www.securityfocus.com/bid/52681" source="BID">52681</ref>
      <ref url="http://www.osvdb.org/80307" source="OSVDB">80307</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/03/27/4" source="MLIST">[oss-security] 20120427 Fwd: CVE-2012-0037: libraptor - XXE in RDF/XML File Interpretation  (Multiple office products affected)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2012:063" source="MANDRIVA">MDVSA-2012:063</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2012:062" source="MANDRIVA">MDVSA-2012:062</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2012:061" source="MANDRIVA">MDVSA-2012:061</ref>
      <ref url="http://www.libreoffice.org/advisories/CVE-2012-0037/" source="CONFIRM" adv="1">http://www.libreoffice.org/advisories/CVE-2012-0037/</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2438" source="DEBIAN">DSA-2438</ref>
      <ref url="http://vsecurity.com/resources/advisory/20120324-1/" source="MISC">http://vsecurity.com/resources/advisory/20120324-1/</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201209-05.xml" source="GENTOO">GLSA-201209-05</ref>
      <ref url="http://secunia.com/advisories/50692" source="SECUNIA">50692</ref>
      <ref url="http://secunia.com/advisories/48649" source="SECUNIA">48649</ref>
      <ref url="http://secunia.com/advisories/48542" source="SECUNIA" adv="1">48542</ref>
      <ref url="http://secunia.com/advisories/48529" source="SECUNIA" adv="1">48529</ref>
      <ref url="http://secunia.com/advisories/48526" source="SECUNIA" adv="1">48526</ref>
      <ref url="http://secunia.com/advisories/48494" source="SECUNIA">48494</ref>
      <ref url="http://secunia.com/advisories/48493" source="SECUNIA" adv="1">48493</ref>
      <ref url="http://secunia.com/advisories/48479" source="SECUNIA" adv="1">48479</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0411.html" source="REDHAT">RHSA-2012:0411</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0410.html" source="REDHAT">RHSA-2012:0410</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078242.html" source="FEDORA">FEDORA-2012-4663</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077708.html" source="FEDORA">FEDORA-2012-4629</ref>
      <ref url="http://librdf.org/raptor/RELEASE.html#rel2_0_7" source="CONFIRM">http://librdf.org/raptor/RELEASE.html#rel2_0_7</ref>
      <ref url="http://blog.documentfoundation.org/2012/03/22/tdf-announces-libreoffice-3-4-6/" source="CONFIRM">http://blog.documentfoundation.org/2012/03/22/tdf-announces-libreoffice-3-4-6/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="openoffice.org">
        <vers num="3.3"/>
        <vers num="3.4" edition="beta"/>
      </prod>
      <prod vendor="libreoffice" name="libreoffice">
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.4.0"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.5"/>
        <vers num="3.5"/>
      </prod>
      <prod vendor="redland" name="libraptor">
        <vers prev="1" num="2.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0038" published="2012-05-17" name="CVE-2012-0038" modified="2012-05-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Integer overflow in the xfs_acl_from_disk function in fs/xfs/xfs_acl.c in the Linux kernel before 3.1.9 allows local users to cause a denial of service (panic) via a filesystem with a malformed ACL, leading to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba" source="CONFIRM">https://github.com/torvalds/linux/commit/fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba</ref>
      <ref url="https://github.com/torvalds/linux/commit/093019cf1b18dd31b2c3b77acce4e000e2cbc9ce" source="CONFIRM">https://github.com/torvalds/linux/commit/093019cf1b18dd31b2c3b77acce4e000e2cbc9ce</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=773280" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=773280</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/10/11" source="MLIST">[oss-security] 20120110 Re: CVE request: kernel: xfs heap overflow</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1.9" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1.9</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=093019cf1b18dd31b2c3b77acce4e000e2cbc9ce" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=093019cf1b18dd31b2c3b77acce4e000e2cbc9ce</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="1.2.0"/>
        <vers num="1.3.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.2"/>
        <vers num="2.0.20"/>
        <vers num="2.0.21"/>
        <vers num="2.0.22"/>
        <vers num="2.0.23"/>
        <vers num="2.0.24"/>
        <vers num="2.0.25"/>
        <vers num="2.0.26"/>
        <vers num="2.0.27"/>
        <vers num="2.0.28"/>
        <vers num="2.0.29"/>
        <vers num="2.0.3"/>
        <vers num="2.0.30"/>
        <vers num="2.0.31"/>
        <vers num="2.0.32"/>
        <vers num="2.0.33"/>
        <vers num="2.0.34"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1.132"/>
        <vers num="2.1.89"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13" edition="pre15"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15" edition="pre16"/>
        <vers num="2.2.16" edition="pre5"/>
        <vers num="2.2.16" edition="pre6"/>
        <vers num="2.2.17" edition="pre14"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.2"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21" edition="pre1"/>
        <vers num="2.2.21" edition="pre2"/>
        <vers num="2.2.21" edition="pre3"/>
        <vers num="2.2.21" edition="pre4"/>
        <vers num="2.2.21" edition="rc1"/>
        <vers num="2.2.21" edition="rc2"/>
        <vers num="2.2.21" edition="rc3"/>
        <vers num="2.2.21" edition="rc4"/>
        <vers num="2.2.22" edition="rc1"/>
        <vers num="2.2.22" edition="rc2"/>
        <vers num="2.2.22" edition="rc3"/>
        <vers num="2.2.23" edition="rc1"/>
        <vers num="2.2.23" edition="rc2"/>
        <vers num="2.2.24" edition="rc2"/>
        <vers num="2.2.24" edition="rc3"/>
        <vers num="2.2.24" edition="rc4"/>
        <vers num="2.2.24" edition="rc5"/>
        <vers num="2.2.25"/>
        <vers num="2.2.26"/>
        <vers num="2.2.27" edition="pre1"/>
        <vers num="2.2.27" edition="pre2"/>
        <vers num="2.2.27" edition="rc1"/>
        <vers num="2.2.27" edition="rc2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4" edition="rc1"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.3.15"/>
        <vers num="2.3.16"/>
        <vers num="2.3.17"/>
        <vers num="2.3.18"/>
        <vers num="2.3.19"/>
        <vers num="2.3.2"/>
        <vers num="2.3.20"/>
        <vers num="2.3.21"/>
        <vers num="2.3.22"/>
        <vers num="2.3.23"/>
        <vers num="2.3.24"/>
        <vers num="2.3.25"/>
        <vers num="2.3.26"/>
        <vers num="2.3.27"/>
        <vers num="2.3.28"/>
        <vers num="2.3.29"/>
        <vers num="2.3.3"/>
        <vers num="2.3.30"/>
        <vers num="2.3.31"/>
        <vers num="2.3.32"/>
        <vers num="2.3.33"/>
        <vers num="2.3.34"/>
        <vers num="2.3.35"/>
        <vers num="2.3.36"/>
        <vers num="2.3.37"/>
        <vers num="2.3.38"/>
        <vers num="2.3.39"/>
        <vers num="2.3.4"/>
        <vers num="2.3.40"/>
        <vers num="2.3.41"/>
        <vers num="2.3.42"/>
        <vers num="2.3.43"/>
        <vers num="2.3.44"/>
        <vers num="2.3.45"/>
        <vers num="2.3.46"/>
        <vers num="2.3.47"/>
        <vers num="2.3.48"/>
        <vers num="2.3.49"/>
        <vers num="2.3.5"/>
        <vers num="2.3.50"/>
        <vers num="2.3.51"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.3.99" edition="pre1"/>
        <vers num="2.3.99" edition="pre2"/>
        <vers num="2.3.99" edition="pre3"/>
        <vers num="2.3.99" edition="pre4"/>
        <vers num="2.3.99" edition="pre5"/>
        <vers num="2.3.99" edition="pre6"/>
        <vers num="2.3.99" edition="pre7"/>
        <vers num="2.3.99" edition="pre8"/>
        <vers num="2.3.99" edition="pre9"/>
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11" edition="pre3"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.18" edition="pre9"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22" edition="pre10"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.24"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27" edition="pre1"/>
        <vers num="2.4.27" edition="pre2"/>
        <vers num="2.4.27" edition="pre3"/>
        <vers num="2.4.27" edition="pre4"/>
        <vers num="2.4.27" edition="pre5"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29" edition="rc1"/>
        <vers num="2.4.29" edition="rc2"/>
        <vers num="2.4.3" edition="pre3"/>
        <vers num="2.4.30" edition="rc2"/>
        <vers num="2.4.30" edition="rc3"/>
        <vers num="2.4.31" edition="pre1"/>
        <vers num="2.4.32" edition="pre1"/>
        <vers num="2.4.32" edition="pre2"/>
        <vers num="2.4.33" edition="pre1"/>
        <vers num="2.4.33.2"/>
        <vers num="2.4.33.3"/>
        <vers num="2.4.33.4"/>
        <vers num="2.4.33.5"/>
        <vers num="2.4.34" edition="rc3"/>
        <vers num="2.4.34.1"/>
        <vers num="2.4.34.2"/>
        <vers num="2.4.35"/>
        <vers num="2.4.35.2"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
        <vers num="2.5.14"/>
        <vers num="2.5.15"/>
        <vers num="2.5.16"/>
        <vers num="2.5.17"/>
        <vers num="2.5.18"/>
        <vers num="2.5.19"/>
        <vers num="2.5.2"/>
        <vers num="2.5.20"/>
        <vers num="2.5.21"/>
        <vers num="2.5.22"/>
        <vers num="2.5.23"/>
        <vers num="2.5.24"/>
        <vers num="2.5.25"/>
        <vers num="2.5.26"/>
        <vers num="2.5.27"/>
        <vers num="2.5.28"/>
        <vers num="2.5.29"/>
        <vers num="2.5.3"/>
        <vers num="2.5.30"/>
        <vers num="2.5.31"/>
        <vers num="2.5.32"/>
        <vers num="2.5.33"/>
        <vers num="2.5.34"/>
        <vers num="2.5.35"/>
        <vers num="2.5.36"/>
        <vers num="2.5.37"/>
        <vers num="2.5.38"/>
        <vers num="2.5.39"/>
        <vers num="2.5.4"/>
        <vers num="2.5.40"/>
        <vers num="2.5.41"/>
        <vers num="2.5.42"/>
        <vers num="2.5.43"/>
        <vers num="2.5.44"/>
        <vers num="2.5.45"/>
        <vers num="2.5.46"/>
        <vers num="2.5.47"/>
        <vers num="2.5.48"/>
        <vers num="2.5.49"/>
        <vers num="2.5.5"/>
        <vers num="2.5.50"/>
        <vers num="2.5.51"/>
        <vers num="2.5.52"/>
        <vers num="2.5.53"/>
        <vers num="2.5.54"/>
        <vers num="2.5.55"/>
        <vers num="2.5.56"/>
        <vers num="2.5.57"/>
        <vers num="2.5.58"/>
        <vers num="2.5.59"/>
        <vers num="2.5.6"/>
        <vers num="2.5.60"/>
        <vers num="2.5.61"/>
        <vers num="2.5.62"/>
        <vers num="2.5.63"/>
        <vers num="2.5.64"/>
        <vers num="2.5.65"/>
        <vers num="2.5.66"/>
        <vers num="2.5.67"/>
        <vers num="2.5.68"/>
        <vers num="2.5.69"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.1" edition="rc3"/>
        <vers num="2.6.10" edition="rc1"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.10" edition="rc3"/>
        <vers num="2.6.11" edition="rc1"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
        <vers num="2.6.11" edition="rc4"/>
        <vers num="2.6.11" edition="rc5"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.10"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.11.9"/>
        <vers num="2.6.12" edition="rc1"/>
        <vers num="2.6.12" edition="rc2"/>
        <vers num="2.6.12" edition="rc3"/>
        <vers num="2.6.12" edition="rc4"/>
        <vers num="2.6.12" edition="rc5"/>
        <vers num="2.6.12" edition="rc6"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13" edition="rc1"/>
        <vers num="2.6.13" edition="rc2"/>
        <vers num="2.6.13" edition="rc3"/>
        <vers num="2.6.13" edition="rc4"/>
        <vers num="2.6.13" edition="rc5"/>
        <vers num="2.6.13" edition="rc6"/>
        <vers num="2.6.13" edition="rc7"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.13.5"/>
        <vers num="2.6.14" edition="rc1"/>
        <vers num="2.6.14" edition="rc2"/>
        <vers num="2.6.14" edition="rc3"/>
        <vers num="2.6.14" edition="rc4"/>
        <vers num="2.6.14" edition="rc5"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.14.5"/>
        <vers num="2.6.14.6"/>
        <vers num="2.6.14.7"/>
        <vers num="2.6.15" edition="rc1"/>
        <vers num="2.6.15" edition="rc2"/>
        <vers num="2.6.15" edition="rc3"/>
        <vers num="2.6.15" edition="rc4"/>
        <vers num="2.6.15" edition="rc5"/>
        <vers num="2.6.15" edition="rc6"/>
        <vers num="2.6.15" edition="rc7"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.10"/>
        <vers num="2.6.15.11"/>
        <vers num="2.6.15.2"/>
        <vers num="2.6.15.3"/>
        <vers num="2.6.15.4"/>
        <vers num="2.6.15.5"/>
        <vers num="2.6.15.6"/>
        <vers num="2.6.15.7"/>
        <vers num="2.6.15.8"/>
        <vers num="2.6.15.9"/>
        <vers num="2.6.16" edition="rc1"/>
        <vers num="2.6.16" edition="rc2"/>
        <vers num="2.6.16" edition="rc3"/>
        <vers num="2.6.16" edition="rc4"/>
        <vers num="2.6.16" edition="rc5"/>
        <vers num="2.6.16" edition="rc6"/>
        <vers num="2.6.16" edition="rc7"/>
        <vers num="2.6.16.1"/>
        <vers num="2.6.16.10"/>
        <vers num="2.6.16.11"/>
        <vers num="2.6.16.12"/>
        <vers num="2.6.16.13"/>
        <vers num="2.6.16.14"/>
        <vers num="2.6.16.15"/>
        <vers num="2.6.16.16"/>
        <vers num="2.6.16.17"/>
        <vers num="2.6.16.18"/>
        <vers num="2.6.16.19"/>
        <vers num="2.6.16.2"/>
        <vers num="2.6.16.20"/>
        <vers num="2.6.16.21"/>
        <vers num="2.6.16.22"/>
        <vers num="2.6.16.23"/>
        <vers num="2.6.16.24"/>
        <vers num="2.6.16.25"/>
        <vers num="2.6.16.26"/>
        <vers num="2.6.16.27"/>
        <vers num="2.6.16.28"/>
        <vers num="2.6.16.29"/>
        <vers num="2.6.16.3"/>
        <vers num="2.6.16.30"/>
        <vers num="2.6.16.31"/>
        <vers num="2.6.16.32"/>
        <vers num="2.6.16.33"/>
        <vers num="2.6.16.34"/>
        <vers num="2.6.16.35"/>
        <vers num="2.6.16.36"/>
        <vers num="2.6.16.37"/>
        <vers num="2.6.16.38"/>
        <vers num="2.6.16.39"/>
        <vers num="2.6.16.4"/>
        <vers num="2.6.16.40"/>
        <vers num="2.6.16.41"/>
        <vers num="2.6.16.42"/>
        <vers num="2.6.16.43"/>
        <vers num="2.6.16.44"/>
        <vers num="2.6.16.45"/>
        <vers num="2.6.16.46"/>
        <vers num="2.6.16.47"/>
        <vers num="2.6.16.48"/>
        <vers num="2.6.16.49"/>
        <vers num="2.6.16.5"/>
        <vers num="2.6.16.50"/>
        <vers num="2.6.16.51"/>
        <vers num="2.6.16.52"/>
        <vers num="2.6.16.53"/>
        <vers num="2.6.16.54"/>
        <vers num="2.6.16.55"/>
        <vers num="2.6.16.56"/>
        <vers num="2.6.16.57"/>
        <vers num="2.6.16.58"/>
        <vers num="2.6.16.59"/>
        <vers num="2.6.16.6"/>
        <vers num="2.6.16.60"/>
        <vers num="2.6.16.61"/>
        <vers num="2.6.16.62"/>
        <vers num="2.6.16.7"/>
        <vers num="2.6.16.8"/>
        <vers num="2.6.16.9"/>
        <vers num="2.6.17" edition="rc1"/>
        <vers num="2.6.17" edition="rc2"/>
        <vers num="2.6.17" edition="rc3"/>
        <vers num="2.6.17" edition="rc4"/>
        <vers num="2.6.17" edition="rc5"/>
        <vers num="2.6.17" edition="rc6"/>
        <vers num="2.6.17.1"/>
        <vers num="2.6.17.10"/>
        <vers num="2.6.17.11"/>
        <vers num="2.6.17.12"/>
        <vers num="2.6.17.13"/>
        <vers num="2.6.17.14"/>
        <vers num="2.6.17.2"/>
        <vers num="2.6.17.3"/>
        <vers num="2.6.17.4"/>
        <vers num="2.6.17.5"/>
        <vers num="2.6.17.6"/>
        <vers num="2.6.17.7"/>
        <vers num="2.6.17.8"/>
        <vers num="2.6.17.9"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.18.1"/>
        <vers num="2.6.18.2"/>
        <vers num="2.6.18.3"/>
        <vers num="2.6.18.4"/>
        <vers num="2.6.18.5"/>
        <vers num="2.6.18.6"/>
        <vers num="2.6.18.7"/>
        <vers num="2.6.18.8"/>
        <vers num="2.6.19" edition="rc1"/>
        <vers num="2.6.19" edition="rc2"/>
        <vers num="2.6.19" edition="rc3"/>
        <vers num="2.6.19" edition="rc4"/>
        <vers num="2.6.19.1"/>
        <vers num="2.6.19.2"/>
        <vers num="2.6.19.3"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.2" edition="rc1"/>
        <vers num="2.6.2" edition="rc2"/>
        <vers num="2.6.2" edition="rc3"/>
        <vers num="2.6.20" edition="rc2"/>
        <vers num="2.6.20.1"/>
        <vers num="2.6.20.10"/>
        <vers num="2.6.20.11"/>
        <vers num="2.6.20.12"/>
        <vers num="2.6.20.13"/>
        <vers num="2.6.20.14"/>
        <vers num="2.6.20.15"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.2"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.20.3"/>
        <vers num="2.6.20.4"/>
        <vers num="2.6.20.5"/>
        <vers num="2.6.20.6"/>
        <vers num="2.6.20.7"/>
        <vers num="2.6.20.8"/>
        <vers num="2.6.20.9"/>
        <vers num="2.6.21" edition="git1"/>
        <vers num="2.6.21" edition="git2"/>
        <vers num="2.6.21" edition="git3"/>
        <vers num="2.6.21" edition="git4"/>
        <vers num="2.6.21" edition="git5"/>
        <vers num="2.6.21" edition="git6"/>
        <vers num="2.6.21" edition="git7"/>
        <vers num="2.6.21" edition="rc3"/>
        <vers num="2.6.21" edition="rc4"/>
        <vers num="2.6.21" edition="rc5"/>
        <vers num="2.6.21" edition="rc6"/>
        <vers num="2.6.21" edition="rc7"/>
        <vers num="2.6.21.1"/>
        <vers num="2.6.21.2"/>
        <vers num="2.6.21.3"/>
        <vers num="2.6.21.4"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers num="2.6.22.15"/>
        <vers num="2.6.22.16"/>
        <vers num="2.6.22.17"/>
        <vers num="2.6.22.18"/>
        <vers num="2.6.22.19"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.20"/>
        <vers num="2.6.22.3"/>
        <vers num="2.6.22.4"/>
        <vers num="2.6.22.5"/>
        <vers num="2.6.22.6"/>
        <vers num="2.6.22.7"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.27.41"/>
        <vers num="2.6.27.42"/>
        <vers num="2.6.27.43"/>
        <vers num="2.6.27.44"/>
        <vers num="2.6.27.45"/>
        <vers num="2.6.27.46"/>
        <vers num="2.6.27.47"/>
        <vers num="2.6.27.48"/>
        <vers num="2.6.27.49"/>
        <vers num="2.6.27.5"/>
        <vers num="2.6.27.50"/>
        <vers num="2.6.27.51"/>
        <vers num="2.6.27.52"/>
        <vers num="2.6.27.53"/>
        <vers num="2.6.27.54"/>
        <vers num="2.6.27.55"/>
        <vers num="2.6.27.56"/>
        <vers num="2.6.27.57"/>
        <vers num="2.6.27.58"/>
        <vers num="2.6.27.59"/>
        <vers num="2.6.27.6"/>
        <vers num="2.6.27.60"/>
        <vers num="2.6.27.61"/>
        <vers num="2.6.27.62"/>
        <vers num="2.6.27.7"/>
        <vers num="2.6.27.8"/>
        <vers num="2.6.27.9"/>
        <vers num="2.6.28"/>
        <vers num="2.6.28.1"/>
        <vers num="2.6.28.10"/>
        <vers num="2.6.28.2"/>
        <vers num="2.6.28.3"/>
        <vers num="2.6.28.4"/>
        <vers num="2.6.28.5"/>
        <vers num="2.6.28.6"/>
        <vers num="2.6.28.7"/>
        <vers num="2.6.28.8"/>
        <vers num="2.6.28.9"/>
        <vers num="2.6.29"/>
        <vers num="2.6.29.1"/>
        <vers num="2.6.29.2"/>
        <vers num="2.6.29.3"/>
        <vers num="2.6.29.4"/>
        <vers num="2.6.29.5"/>
        <vers num="2.6.29.6"/>
        <vers num="2.6.3" edition="rc1"/>
        <vers num="2.6.3" edition="rc2"/>
        <vers num="2.6.3" edition="rc3"/>
        <vers num="2.6.3" edition="rc4"/>
        <vers num="2.6.32"/>
        <vers num="2.6.32.1"/>
        <vers num="2.6.32.10"/>
        <vers num="2.6.32.11"/>
        <vers num="2.6.32.12"/>
        <vers num="2.6.32.13"/>
        <vers num="2.6.32.14"/>
        <vers num="2.6.32.15"/>
        <vers num="2.6.32.16"/>
        <vers num="2.6.32.17"/>
        <vers num="2.6.32.18"/>
        <vers num="2.6.32.2"/>
        <vers num="2.6.32.28"/>
        <vers num="2.6.32.29"/>
        <vers num="2.6.32.3"/>
        <vers num="2.6.32.30"/>
        <vers num="2.6.32.31"/>
        <vers num="2.6.32.32"/>
        <vers num="2.6.32.33"/>
        <vers num="2.6.32.34"/>
        <vers num="2.6.32.35"/>
        <vers num="2.6.32.36"/>
        <vers num="2.6.32.37"/>
        <vers num="2.6.32.38"/>
        <vers num="2.6.32.39"/>
        <vers num="2.6.32.4"/>
        <vers num="2.6.32.40"/>
        <vers num="2.6.32.41"/>
        <vers num="2.6.32.42"/>
        <vers num="2.6.32.43"/>
        <vers num="2.6.32.44"/>
        <vers num="2.6.32.45"/>
        <vers num="2.6.32.46"/>
        <vers num="2.6.32.47"/>
        <vers num="2.6.32.48"/>
        <vers num="2.6.32.49"/>
        <vers num="2.6.32.5"/>
        <vers num="2.6.32.50"/>
        <vers num="2.6.32.51"/>
        <vers num="2.6.32.52"/>
        <vers num="2.6.32.53"/>
        <vers num="2.6.32.54"/>
        <vers num="2.6.32.55"/>
        <vers num="2.6.32.56"/>
        <vers num="2.6.32.57"/>
        <vers num="2.6.32.58"/>
        <vers num="2.6.32.6"/>
        <vers num="2.6.32.7"/>
        <vers num="2.6.32.8"/>
        <vers num="2.6.32.9"/>
        <vers num="2.6.33.10"/>
        <vers num="2.6.33.11"/>
        <vers num="2.6.33.12"/>
        <vers num="2.6.33.13"/>
        <vers num="2.6.33.14"/>
        <vers num="2.6.33.15"/>
        <vers num="2.6.33.16"/>
        <vers num="2.6.33.17"/>
        <vers num="2.6.33.18"/>
        <vers num="2.6.33.19"/>
        <vers num="2.6.33.20"/>
        <vers num="2.6.33.8"/>
        <vers num="2.6.33.9"/>
        <vers num="2.6.34.1"/>
        <vers num="2.6.34.10"/>
        <vers num="2.6.34.2"/>
        <vers num="2.6.34.3"/>
        <vers num="2.6.34.8"/>
        <vers num="2.6.34.9"/>
        <vers num="2.6.35.1"/>
        <vers num="2.6.35.10"/>
        <vers num="2.6.35.11"/>
        <vers num="2.6.35.12"/>
        <vers num="2.6.35.13"/>
        <vers num="2.6.37" edition="rc1"/>
        <vers num="2.6.37" edition="rc2"/>
        <vers num="2.6.37" edition="rc3"/>
        <vers num="2.6.37" edition="rc4"/>
        <vers num="2.6.37" edition="rc5"/>
        <vers num="2.6.38" edition="rc1"/>
        <vers num="2.6.38" edition="rc2"/>
        <vers num="2.6.38" edition="rc3"/>
        <vers num="2.6.38" edition="rc4"/>
        <vers num="2.6.38" edition="rc5"/>
        <vers num="2.6.38" edition="rc6"/>
        <vers num="2.6.38" edition="rc7"/>
        <vers num="2.6.38" edition="rc8"/>
        <vers num="2.6.39" edition="rc1"/>
        <vers num="2.6.39" edition="rc2"/>
        <vers num="2.6.39" edition="rc3"/>
        <vers num="2.6.39" edition="rc4"/>
        <vers num="2.6.39" edition="rc5"/>
        <vers num="2.6.39" edition="rc6"/>
        <vers num="2.6.39" edition="rc7"/>
        <vers num="2.6.4" edition="rc1"/>
        <vers num="2.6.4" edition="rc2"/>
        <vers num="2.6.4" edition="rc3"/>
        <vers num="2.6.5" edition="rc1"/>
        <vers num="2.6.5" edition="rc2"/>
        <vers num="2.6.5" edition="rc3"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.6" edition="rc2"/>
        <vers num="2.6.6" edition="rc3"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.7" edition="rc2"/>
        <vers num="2.6.7" edition="rc3"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.8" edition="rc4"/>
        <vers num="2.6.8.1"/>
        <vers num="2.6.9" edition="rc1"/>
        <vers num="2.6.9" edition="rc2"/>
        <vers num="2.6.9" edition="rc3"/>
        <vers num="2.6.9" edition="rc4"/>
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers prev="1" num="3.1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0039" published="2012-01-14" name="CVE-2012-0039" modified="2012-02-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED ** GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.  NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=772720" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=772720</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/10/12" source="MLIST">[oss-security] 20120110 glib2 hash dos oCert-2011-003</ref>
      <ref url="http://mail.gnome.org/archives/gtk-devel-list/2003-May/msg00111.html" source="MLIST">[gtk-devel-list] 20030529 Algorimic Complexity Attack on GLIB 2.2.1</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=655044" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=655044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="glib">
        <vers num="1.1.12"/>
        <vers num="1.1.12-1"/>
        <vers num="1.1.15"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.10"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.3.14"/>
        <vers num="1.3.15"/>
        <vers num="1.3.9"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.2"/>
        <vers num="2.10.3"/>
        <vers num="2.11.0"/>
        <vers num="2.11.1"/>
        <vers num="2.11.2"/>
        <vers num="2.11.3"/>
        <vers num="2.11.4"/>
        <vers num="2.12.0"/>
        <vers num="2.12.1"/>
        <vers num="2.12.10"/>
        <vers num="2.12.11"/>
        <vers num="2.12.12"/>
        <vers num="2.12.13"/>
        <vers num="2.12.2"/>
        <vers num="2.12.3"/>
        <vers num="2.12.4"/>
        <vers num="2.12.5"/>
        <vers num="2.12.6"/>
        <vers num="2.12.7"/>
        <vers num="2.12.8"/>
        <vers num="2.12.9"/>
        <vers num="2.13.0"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.13.3"/>
        <vers num="2.13.4"/>
        <vers num="2.13.5"/>
        <vers num="2.13.6"/>
        <vers num="2.13.7"/>
        <vers num="2.14.0"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.14.5"/>
        <vers num="2.14.6"/>
        <vers num="2.15.0"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers num="2.15.3"/>
        <vers num="2.15.4"/>
        <vers num="2.15.5"/>
        <vers num="2.15.6"/>
        <vers num="2.16.0"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers num="2.16.3"/>
        <vers num="2.16.4"/>
        <vers num="2.16.5"/>
        <vers num="2.16.6"/>
        <vers num="2.17.0"/>
        <vers num="2.17.1"/>
        <vers num="2.17.2"/>
        <vers num="2.17.3"/>
        <vers num="2.17.4"/>
        <vers num="2.17.5"/>
        <vers num="2.17.6"/>
        <vers num="2.17.7"/>
        <vers num="2.18.0"/>
        <vers num="2.18.1"/>
        <vers num="2.18.2"/>
        <vers num="2.18.3"/>
        <vers num="2.18.4"/>
        <vers num="2.19.0"/>
        <vers num="2.19.1"/>
        <vers num="2.19.10"/>
        <vers num="2.19.2"/>
        <vers num="2.19.3"/>
        <vers num="2.19.4"/>
        <vers num="2.19.5"/>
        <vers num="2.19.6"/>
        <vers num="2.19.7"/>
        <vers num="2.19.8"/>
        <vers num="2.19.9"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.20.0"/>
        <vers num="2.20.1"/>
        <vers num="2.20.2"/>
        <vers num="2.20.3"/>
        <vers num="2.20.4"/>
        <vers num="2.20.5"/>
        <vers num="2.21.0"/>
        <vers num="2.21.1"/>
        <vers num="2.21.2"/>
        <vers num="2.21.3"/>
        <vers num="2.21.4"/>
        <vers num="2.21.5"/>
        <vers num="2.21.6"/>
        <vers num="2.22.0"/>
        <vers num="2.22.1"/>
        <vers num="2.22.2"/>
        <vers num="2.22.3"/>
        <vers num="2.22.4"/>
        <vers num="2.22.5"/>
        <vers num="2.23.0"/>
        <vers num="2.23.1"/>
        <vers num="2.23.2"/>
        <vers num="2.23.3"/>
        <vers num="2.23.4"/>
        <vers num="2.23.5"/>
        <vers num="2.23.6"/>
        <vers num="2.24.0"/>
        <vers num="2.24.1"/>
        <vers num="2.24.2"/>
        <vers num="2.25.0"/>
        <vers num="2.25.1"/>
        <vers num="2.25.10"/>
        <vers num="2.25.11"/>
        <vers num="2.25.12"/>
        <vers num="2.25.13"/>
        <vers num="2.25.14"/>
        <vers num="2.25.15"/>
        <vers num="2.25.16"/>
        <vers num="2.25.17"/>
        <vers num="2.25.2"/>
        <vers num="2.25.3"/>
        <vers num="2.25.4"/>
        <vers num="2.25.5"/>
        <vers num="2.25.6"/>
        <vers num="2.25.7"/>
        <vers num="2.25.8"/>
        <vers num="2.25.9"/>
        <vers num="2.26.0"/>
        <vers num="2.26.1"/>
        <vers num="2.27.0"/>
        <vers num="2.27.1"/>
        <vers num="2.27.2"/>
        <vers num="2.27.3"/>
        <vers num="2.27.4"/>
        <vers num="2.27.5"/>
        <vers num="2.27.90"/>
        <vers num="2.27.91"/>
        <vers num="2.27.92"/>
        <vers num="2.27.93"/>
        <vers num="2.28"/>
        <vers num="2.28.0"/>
        <vers num="2.28.1"/>
        <vers num="2.28.2"/>
        <vers num="2.28.3"/>
        <vers num="2.28.4"/>
        <vers num="2.28.5"/>
        <vers num="2.28.6"/>
        <vers num="2.28.7"/>
        <vers num="2.28.8"/>
        <vers num="2.29.10"/>
        <vers num="2.29.12"/>
        <vers num="2.29.14"/>
        <vers num="2.29.16"/>
        <vers num="2.29.18"/>
        <vers num="2.29.2"/>
        <vers num="2.29.4"/>
        <vers num="2.29.6"/>
        <vers num="2.29.8"/>
        <vers num="2.29.90"/>
        <vers num="2.29.92"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.30.0"/>
        <vers num="2.30.1"/>
        <vers num="2.30.2"/>
        <vers num="2.31.0"/>
        <vers num="2.31.2"/>
        <vers num="2.31.4"/>
        <vers num="2.31.6"/>
        <vers prev="1" num="2.31.8"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="2.8.2"/>
        <vers num="2.8.3"/>
        <vers num="2.8.4"/>
        <vers num="2.8.5"/>
        <vers num="2.8.6"/>
        <vers num="2.9.0"/>
        <vers num="2.9.1"/>
        <vers num="2.9.2"/>
        <vers num="2.9.3"/>
        <vers num="2.9.4"/>
        <vers num="2.9.5"/>
        <vers num="2.9.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0040" published="2012-01-24" name="CVE-2012-0040" modified="2012-01-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72313" source="XF">simplesamlphp-nocookie-logout-xss(72313)</ref>
      <ref url="http://www.securityfocus.com/bid/51372" source="BID">51372</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/20/20" source="MLIST">[oss-security] 20120120 Re: CVE request: simpleSAMLphp 1.8.2 cross site scripting</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2387" source="DEBIAN" adv="1">DSA-2387</ref>
      <ref url="http://secunia.com/advisories/47534" source="SECUNIA" adv="1">47534</ref>
      <ref url="http://secunia.com/advisories/47491" source="SECUNIA" adv="1">47491</ref>
      <ref url="http://osvdb.org/78254" source="OSVDB">78254</ref>
      <ref url="http://code.google.com/p/simplesamlphp/issues/detail?id=468" source="CONFIRM">http://code.google.com/p/simplesamlphp/issues/detail?id=468</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simplesamlphp" name="simplesamlphp">
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers prev="1" num="1.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0041" published="2012-04-11" name="CVE-2012-0041" modified="2013-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a capture file, as demonstrated by an airopeek file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6663" source="CONFIRM" patch="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6663</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40164" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40164</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2012-01.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2012-01.html</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/20/4" source="MLIST">[oss-security] 20120119 Re: CVE request: Wireshark multiple vulnerabilities</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/11/7" source="MLIST">[oss-security] 20120111 Re: CVE request: Wireshark multiple vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/48947" source="SECUNIA">48947</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0125.html" source="REDHAT">RHSA-2013:0125</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15297" source="OVAL">oval:org.mitre.oval:def:15297</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.10"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0042" published="2012-04-11" name="CVE-2012-0042" modified="2013-04-01" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="2.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="5.5" CVSS_base_score="2.9">
    <desc>
      <descript source="cve">Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 does not properly perform certain string conversions, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet, related to epan/to_str.c.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6634" source="CONFIRM" patch="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6634</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40194" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40194</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2012-02.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2012-02.html</ref>
      <ref url="http://www.securitytracker.com/id?1026507" source="SECTRACK">1026507</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/11/7" source="MLIST">[oss-security] 20120111 Re: CVE request: Wireshark multiple vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/48947" source="SECUNIA">48947</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0125.html" source="REDHAT">RHSA-2013:0125</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15368" source="OVAL">oval:org.mitre.oval:def:15368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.10"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0043" published="2012-04-11" name="CVE-2012-0043" modified="2013-04-01" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.5" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Buffer overflow in the reassemble_message function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a series of fragmented RLC packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6391" source="CONFIRM" patch="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6391</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40266" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40266</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2012-03.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2012-03.html</ref>
      <ref url="http://www.securitytracker.com/id?1026508" source="SECTRACK">1026508</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/11/7" source="MLIST">[oss-security] 20120111 Re: CVE request: Wireshark multiple vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15324" source="OVAL">oval:org.mitre.oval:def:15324</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.10"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0044" published="2012-05-17" name="CVE-2012-0044" modified="2013-04-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the drm_mode_dirtyfb_ioctl function in drivers/gpu/drm/drm_crtc.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.1.5 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted ioctl call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/a5cd335165e31db9dbab636fd29895d41da55dd2" source="CONFIRM">https://github.com/torvalds/linux/commit/a5cd335165e31db9dbab636fd29895d41da55dd2</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=772894" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=772894</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1556-1" source="UBUNTU">USN-1556-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1555-1" source="UBUNTU">USN-1555-1</ref>
      <ref url="http://www.securityfocus.com/bid/51371" source="BID">51371</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/12/1" source="MLIST">[oss-security] 20120111 Re: CVE request - kernel: drm: integer overflow in drm_mode_dirtyfb_ioctl()</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1.5" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1.5</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0743.html" source="REDHAT">RHSA-2012:0743</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a5cd335165e31db9dbab636fd29895d41da55dd2" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a5cd335165e31db9dbab636fd29895d41da55dd2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="1.2.0"/>
        <vers num="1.3.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.2"/>
        <vers num="2.0.20"/>
        <vers num="2.0.21"/>
        <vers num="2.0.22"/>
        <vers num="2.0.23"/>
        <vers num="2.0.24"/>
        <vers num="2.0.25"/>
        <vers num="2.0.26"/>
        <vers num="2.0.27"/>
        <vers num="2.0.28"/>
        <vers num="2.0.29"/>
        <vers num="2.0.3"/>
        <vers num="2.0.30"/>
        <vers num="2.0.31"/>
        <vers num="2.0.32"/>
        <vers num="2.0.33"/>
        <vers num="2.0.34"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1.132"/>
        <vers num="2.1.89"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13" edition="pre15"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15" edition="pre16"/>
        <vers num="2.2.16" edition="pre5"/>
        <vers num="2.2.16" edition="pre6"/>
        <vers num="2.2.17" edition="pre14"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.2"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21" edition="pre1"/>
        <vers num="2.2.21" edition="pre2"/>
        <vers num="2.2.21" edition="pre3"/>
        <vers num="2.2.21" edition="pre4"/>
        <vers num="2.2.21" edition="rc1"/>
        <vers num="2.2.21" edition="rc2"/>
        <vers num="2.2.21" edition="rc3"/>
        <vers num="2.2.21" edition="rc4"/>
        <vers num="2.2.22" edition="rc1"/>
        <vers num="2.2.22" edition="rc2"/>
        <vers num="2.2.22" edition="rc3"/>
        <vers num="2.2.23" edition="rc1"/>
        <vers num="2.2.23" edition="rc2"/>
        <vers num="2.2.24" edition="rc2"/>
        <vers num="2.2.24" edition="rc3"/>
        <vers num="2.2.24" edition="rc4"/>
        <vers num="2.2.24" edition="rc5"/>
        <vers num="2.2.25"/>
        <vers num="2.2.26"/>
        <vers num="2.2.27" edition="pre1"/>
        <vers num="2.2.27" edition="pre2"/>
        <vers num="2.2.27" edition="rc1"/>
        <vers num="2.2.27" edition="rc2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4" edition="rc1"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.3.15"/>
        <vers num="2.3.16"/>
        <vers num="2.3.17"/>
        <vers num="2.3.18"/>
        <vers num="2.3.19"/>
        <vers num="2.3.2"/>
        <vers num="2.3.20"/>
        <vers num="2.3.21"/>
        <vers num="2.3.22"/>
        <vers num="2.3.23"/>
        <vers num="2.3.24"/>
        <vers num="2.3.25"/>
        <vers num="2.3.26"/>
        <vers num="2.3.27"/>
        <vers num="2.3.28"/>
        <vers num="2.3.29"/>
        <vers num="2.3.3"/>
        <vers num="2.3.30"/>
        <vers num="2.3.31"/>
        <vers num="2.3.32"/>
        <vers num="2.3.33"/>
        <vers num="2.3.34"/>
        <vers num="2.3.35"/>
        <vers num="2.3.36"/>
        <vers num="2.3.37"/>
        <vers num="2.3.38"/>
        <vers num="2.3.39"/>
        <vers num="2.3.4"/>
        <vers num="2.3.40"/>
        <vers num="2.3.41"/>
        <vers num="2.3.42"/>
        <vers num="2.3.43"/>
        <vers num="2.3.44"/>
        <vers num="2.3.45"/>
        <vers num="2.3.46"/>
        <vers num="2.3.47"/>
        <vers num="2.3.48"/>
        <vers num="2.3.49"/>
        <vers num="2.3.5"/>
        <vers num="2.3.50"/>
        <vers num="2.3.51"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.3.99" edition="pre1"/>
        <vers num="2.3.99" edition="pre2"/>
        <vers num="2.3.99" edition="pre3"/>
        <vers num="2.3.99" edition="pre4"/>
        <vers num="2.3.99" edition="pre5"/>
        <vers num="2.3.99" edition="pre6"/>
        <vers num="2.3.99" edition="pre7"/>
        <vers num="2.3.99" edition="pre8"/>
        <vers num="2.3.99" edition="pre9"/>
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11" edition="pre3"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.18" edition="pre9"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22" edition="pre10"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.24"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27" edition="pre1"/>
        <vers num="2.4.27" edition="pre2"/>
        <vers num="2.4.27" edition="pre3"/>
        <vers num="2.4.27" edition="pre4"/>
        <vers num="2.4.27" edition="pre5"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29" edition="rc1"/>
        <vers num="2.4.29" edition="rc2"/>
        <vers num="2.4.3" edition="pre3"/>
        <vers num="2.4.30" edition="rc2"/>
        <vers num="2.4.30" edition="rc3"/>
        <vers num="2.4.31" edition="pre1"/>
        <vers num="2.4.32" edition="pre1"/>
        <vers num="2.4.32" edition="pre2"/>
        <vers num="2.4.33" edition="pre1"/>
        <vers num="2.4.33.2"/>
        <vers num="2.4.33.3"/>
        <vers num="2.4.33.4"/>
        <vers num="2.4.33.5"/>
        <vers num="2.4.34" edition="rc3"/>
        <vers num="2.4.34.1"/>
        <vers num="2.4.34.2"/>
        <vers num="2.4.35"/>
        <vers num="2.4.35.2"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
        <vers num="2.5.14"/>
        <vers num="2.5.15"/>
        <vers num="2.5.16"/>
        <vers num="2.5.17"/>
        <vers num="2.5.18"/>
        <vers num="2.5.19"/>
        <vers num="2.5.2"/>
        <vers num="2.5.20"/>
        <vers num="2.5.21"/>
        <vers num="2.5.22"/>
        <vers num="2.5.23"/>
        <vers num="2.5.24"/>
        <vers num="2.5.25"/>
        <vers num="2.5.26"/>
        <vers num="2.5.27"/>
        <vers num="2.5.28"/>
        <vers num="2.5.29"/>
        <vers num="2.5.3"/>
        <vers num="2.5.30"/>
        <vers num="2.5.31"/>
        <vers num="2.5.32"/>
        <vers num="2.5.33"/>
        <vers num="2.5.34"/>
        <vers num="2.5.35"/>
        <vers num="2.5.36"/>
        <vers num="2.5.37"/>
        <vers num="2.5.38"/>
        <vers num="2.5.39"/>
        <vers num="2.5.4"/>
        <vers num="2.5.40"/>
        <vers num="2.5.41"/>
        <vers num="2.5.42"/>
        <vers num="2.5.43"/>
        <vers num="2.5.44"/>
        <vers num="2.5.45"/>
        <vers num="2.5.46"/>
        <vers num="2.5.47"/>
        <vers num="2.5.48"/>
        <vers num="2.5.49"/>
        <vers num="2.5.5"/>
        <vers num="2.5.50"/>
        <vers num="2.5.51"/>
        <vers num="2.5.52"/>
        <vers num="2.5.53"/>
        <vers num="2.5.54"/>
        <vers num="2.5.55"/>
        <vers num="2.5.56"/>
        <vers num="2.5.57"/>
        <vers num="2.5.58"/>
        <vers num="2.5.59"/>
        <vers num="2.5.6"/>
        <vers num="2.5.60"/>
        <vers num="2.5.61"/>
        <vers num="2.5.62"/>
        <vers num="2.5.63"/>
        <vers num="2.5.64"/>
        <vers num="2.5.65"/>
        <vers num="2.5.66"/>
        <vers num="2.5.67"/>
        <vers num="2.5.68"/>
        <vers num="2.5.69"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.1" edition="rc3"/>
        <vers num="2.6.10" edition="rc1"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.10" edition="rc3"/>
        <vers num="2.6.11" edition="rc1"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
        <vers num="2.6.11" edition="rc4"/>
        <vers num="2.6.11" edition="rc5"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.10"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.11.9"/>
        <vers num="2.6.12" edition="rc1"/>
        <vers num="2.6.12" edition="rc2"/>
        <vers num="2.6.12" edition="rc3"/>
        <vers num="2.6.12" edition="rc4"/>
        <vers num="2.6.12" edition="rc5"/>
        <vers num="2.6.12" edition="rc6"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13" edition="rc1"/>
        <vers num="2.6.13" edition="rc2"/>
        <vers num="2.6.13" edition="rc3"/>
        <vers num="2.6.13" edition="rc4"/>
        <vers num="2.6.13" edition="rc5"/>
        <vers num="2.6.13" edition="rc6"/>
        <vers num="2.6.13" edition="rc7"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.13.5"/>
        <vers num="2.6.14" edition="rc1"/>
        <vers num="2.6.14" edition="rc2"/>
        <vers num="2.6.14" edition="rc3"/>
        <vers num="2.6.14" edition="rc4"/>
        <vers num="2.6.14" edition="rc5"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.14.5"/>
        <vers num="2.6.14.6"/>
        <vers num="2.6.14.7"/>
        <vers num="2.6.15" edition="rc1"/>
        <vers num="2.6.15" edition="rc2"/>
        <vers num="2.6.15" edition="rc3"/>
        <vers num="2.6.15" edition="rc4"/>
        <vers num="2.6.15" edition="rc5"/>
        <vers num="2.6.15" edition="rc6"/>
        <vers num="2.6.15" edition="rc7"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.10"/>
        <vers num="2.6.15.11"/>
        <vers num="2.6.15.2"/>
        <vers num="2.6.15.3"/>
        <vers num="2.6.15.4"/>
        <vers num="2.6.15.5"/>
        <vers num="2.6.15.6"/>
        <vers num="2.6.15.7"/>
        <vers num="2.6.15.8"/>
        <vers num="2.6.15.9"/>
        <vers num="2.6.16" edition="rc1"/>
        <vers num="2.6.16" edition="rc2"/>
        <vers num="2.6.16" edition="rc3"/>
        <vers num="2.6.16" edition="rc4"/>
        <vers num="2.6.16" edition="rc5"/>
        <vers num="2.6.16" edition="rc6"/>
        <vers num="2.6.16" edition="rc7"/>
        <vers num="2.6.16.1"/>
        <vers num="2.6.16.10"/>
        <vers num="2.6.16.11"/>
        <vers num="2.6.16.12"/>
        <vers num="2.6.16.13"/>
        <vers num="2.6.16.14"/>
        <vers num="2.6.16.15"/>
        <vers num="2.6.16.16"/>
        <vers num="2.6.16.17"/>
        <vers num="2.6.16.18"/>
        <vers num="2.6.16.19"/>
        <vers num="2.6.16.2"/>
        <vers num="2.6.16.20"/>
        <vers num="2.6.16.21"/>
        <vers num="2.6.16.22"/>
        <vers num="2.6.16.23"/>
        <vers num="2.6.16.24"/>
        <vers num="2.6.16.25"/>
        <vers num="2.6.16.26"/>
        <vers num="2.6.16.27"/>
        <vers num="2.6.16.28"/>
        <vers num="2.6.16.29"/>
        <vers num="2.6.16.3"/>
        <vers num="2.6.16.30"/>
        <vers num="2.6.16.31"/>
        <vers num="2.6.16.32"/>
        <vers num="2.6.16.33"/>
        <vers num="2.6.16.34"/>
        <vers num="2.6.16.35"/>
        <vers num="2.6.16.36"/>
        <vers num="2.6.16.37"/>
        <vers num="2.6.16.38"/>
        <vers num="2.6.16.39"/>
        <vers num="2.6.16.4"/>
        <vers num="2.6.16.40"/>
        <vers num="2.6.16.41"/>
        <vers num="2.6.16.42"/>
        <vers num="2.6.16.43"/>
        <vers num="2.6.16.44"/>
        <vers num="2.6.16.45"/>
        <vers num="2.6.16.46"/>
        <vers num="2.6.16.47"/>
        <vers num="2.6.16.48"/>
        <vers num="2.6.16.49"/>
        <vers num="2.6.16.5"/>
        <vers num="2.6.16.50"/>
        <vers num="2.6.16.51"/>
        <vers num="2.6.16.52"/>
        <vers num="2.6.16.53"/>
        <vers num="2.6.16.54"/>
        <vers num="2.6.16.55"/>
        <vers num="2.6.16.56"/>
        <vers num="2.6.16.57"/>
        <vers num="2.6.16.58"/>
        <vers num="2.6.16.59"/>
        <vers num="2.6.16.6"/>
        <vers num="2.6.16.60"/>
        <vers num="2.6.16.61"/>
        <vers num="2.6.16.62"/>
        <vers num="2.6.16.7"/>
        <vers num="2.6.16.8"/>
        <vers num="2.6.16.9"/>
        <vers num="2.6.17" edition="rc1"/>
        <vers num="2.6.17" edition="rc2"/>
        <vers num="2.6.17" edition="rc3"/>
        <vers num="2.6.17" edition="rc4"/>
        <vers num="2.6.17" edition="rc5"/>
        <vers num="2.6.17" edition="rc6"/>
        <vers num="2.6.17.1"/>
        <vers num="2.6.17.10"/>
        <vers num="2.6.17.11"/>
        <vers num="2.6.17.12"/>
        <vers num="2.6.17.13"/>
        <vers num="2.6.17.14"/>
        <vers num="2.6.17.2"/>
        <vers num="2.6.17.3"/>
        <vers num="2.6.17.4"/>
        <vers num="2.6.17.5"/>
        <vers num="2.6.17.6"/>
        <vers num="2.6.17.7"/>
        <vers num="2.6.17.8"/>
        <vers num="2.6.17.9"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.18.1"/>
        <vers num="2.6.18.2"/>
        <vers num="2.6.18.3"/>
        <vers num="2.6.18.4"/>
        <vers num="2.6.18.5"/>
        <vers num="2.6.18.6"/>
        <vers num="2.6.18.7"/>
        <vers num="2.6.18.8"/>
        <vers num="2.6.19" edition="rc1"/>
        <vers num="2.6.19" edition="rc2"/>
        <vers num="2.6.19" edition="rc3"/>
        <vers num="2.6.19" edition="rc4"/>
        <vers num="2.6.19.1"/>
        <vers num="2.6.19.2"/>
        <vers num="2.6.19.3"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.2" edition="rc1"/>
        <vers num="2.6.2" edition="rc2"/>
        <vers num="2.6.2" edition="rc3"/>
        <vers num="2.6.20" edition="rc2"/>
        <vers num="2.6.20.1"/>
        <vers num="2.6.20.10"/>
        <vers num="2.6.20.11"/>
        <vers num="2.6.20.12"/>
        <vers num="2.6.20.13"/>
        <vers num="2.6.20.14"/>
        <vers num="2.6.20.15"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.2"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.20.3"/>
        <vers num="2.6.20.4"/>
        <vers num="2.6.20.5"/>
        <vers num="2.6.20.6"/>
        <vers num="2.6.20.7"/>
        <vers num="2.6.20.8"/>
        <vers num="2.6.20.9"/>
        <vers num="2.6.21" edition="git1"/>
        <vers num="2.6.21" edition="git2"/>
        <vers num="2.6.21" edition="git3"/>
        <vers num="2.6.21" edition="git4"/>
        <vers num="2.6.21" edition="git5"/>
        <vers num="2.6.21" edition="git6"/>
        <vers num="2.6.21" edition="git7"/>
        <vers num="2.6.21" edition="rc3"/>
        <vers num="2.6.21" edition="rc4"/>
        <vers num="2.6.21" edition="rc5"/>
        <vers num="2.6.21" edition="rc6"/>
        <vers num="2.6.21" edition="rc7"/>
        <vers num="2.6.21.1"/>
        <vers num="2.6.21.2"/>
        <vers num="2.6.21.3"/>
        <vers num="2.6.21.4"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers num="2.6.22.15"/>
        <vers num="2.6.22.16"/>
        <vers num="2.6.22.17"/>
        <vers num="2.6.22.18"/>
        <vers num="2.6.22.19"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.20"/>
        <vers num="2.6.22.3"/>
        <vers num="2.6.22.4"/>
        <vers num="2.6.22.5"/>
        <vers num="2.6.22.6"/>
        <vers num="2.6.22.7"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.27.41"/>
        <vers num="2.6.27.42"/>
        <vers num="2.6.27.43"/>
        <vers num="2.6.27.44"/>
        <vers num="2.6.27.45"/>
        <vers num="2.6.27.46"/>
        <vers num="2.6.27.47"/>
        <vers num="2.6.27.48"/>
        <vers num="2.6.27.49"/>
        <vers num="2.6.27.5"/>
        <vers num="2.6.27.50"/>
        <vers num="2.6.27.51"/>
        <vers num="2.6.27.52"/>
        <vers num="2.6.27.53"/>
        <vers num="2.6.27.54"/>
        <vers num="2.6.27.55"/>
        <vers num="2.6.27.56"/>
        <vers num="2.6.27.57"/>
        <vers num="2.6.27.58"/>
        <vers num="2.6.27.59"/>
        <vers num="2.6.27.6"/>
        <vers num="2.6.27.60"/>
        <vers num="2.6.27.61"/>
        <vers num="2.6.27.62"/>
        <vers num="2.6.27.7"/>
        <vers num="2.6.27.8"/>
        <vers num="2.6.27.9"/>
        <vers num="2.6.28"/>
        <vers num="2.6.28.1"/>
        <vers num="2.6.28.10"/>
        <vers num="2.6.28.2"/>
        <vers num="2.6.28.3"/>
        <vers num="2.6.28.4"/>
        <vers num="2.6.28.5"/>
        <vers num="2.6.28.6"/>
        <vers num="2.6.28.7"/>
        <vers num="2.6.28.8"/>
        <vers num="2.6.28.9"/>
        <vers num="2.6.29"/>
        <vers num="2.6.29.1"/>
        <vers num="2.6.29.2"/>
        <vers num="2.6.29.3"/>
        <vers num="2.6.29.4"/>
        <vers num="2.6.29.5"/>
        <vers num="2.6.29.6"/>
        <vers num="2.6.3" edition="rc1"/>
        <vers num="2.6.3" edition="rc2"/>
        <vers num="2.6.3" edition="rc3"/>
        <vers num="2.6.3" edition="rc4"/>
        <vers num="2.6.32"/>
        <vers num="2.6.32.1"/>
        <vers num="2.6.32.10"/>
        <vers num="2.6.32.11"/>
        <vers num="2.6.32.12"/>
        <vers num="2.6.32.13"/>
        <vers num="2.6.32.14"/>
        <vers num="2.6.32.15"/>
        <vers num="2.6.32.16"/>
        <vers num="2.6.32.17"/>
        <vers num="2.6.32.18"/>
        <vers num="2.6.32.2"/>
        <vers num="2.6.32.28"/>
        <vers num="2.6.32.29"/>
        <vers num="2.6.32.3"/>
        <vers num="2.6.32.30"/>
        <vers num="2.6.32.31"/>
        <vers num="2.6.32.32"/>
        <vers num="2.6.32.33"/>
        <vers num="2.6.32.34"/>
        <vers num="2.6.32.35"/>
        <vers num="2.6.32.36"/>
        <vers num="2.6.32.37"/>
        <vers num="2.6.32.38"/>
        <vers num="2.6.32.39"/>
        <vers num="2.6.32.4"/>
        <vers num="2.6.32.40"/>
        <vers num="2.6.32.41"/>
        <vers num="2.6.32.42"/>
        <vers num="2.6.32.43"/>
        <vers num="2.6.32.44"/>
        <vers num="2.6.32.45"/>
        <vers num="2.6.32.46"/>
        <vers num="2.6.32.47"/>
        <vers num="2.6.32.48"/>
        <vers num="2.6.32.49"/>
        <vers num="2.6.32.5"/>
        <vers num="2.6.32.50"/>
        <vers num="2.6.32.51"/>
        <vers num="2.6.32.52"/>
        <vers num="2.6.32.53"/>
        <vers num="2.6.32.54"/>
        <vers num="2.6.32.55"/>
        <vers num="2.6.32.56"/>
        <vers num="2.6.32.57"/>
        <vers num="2.6.32.58"/>
        <vers num="2.6.32.6"/>
        <vers num="2.6.32.7"/>
        <vers num="2.6.32.8"/>
        <vers num="2.6.32.9"/>
        <vers num="2.6.33.10"/>
        <vers num="2.6.33.11"/>
        <vers num="2.6.33.12"/>
        <vers num="2.6.33.13"/>
        <vers num="2.6.33.14"/>
        <vers num="2.6.33.15"/>
        <vers num="2.6.33.16"/>
        <vers num="2.6.33.17"/>
        <vers num="2.6.33.18"/>
        <vers num="2.6.33.19"/>
        <vers num="2.6.33.20"/>
        <vers num="2.6.33.8"/>
        <vers num="2.6.33.9"/>
        <vers num="2.6.34.1"/>
        <vers num="2.6.34.10"/>
        <vers num="2.6.34.2"/>
        <vers num="2.6.34.3"/>
        <vers num="2.6.34.8"/>
        <vers num="2.6.34.9"/>
        <vers num="2.6.35.1"/>
        <vers num="2.6.35.10"/>
        <vers num="2.6.35.11"/>
        <vers num="2.6.35.12"/>
        <vers num="2.6.35.13"/>
        <vers num="2.6.37" edition="rc1"/>
        <vers num="2.6.37" edition="rc2"/>
        <vers num="2.6.37" edition="rc3"/>
        <vers num="2.6.37" edition="rc4"/>
        <vers num="2.6.37" edition="rc5"/>
        <vers num="2.6.38" edition="rc1"/>
        <vers num="2.6.38" edition="rc2"/>
        <vers num="2.6.38" edition="rc3"/>
        <vers num="2.6.38" edition="rc4"/>
        <vers num="2.6.38" edition="rc5"/>
        <vers num="2.6.38" edition="rc6"/>
        <vers num="2.6.38" edition="rc7"/>
        <vers num="2.6.38" edition="rc8"/>
        <vers num="2.6.39" edition="rc1"/>
        <vers num="2.6.39" edition="rc2"/>
        <vers num="2.6.39" edition="rc3"/>
        <vers num="2.6.39" edition="rc4"/>
        <vers num="2.6.39" edition="rc5"/>
        <vers num="2.6.39" edition="rc6"/>
        <vers num="2.6.39" edition="rc7"/>
        <vers num="2.6.4" edition="rc1"/>
        <vers num="2.6.4" edition="rc2"/>
        <vers num="2.6.4" edition="rc3"/>
        <vers num="2.6.5" edition="rc1"/>
        <vers num="2.6.5" edition="rc2"/>
        <vers num="2.6.5" edition="rc3"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.6" edition="rc2"/>
        <vers num="2.6.6" edition="rc3"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.7" edition="rc2"/>
        <vers num="2.6.7" edition="rc3"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.8" edition="rc4"/>
        <vers num="2.6.8.1"/>
        <vers num="2.6.9" edition="rc1"/>
        <vers num="2.6.9" edition="rc2"/>
        <vers num="2.6.9" edition="rc3"/>
        <vers num="2.6.9" edition="rc4"/>
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers prev="1" num="3.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0045" published="2012-07-03" name="CVE-2012-0045" modified="2012-07-03" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The em_syscall function in arch/x86/kvm/emulate.c in the KVM implementation in the Linux kernel before 3.2.14 does not properly handle the 0f05 (aka syscall) opcode, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application, as demonstrated by an NASM file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/c2226fc9e87ba3da060e47333657cd6616652b84" source="CONFIRM" patch="1">https://github.com/torvalds/linux/commit/c2226fc9e87ba3da060e47333657cd6616652b84</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=773370" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=773370</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/12/2" source="MLIST">[oss-security] 20120111 Re: CVE request -- kernel: kvm: syscall instruction induced guest panic</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.14" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.14</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c2226fc9e87ba3da060e47333657cd6616652b84" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c2226fc9e87ba3da060e47333657cd6616652b84</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers prev="1" num="3.2.13"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0047" published="2012-03-23" name="CVE-2012-0047" modified="2012-10-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74273" source="XF">apache-wicket-unspec-xss(74273)</ref>
      <ref url="http://www.securitytracker.com/id?1026839" source="SECTRACK">1026839</ref>
      <ref url="http://wicket.apache.org/2012/03/22/wicket-cve-2012-0047.html" source="CONFIRM" adv="1">http://wicket.apache.org/2012/03/22/wicket-cve-2012-0047.html</ref>
      <ref url="http://osvdb.org/80300" source="OSVDB">80300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="wicket">
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.10"/>
        <vers num="1.4.11"/>
        <vers num="1.4.12"/>
        <vers num="1.4.13"/>
        <vers num="1.4.14"/>
        <vers num="1.4.15"/>
        <vers num="1.4.16"/>
        <vers num="1.4.17"/>
        <vers num="1.4.18"/>
        <vers num="1.4.19"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0048" published="2012-08-25" name="CVE-2012-0048" modified="2012-08-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">OpenTTD 0.3.5 through 1.1.4 allows remote attackers to cause a denial of service (game pause) by connecting to the server and not finishing the (1) authorization phase or (2) map download, aka a "slow read" attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://vcs.openttd.org/svn/changeset/23764" source="CONFIRM" patch="1">http://vcs.openttd.org/svn/changeset/23764</ref>
      <ref url="http://www.tt-forums.net/viewtopic.php?f=33&amp;t=58073&amp;hilit=pause#p989303" source="MISC">http://www.tt-forums.net/viewtopic.php?f=33&amp;t=58073&amp;hilit=pause#p989303</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/13/8" source="MLIST">[oss-security] 20120113 Re: CVE request for OpenTTD</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/07/2" source="MLIST">[oss-security] 20120107 CVE request for OpenTTD</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2524" source="DEBIAN">DSA-2524</ref>
      <ref url="http://security.openttd.org/en/CVE-2012-0049" source="CONFIRM" adv="1">http://security.openttd.org/en/CVE-2012-0049</ref>
      <ref url="http://secunia.com/advisories/50137" source="SECUNIA" adv="1">50137</ref>
      <ref url="http://bugs.openttd.org/task/4955" source="CONFIRM" adv="1">http://bugs.openttd.org/task/4955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openttd" name="openttd">
        <vers num="0.3.5"/>
        <vers num="0.3.6"/>
        <vers num="0.3.7"/>
        <vers num="0.4.0"/>
        <vers num="0.4.0.1"/>
        <vers num="0.4.5"/>
        <vers num="0.4.6"/>
        <vers num="0.4.7"/>
        <vers num="0.4.8" edition="rc1"/>
        <vers num="0.4.8" edition="rc2"/>
        <vers num="0.5.0" edition="rc1"/>
        <vers num="0.5.0" edition="rc2"/>
        <vers num="0.5.0" edition="rc3"/>
        <vers num="0.5.0" edition="rc4"/>
        <vers num="0.5.0" edition="rc5"/>
        <vers num="0.5.1" edition="rc1"/>
        <vers num="0.5.1" edition="rc2"/>
        <vers num="0.5.1" edition="rc3"/>
        <vers num="0.5.2" edition="rc1"/>
        <vers num="0.5.3" edition="rc1"/>
        <vers num="0.5.3" edition="rc2"/>
        <vers num="0.5.3" edition="rc3"/>
        <vers num="0.6.0" edition="beta1"/>
        <vers num="0.6.0" edition="beta2"/>
        <vers num="0.6.0" edition="beta3"/>
        <vers num="0.6.0" edition="beta4"/>
        <vers num="0.6.0" edition="beta5"/>
        <vers num="0.6.0" edition="rc1"/>
        <vers num="0.6.1" edition="rc1"/>
        <vers num="0.6.1" edition="rc2"/>
        <vers num="0.6.2" edition="rc1"/>
        <vers num="0.6.2" edition="rc2"/>
        <vers num="0.6.2-rc1"/>
        <vers num="0.6.2-rc2"/>
        <vers num="0.6.3" edition="rc1"/>
        <vers num="0.7.0" edition="beta1"/>
        <vers num="0.7.0" edition="beta2"/>
        <vers num="0.7.0" edition="rc1"/>
        <vers num="0.7.0" edition="rc2"/>
        <vers num="0.7.1" edition="rc1"/>
        <vers num="0.7.1" edition="rc2"/>
        <vers num="0.7.1" edition="rc3"/>
        <vers num="0.7.2" edition="rc1"/>
        <vers num="0.7.2" edition="rc2"/>
        <vers num="0.7.3" edition="rc1"/>
        <vers num="0.7.3" edition="rc2"/>
        <vers num="0.7.4" edition="rc1"/>
        <vers num="0.7.5" edition="rc1"/>
        <vers num="1.0.0" edition="beta1"/>
        <vers num="1.0.0" edition="beta2"/>
        <vers num="1.0.0" edition="beta3"/>
        <vers num="1.0.0" edition="beta4"/>
        <vers num="1.0.0" edition="rc1"/>
        <vers num="1.0.0" edition="rc2"/>
        <vers num="1.0.0" edition="rc3"/>
        <vers num="1.0.1" edition="rc1"/>
        <vers num="1.0.1" edition="rc2"/>
        <vers num="1.0.2" edition="rc1"/>
        <vers num="1.0.3" edition="rc1"/>
        <vers num="1.0.4" edition="rc1"/>
        <vers num="1.0.5" edition="rc1"/>
        <vers num="1.0.5" edition="rc2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0050" published="2012-01-19" name="CVE-2012-0050" modified="2012-11-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSL 0.9.8s and 1.0.0f does not properly support DTLS applications, which allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an out-of-bounds read.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4108.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1026548" source="SECTRACK">1026548</ref>
      <ref url="http://www.securityfocus.com/bid/51563" source="BID">51563</ref>
      <ref url="http://www.openssl.org/news/secadv_20120118.txt" source="CONFIRM" adv="1">http://www.openssl.org/news/secadv_20120118.txt</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2012:011" source="MANDRIVA">MDVSA-2012:011</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2392" source="DEBIAN">DSA-2392</ref>
      <ref url="http://secunia.com/advisories/48528" source="SECUNIA">48528</ref>
      <ref url="http://secunia.com/advisories/47755" source="SECUNIA">47755</ref>
      <ref url="http://secunia.com/advisories/47677" source="SECUNIA">47677</ref>
      <ref url="http://secunia.com/advisories/47631" source="SECUNIA">47631</ref>
      <ref url="http://osvdb.org/78320" source="OSVDB">78320</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=134039053214295&amp;w=2" source="HP">HPSBOV02793</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=134039053214295&amp;w=2" source="HP">SSRT100891</ref>
      <ref url="http://h20565.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03169289" source="HP">SSRT100747</ref>
      <ref url="http://h20565.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03169289" source="HP">HPSBUX02737</ref>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/openssl_advisory3.asc" source="CONFIRM">http://aix.software.ibm.com/aix/efixes/security/openssl_advisory3.asc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.8s"/>
        <vers num="1.0.0f"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0053" published="2012-01-27" name="CVE-2012-0053" modified="2012-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1235454" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1235454</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=785069" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=785069</ref>
      <ref url="http://www.securityfocus.com/bid/51706" source="BID">51706</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html</ref>
      <ref url="http://support.apple.com/kb/HT5501" source="CONFIRM">http://support.apple.com/kb/HT5501</ref>
      <ref url="http://secunia.com/advisories/48551" source="SECUNIA">48551</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0128.html" source="REDHAT">RHSA-2012:0128</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html" source="SUSE">openSUSE-SU-2012:0314</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html" source="APPLE">APPLE-SA-2012-09-19-2</ref>
      <ref url="http://httpd.apache.org/security/vulnerabilities_22.html" source="CONFIRM" adv="1">http://httpd.apache.org/security/vulnerabilities_22.html</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041" source="HP">SSRT100877</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041" source="HP">HPSBMU02786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.2"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15"/>
        <vers num="2.2.16"/>
        <vers num="2.2.17"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.2"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.6"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0054" published="2012-03-19" name="CVE-2012-0054" modified="2012-08-03" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">libs/updater.py in GoLismero 0.6.3, and other versions before Git revision 2b3bb43d6867, as used in backtrack and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on GoLismero-controlled files, as demonstrated using Admin/changes.dat.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/78472" source="OSVDB">78472</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/17/7" source="MLIST">[oss-security] 20120117 CVE-request: golismero symlink vulnerability</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/17/10" source="MLIST">[oss-security] 20120117 Re: CVE-request: golismero symlink vulnerability</ref>
      <ref url="http://code.google.com/p/golismero/source/detail?r=2b3bb43d68676efd687361f7de29380189031ab8" source="MISC">http://code.google.com/p/golismero/source/detail?r=2b3bb43d68676efd687361f7de29380189031ab8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="golismero" name="golismero">
        <vers num="0.6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0056" published="2012-01-27" name="CVE-2012-0056" modified="2012-03-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The mem_write function in Linux kernel 2.6.39 and other versions, when ASLR is disabled, does not properly check permissions when writing to /proc/&lt;pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=782642" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=782642</ref>
      <ref url="http://www.securityfocus.com/bid/51625" source="BID">51625</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2012-0061.html" source="REDHAT">RHSA-2012:0061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2012-0052.html" source="REDHAT">RHSA-2012:0052</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/22/4" source="MLIST">[oss-security] 20120122 Re: CVE request: kernel: proc: clean up and fix /proc/&lt;pid>/mem handling</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/19/4" source="MLIST">[oss-security] 20120119 Re: CVE request: kernel: proc: clean up and fix /proc/&lt;pid>/mem handling</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/18/2" source="MLIST">[oss-security] 20120117 Re: CVE request: kernel: proc: clean up and fix /proc/&lt;pid>/mem handling</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/18/1" source="MLIST">[oss-security] 20120118 CVE request: kernel: proc: clean up and fix /proc/&lt;pid>/mem handling</ref>
      <ref url="http://ubuntu.com/usn/usn-1336-1" source="UBUNTU">USN-1336-1</ref>
      <ref url="http://secunia.com/advisories/47708" source="SECUNIA" adv="1">47708</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=e268337dfe26dfc7efd422a804dbb27977a3cccc" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=e268337dfe26dfc7efd422a804dbb27977a3cccc</ref>
      <ref url="http://blog.zx2c4.com/749" source="MISC">http://blog.zx2c4.com/749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.39"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0057" published="2012-02-01" name="CVE-2012-0057" modified="2012-07-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugs.php.net/bug.php?id=54446" source="CONFIRM" patch="1" adv="1">https://bugs.php.net/bug.php?id=54446</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/72908" source="XF">php-libxslt-security-bypass(72908)</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2399" source="DEBIAN">DSA-2399</ref>
      <ref url="http://secunia.com/advisories/48668" source="SECUNIA">48668</ref>
      <ref url="http://php.net/ChangeLog-5.php#5.3.9" source="CONFIRM">http://php.net/ChangeLog-5.php#5.3.9</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/18/3" source="MLIST">[oss-security] 20120117 Re: CVE affected for PHP 5.3.9 ?</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/15/2" source="MLIST">[oss-security] 20120114 Re: CVE affected for PHP 5.3.9 ?</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/15/10" source="MLIST">[oss-security] 20120115 Re: CVE affected for PHP 5.3.9 ?</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/15/1" source="MLIST">[oss-security] 20120115 Re: CVE affected for PHP 5.3.9 ?</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/14/3" source="MLIST">[oss-security] 20120114 Re: CVE affected for PHP 5.3.9 ?</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/14/2" source="MLIST">[oss-security] 20120114 Re: CVE affected for PHP 5.3.9 ?</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/14/1" source="MLIST">[oss-security] 20120113 Re: CVE affected for PHP 5.3.9 ?</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/13/7" source="MLIST">[oss-security] 20120113 Re: CVE affected for PHP 5.3.9 ?</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/13/6" source="MLIST">[oss-security] 20120113 Re: CVE affected for PHP 5.3.9 ?</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/13/5" source="MLIST">[oss-security] 20120113 Re: CVE affected for PHP 5.3.9 ?</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/13/4" source="MLIST">[oss-security] 20120113 CVE affected for PHP 5.3.9 ?</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/13/10" source="MLIST">[oss-security] 20120113 Re: CVE affected for PHP 5.3.9 ?</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00016.html" source="SUSE">openSUSE-SU-2012:0426</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041" source="HP">SSRT100877</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041" source="HP">HPSBMU02786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.0.0" edition="beta1"/>
        <vers num="5.0.0" edition="beta2"/>
        <vers num="5.0.0" edition="beta3"/>
        <vers num="5.0.0" edition="beta4"/>
        <vers num="5.0.0" edition="rc1"/>
        <vers num="5.0.0" edition="rc2"/>
        <vers num="5.0.0" edition="rc3"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="5.1.2"/>
        <vers num="5.1.3"/>
        <vers num="5.1.4"/>
        <vers num="5.1.5"/>
        <vers num="5.1.6"/>
        <vers num="5.2.0"/>
        <vers num="5.2.1"/>
        <vers num="5.2.10"/>
        <vers num="5.2.11"/>
        <vers num="5.2.12"/>
        <vers num="5.2.13"/>
        <vers num="5.2.14"/>
        <vers num="5.2.15"/>
        <vers num="5.2.16"/>
        <vers num="5.2.17"/>
        <vers num="5.2.2"/>
        <vers num="5.2.3"/>
        <vers num="5.2.4"/>
        <vers num="5.2.5"/>
        <vers num="5.2.6"/>
        <vers num="5.2.7"/>
        <vers num="5.2.8"/>
        <vers num="5.2.9"/>
        <vers num="5.3.0"/>
        <vers num="5.3.1"/>
        <vers num="5.3.2"/>
        <vers num="5.3.3"/>
        <vers num="5.3.4"/>
        <vers num="5.3.5"/>
        <vers num="5.3.6"/>
        <vers num="5.3.7"/>
        <vers prev="1" num="5.3.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0058" published="2012-05-17" name="CVE-2012-0058" modified="2012-08-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/802f43594d6e4d2ac61086d239153c17873a0428" source="CONFIRM">https://github.com/torvalds/linux/commit/802f43594d6e4d2ac61086d239153c17873a0428</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=782696" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=782696</ref>
      <ref url="http://www.securitytracker.com/id?1027085" source="SECTRACK">1027085</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/18/7" source="MLIST">[oss-security] 20120117 Re: CVE request: kernel: Unused iocbs in a batch should not be accounted as active</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.2" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="1.2.0"/>
        <vers num="1.3.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.2"/>
        <vers num="2.0.20"/>
        <vers num="2.0.21"/>
        <vers num="2.0.22"/>
        <vers num="2.0.23"/>
        <vers num="2.0.24"/>
        <vers num="2.0.25"/>
        <vers num="2.0.26"/>
        <vers num="2.0.27"/>
        <vers num="2.0.28"/>
        <vers num="2.0.29"/>
        <vers num="2.0.3"/>
        <vers num="2.0.30"/>
        <vers num="2.0.31"/>
        <vers num="2.0.32"/>
        <vers num="2.0.33"/>
        <vers num="2.0.34"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1.132"/>
        <vers num="2.1.89"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13" edition="pre15"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15" edition="pre16"/>
        <vers num="2.2.16" edition="pre5"/>
        <vers num="2.2.16" edition="pre6"/>
        <vers num="2.2.17" edition="pre14"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.2"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21" edition="pre1"/>
        <vers num="2.2.21" edition="pre2"/>
        <vers num="2.2.21" edition="pre3"/>
        <vers num="2.2.21" edition="pre4"/>
        <vers num="2.2.21" edition="rc1"/>
        <vers num="2.2.21" edition="rc2"/>
        <vers num="2.2.21" edition="rc3"/>
        <vers num="2.2.21" edition="rc4"/>
        <vers num="2.2.22" edition="rc1"/>
        <vers num="2.2.22" edition="rc2"/>
        <vers num="2.2.22" edition="rc3"/>
        <vers num="2.2.23" edition="rc1"/>
        <vers num="2.2.23" edition="rc2"/>
        <vers num="2.2.24" edition="rc2"/>
        <vers num="2.2.24" edition="rc3"/>
        <vers num="2.2.24" edition="rc4"/>
        <vers num="2.2.24" edition="rc5"/>
        <vers num="2.2.25"/>
        <vers num="2.2.26"/>
        <vers num="2.2.27" edition="pre1"/>
        <vers num="2.2.27" edition="pre2"/>
        <vers num="2.2.27" edition="rc1"/>
        <vers num="2.2.27" edition="rc2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4" edition="rc1"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.3.15"/>
        <vers num="2.3.16"/>
        <vers num="2.3.17"/>
        <vers num="2.3.18"/>
        <vers num="2.3.19"/>
        <vers num="2.3.2"/>
        <vers num="2.3.20"/>
        <vers num="2.3.21"/>
        <vers num="2.3.22"/>
        <vers num="2.3.23"/>
        <vers num="2.3.24"/>
        <vers num="2.3.25"/>
        <vers num="2.3.26"/>
        <vers num="2.3.27"/>
        <vers num="2.3.28"/>
        <vers num="2.3.29"/>
        <vers num="2.3.3"/>
        <vers num="2.3.30"/>
        <vers num="2.3.31"/>
        <vers num="2.3.32"/>
        <vers num="2.3.33"/>
        <vers num="2.3.34"/>
        <vers num="2.3.35"/>
        <vers num="2.3.36"/>
        <vers num="2.3.37"/>
        <vers num="2.3.38"/>
        <vers num="2.3.39"/>
        <vers num="2.3.4"/>
        <vers num="2.3.40"/>
        <vers num="2.3.41"/>
        <vers num="2.3.42"/>
        <vers num="2.3.43"/>
        <vers num="2.3.44"/>
        <vers num="2.3.45"/>
        <vers num="2.3.46"/>
        <vers num="2.3.47"/>
        <vers num="2.3.48"/>
        <vers num="2.3.49"/>
        <vers num="2.3.5"/>
        <vers num="2.3.50"/>
        <vers num="2.3.51"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.3.99" edition="pre1"/>
        <vers num="2.3.99" edition="pre2"/>
        <vers num="2.3.99" edition="pre3"/>
        <vers num="2.3.99" edition="pre4"/>
        <vers num="2.3.99" edition="pre5"/>
        <vers num="2.3.99" edition="pre6"/>
        <vers num="2.3.99" edition="pre7"/>
        <vers num="2.3.99" edition="pre8"/>
        <vers num="2.3.99" edition="pre9"/>
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11" edition="pre3"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.18" edition="pre9"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22" edition="pre10"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.24"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27" edition="pre1"/>
        <vers num="2.4.27" edition="pre2"/>
        <vers num="2.4.27" edition="pre3"/>
        <vers num="2.4.27" edition="pre4"/>
        <vers num="2.4.27" edition="pre5"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29" edition="rc1"/>
        <vers num="2.4.29" edition="rc2"/>
        <vers num="2.4.3" edition="pre3"/>
        <vers num="2.4.30" edition="rc2"/>
        <vers num="2.4.30" edition="rc3"/>
        <vers num="2.4.31" edition="pre1"/>
        <vers num="2.4.32" edition="pre1"/>
        <vers num="2.4.32" edition="pre2"/>
        <vers num="2.4.33" edition="pre1"/>
        <vers num="2.4.33.2"/>
        <vers num="2.4.33.3"/>
        <vers num="2.4.33.4"/>
        <vers num="2.4.33.5"/>
        <vers num="2.4.34" edition="rc3"/>
        <vers num="2.4.34.1"/>
        <vers num="2.4.34.2"/>
        <vers num="2.4.35"/>
        <vers num="2.4.35.2"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
        <vers num="2.5.14"/>
        <vers num="2.5.15"/>
        <vers num="2.5.16"/>
        <vers num="2.5.17"/>
        <vers num="2.5.18"/>
        <vers num="2.5.19"/>
        <vers num="2.5.2"/>
        <vers num="2.5.20"/>
        <vers num="2.5.21"/>
        <vers num="2.5.22"/>
        <vers num="2.5.23"/>
        <vers num="2.5.24"/>
        <vers num="2.5.25"/>
        <vers num="2.5.26"/>
        <vers num="2.5.27"/>
        <vers num="2.5.28"/>
        <vers num="2.5.29"/>
        <vers num="2.5.3"/>
        <vers num="2.5.30"/>
        <vers num="2.5.31"/>
        <vers num="2.5.32"/>
        <vers num="2.5.33"/>
        <vers num="2.5.34"/>
        <vers num="2.5.35"/>
        <vers num="2.5.36"/>
        <vers num="2.5.37"/>
        <vers num="2.5.38"/>
        <vers num="2.5.39"/>
        <vers num="2.5.4"/>
        <vers num="2.5.40"/>
        <vers num="2.5.41"/>
        <vers num="2.5.42"/>
        <vers num="2.5.43"/>
        <vers num="2.5.44"/>
        <vers num="2.5.45"/>
        <vers num="2.5.46"/>
        <vers num="2.5.47"/>
        <vers num="2.5.48"/>
        <vers num="2.5.49"/>
        <vers num="2.5.5"/>
        <vers num="2.5.50"/>
        <vers num="2.5.51"/>
        <vers num="2.5.52"/>
        <vers num="2.5.53"/>
        <vers num="2.5.54"/>
        <vers num="2.5.55"/>
        <vers num="2.5.56"/>
        <vers num="2.5.57"/>
        <vers num="2.5.58"/>
        <vers num="2.5.59"/>
        <vers num="2.5.6"/>
        <vers num="2.5.60"/>
        <vers num="2.5.61"/>
        <vers num="2.5.62"/>
        <vers num="2.5.63"/>
        <vers num="2.5.64"/>
        <vers num="2.5.65"/>
        <vers num="2.5.66"/>
        <vers num="2.5.67"/>
        <vers num="2.5.68"/>
        <vers num="2.5.69"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.1" edition="rc3"/>
        <vers num="2.6.10" edition="rc1"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.10" edition="rc3"/>
        <vers num="2.6.11" edition="rc1"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
        <vers num="2.6.11" edition="rc4"/>
        <vers num="2.6.11" edition="rc5"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.10"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.11.9"/>
        <vers num="2.6.12" edition="rc1"/>
        <vers num="2.6.12" edition="rc2"/>
        <vers num="2.6.12" edition="rc3"/>
        <vers num="2.6.12" edition="rc4"/>
        <vers num="2.6.12" edition="rc5"/>
        <vers num="2.6.12" edition="rc6"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13" edition="rc1"/>
        <vers num="2.6.13" edition="rc2"/>
        <vers num="2.6.13" edition="rc3"/>
        <vers num="2.6.13" edition="rc4"/>
        <vers num="2.6.13" edition="rc5"/>
        <vers num="2.6.13" edition="rc6"/>
        <vers num="2.6.13" edition="rc7"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.13.5"/>
        <vers num="2.6.14" edition="rc1"/>
        <vers num="2.6.14" edition="rc2"/>
        <vers num="2.6.14" edition="rc3"/>
        <vers num="2.6.14" edition="rc4"/>
        <vers num="2.6.14" edition="rc5"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.14.5"/>
        <vers num="2.6.14.6"/>
        <vers num="2.6.14.7"/>
        <vers num="2.6.15" edition="rc1"/>
        <vers num="2.6.15" edition="rc2"/>
        <vers num="2.6.15" edition="rc3"/>
        <vers num="2.6.15" edition="rc4"/>
        <vers num="2.6.15" edition="rc5"/>
        <vers num="2.6.15" edition="rc6"/>
        <vers num="2.6.15" edition="rc7"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.10"/>
        <vers num="2.6.15.11"/>
        <vers num="2.6.15.2"/>
        <vers num="2.6.15.3"/>
        <vers num="2.6.15.4"/>
        <vers num="2.6.15.5"/>
        <vers num="2.6.15.6"/>
        <vers num="2.6.15.7"/>
        <vers num="2.6.15.8"/>
        <vers num="2.6.15.9"/>
        <vers num="2.6.16" edition="rc1"/>
        <vers num="2.6.16" edition="rc2"/>
        <vers num="2.6.16" edition="rc3"/>
        <vers num="2.6.16" edition="rc4"/>
        <vers num="2.6.16" edition="rc5"/>
        <vers num="2.6.16" edition="rc6"/>
        <vers num="2.6.16" edition="rc7"/>
        <vers num="2.6.16.1"/>
        <vers num="2.6.16.10"/>
        <vers num="2.6.16.11"/>
        <vers num="2.6.16.12"/>
        <vers num="2.6.16.13"/>
        <vers num="2.6.16.14"/>
        <vers num="2.6.16.15"/>
        <vers num="2.6.16.16"/>
        <vers num="2.6.16.17"/>
        <vers num="2.6.16.18"/>
        <vers num="2.6.16.19"/>
        <vers num="2.6.16.2"/>
        <vers num="2.6.16.20"/>
        <vers num="2.6.16.21"/>
        <vers num="2.6.16.22"/>
        <vers num="2.6.16.23"/>
        <vers num="2.6.16.24"/>
        <vers num="2.6.16.25"/>
        <vers num="2.6.16.26"/>
        <vers num="2.6.16.27"/>
        <vers num="2.6.16.28"/>
        <vers num="2.6.16.29"/>
        <vers num="2.6.16.3"/>
        <vers num="2.6.16.30"/>
        <vers num="2.6.16.31"/>
        <vers num="2.6.16.32"/>
        <vers num="2.6.16.33"/>
        <vers num="2.6.16.34"/>
        <vers num="2.6.16.35"/>
        <vers num="2.6.16.36"/>
        <vers num="2.6.16.37"/>
        <vers num="2.6.16.38"/>
        <vers num="2.6.16.39"/>
        <vers num="2.6.16.4"/>
        <vers num="2.6.16.40"/>
        <vers num="2.6.16.41"/>
        <vers num="2.6.16.42"/>
        <vers num="2.6.16.43"/>
        <vers num="2.6.16.44"/>
        <vers num="2.6.16.45"/>
        <vers num="2.6.16.46"/>
        <vers num="2.6.16.47"/>
        <vers num="2.6.16.48"/>
        <vers num="2.6.16.49"/>
        <vers num="2.6.16.5"/>
        <vers num="2.6.16.50"/>
        <vers num="2.6.16.51"/>
        <vers num="2.6.16.52"/>
        <vers num="2.6.16.53"/>
        <vers num="2.6.16.54"/>
        <vers num="2.6.16.55"/>
        <vers num="2.6.16.56"/>
        <vers num="2.6.16.57"/>
        <vers num="2.6.16.58"/>
        <vers num="2.6.16.59"/>
        <vers num="2.6.16.6"/>
        <vers num="2.6.16.60"/>
        <vers num="2.6.16.61"/>
        <vers num="2.6.16.62"/>
        <vers num="2.6.16.7"/>
        <vers num="2.6.16.8"/>
        <vers num="2.6.16.9"/>
        <vers num="2.6.17" edition="rc1"/>
        <vers num="2.6.17" edition="rc2"/>
        <vers num="2.6.17" edition="rc3"/>
        <vers num="2.6.17" edition="rc4"/>
        <vers num="2.6.17" edition="rc5"/>
        <vers num="2.6.17" edition="rc6"/>
        <vers num="2.6.17.1"/>
        <vers num="2.6.17.10"/>
        <vers num="2.6.17.11"/>
        <vers num="2.6.17.12"/>
        <vers num="2.6.17.13"/>
        <vers num="2.6.17.14"/>
        <vers num="2.6.17.2"/>
        <vers num="2.6.17.3"/>
        <vers num="2.6.17.4"/>
        <vers num="2.6.17.5"/>
        <vers num="2.6.17.6"/>
        <vers num="2.6.17.7"/>
        <vers num="2.6.17.8"/>
        <vers num="2.6.17.9"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.18.1"/>
        <vers num="2.6.18.2"/>
        <vers num="2.6.18.3"/>
        <vers num="2.6.18.4"/>
        <vers num="2.6.18.5"/>
        <vers num="2.6.18.6"/>
        <vers num="2.6.18.7"/>
        <vers num="2.6.18.8"/>
        <vers num="2.6.19" edition="rc1"/>
        <vers num="2.6.19" edition="rc2"/>
        <vers num="2.6.19" edition="rc3"/>
        <vers num="2.6.19" edition="rc4"/>
        <vers num="2.6.19.1"/>
        <vers num="2.6.19.2"/>
        <vers num="2.6.19.3"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.2" edition="rc1"/>
        <vers num="2.6.2" edition="rc2"/>
        <vers num="2.6.2" edition="rc3"/>
        <vers num="2.6.20" edition="rc2"/>
        <vers num="2.6.20.1"/>
        <vers num="2.6.20.10"/>
        <vers num="2.6.20.11"/>
        <vers num="2.6.20.12"/>
        <vers num="2.6.20.13"/>
        <vers num="2.6.20.14"/>
        <vers num="2.6.20.15"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.2"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.20.3"/>
        <vers num="2.6.20.4"/>
        <vers num="2.6.20.5"/>
        <vers num="2.6.20.6"/>
        <vers num="2.6.20.7"/>
        <vers num="2.6.20.8"/>
        <vers num="2.6.20.9"/>
        <vers num="2.6.21" edition="git1"/>
        <vers num="2.6.21" edition="git2"/>
        <vers num="2.6.21" edition="git3"/>
        <vers num="2.6.21" edition="git4"/>
        <vers num="2.6.21" edition="git5"/>
        <vers num="2.6.21" edition="git6"/>
        <vers num="2.6.21" edition="git7"/>
        <vers num="2.6.21" edition="rc3"/>
        <vers num="2.6.21" edition="rc4"/>
        <vers num="2.6.21" edition="rc5"/>
        <vers num="2.6.21" edition="rc6"/>
        <vers num="2.6.21" edition="rc7"/>
        <vers num="2.6.21.1"/>
        <vers num="2.6.21.2"/>
        <vers num="2.6.21.3"/>
        <vers num="2.6.21.4"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers num="2.6.22.15"/>
        <vers num="2.6.22.16"/>
        <vers num="2.6.22.17"/>
        <vers num="2.6.22.18"/>
        <vers num="2.6.22.19"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.20"/>
        <vers num="2.6.22.3"/>
        <vers num="2.6.22.4"/>
        <vers num="2.6.22.5"/>
        <vers num="2.6.22.6"/>
        <vers num="2.6.22.7"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.27.41"/>
        <vers num="2.6.27.42"/>
        <vers num="2.6.27.43"/>
        <vers num="2.6.27.44"/>
        <vers num="2.6.27.45"/>
        <vers num="2.6.27.46"/>
        <vers num="2.6.27.47"/>
        <vers num="2.6.27.48"/>
        <vers num="2.6.27.49"/>
        <vers num="2.6.27.5"/>
        <vers num="2.6.27.50"/>
        <vers num="2.6.27.51"/>
        <vers num="2.6.27.52"/>
        <vers num="2.6.27.53"/>
        <vers num="2.6.27.54"/>
        <vers num="2.6.27.55"/>
        <vers num="2.6.27.56"/>
        <vers num="2.6.27.57"/>
        <vers num="2.6.27.58"/>
        <vers num="2.6.27.59"/>
        <vers num="2.6.27.6"/>
        <vers num="2.6.27.60"/>
        <vers num="2.6.27.61"/>
        <vers num="2.6.27.62"/>
        <vers num="2.6.27.7"/>
        <vers num="2.6.27.8"/>
        <vers num="2.6.27.9"/>
        <vers num="2.6.28"/>
        <vers num="2.6.28.1"/>
        <vers num="2.6.28.10"/>
        <vers num="2.6.28.2"/>
        <vers num="2.6.28.3"/>
        <vers num="2.6.28.4"/>
        <vers num="2.6.28.5"/>
        <vers num="2.6.28.6"/>
        <vers num="2.6.28.7"/>
        <vers num="2.6.28.8"/>
        <vers num="2.6.28.9"/>
        <vers num="2.6.29"/>
        <vers num="2.6.29.1"/>
        <vers num="2.6.29.2"/>
        <vers num="2.6.29.3"/>
        <vers num="2.6.29.4"/>
        <vers num="2.6.29.5"/>
        <vers num="2.6.29.6"/>
        <vers num="2.6.3" edition="rc1"/>
        <vers num="2.6.3" edition="rc2"/>
        <vers num="2.6.3" edition="rc3"/>
        <vers num="2.6.3" edition="rc4"/>
        <vers num="2.6.32"/>
        <vers num="2.6.32.1"/>
        <vers num="2.6.32.10"/>
        <vers num="2.6.32.11"/>
        <vers num="2.6.32.12"/>
        <vers num="2.6.32.13"/>
        <vers num="2.6.32.14"/>
        <vers num="2.6.32.15"/>
        <vers num="2.6.32.16"/>
        <vers num="2.6.32.17"/>
        <vers num="2.6.32.18"/>
        <vers num="2.6.32.2"/>
        <vers num="2.6.32.28"/>
        <vers num="2.6.32.29"/>
        <vers num="2.6.32.3"/>
        <vers num="2.6.32.30"/>
        <vers num="2.6.32.31"/>
        <vers num="2.6.32.32"/>
        <vers num="2.6.32.33"/>
        <vers num="2.6.32.34"/>
        <vers num="2.6.32.35"/>
        <vers num="2.6.32.36"/>
        <vers num="2.6.32.37"/>
        <vers num="2.6.32.38"/>
        <vers num="2.6.32.39"/>
        <vers num="2.6.32.4"/>
        <vers num="2.6.32.40"/>
        <vers num="2.6.32.41"/>
        <vers num="2.6.32.42"/>
        <vers num="2.6.32.43"/>
        <vers num="2.6.32.44"/>
        <vers num="2.6.32.45"/>
        <vers num="2.6.32.46"/>
        <vers num="2.6.32.47"/>
        <vers num="2.6.32.48"/>
        <vers num="2.6.32.49"/>
        <vers num="2.6.32.5"/>
        <vers num="2.6.32.50"/>
        <vers num="2.6.32.51"/>
        <vers num="2.6.32.52"/>
        <vers num="2.6.32.53"/>
        <vers num="2.6.32.54"/>
        <vers num="2.6.32.55"/>
        <vers num="2.6.32.56"/>
        <vers num="2.6.32.57"/>
        <vers num="2.6.32.58"/>
        <vers num="2.6.32.6"/>
        <vers num="2.6.32.7"/>
        <vers num="2.6.32.8"/>
        <vers num="2.6.32.9"/>
        <vers num="2.6.33.10"/>
        <vers num="2.6.33.11"/>
        <vers num="2.6.33.12"/>
        <vers num="2.6.33.13"/>
        <vers num="2.6.33.14"/>
        <vers num="2.6.33.15"/>
        <vers num="2.6.33.16"/>
        <vers num="2.6.33.17"/>
        <vers num="2.6.33.18"/>
        <vers num="2.6.33.19"/>
        <vers num="2.6.33.20"/>
        <vers num="2.6.33.8"/>
        <vers num="2.6.33.9"/>
        <vers num="2.6.34.1"/>
        <vers num="2.6.34.10"/>
        <vers num="2.6.34.2"/>
        <vers num="2.6.34.3"/>
        <vers num="2.6.34.8"/>
        <vers num="2.6.34.9"/>
        <vers num="2.6.35.1"/>
        <vers num="2.6.35.10"/>
        <vers num="2.6.35.11"/>
        <vers num="2.6.35.12"/>
        <vers num="2.6.35.13"/>
        <vers num="2.6.37" edition="rc1"/>
        <vers num="2.6.37" edition="rc2"/>
        <vers num="2.6.37" edition="rc3"/>
        <vers num="2.6.37" edition="rc4"/>
        <vers num="2.6.37" edition="rc5"/>
        <vers num="2.6.38" edition="rc1"/>
        <vers num="2.6.38" edition="rc2"/>
        <vers num="2.6.38" edition="rc3"/>
        <vers num="2.6.38" edition="rc4"/>
        <vers num="2.6.38" edition="rc5"/>
        <vers num="2.6.38" edition="rc6"/>
        <vers num="2.6.38" edition="rc7"/>
        <vers num="2.6.38" edition="rc8"/>
        <vers num="2.6.39" edition="rc1"/>
        <vers num="2.6.39" edition="rc2"/>
        <vers num="2.6.39" edition="rc3"/>
        <vers num="2.6.39" edition="rc4"/>
        <vers num="2.6.39" edition="rc5"/>
        <vers num="2.6.39" edition="rc6"/>
        <vers num="2.6.39" edition="rc7"/>
        <vers num="2.6.4" edition="rc1"/>
        <vers num="2.6.4" edition="rc2"/>
        <vers num="2.6.4" edition="rc3"/>
        <vers num="2.6.5" edition="rc1"/>
        <vers num="2.6.5" edition="rc2"/>
        <vers num="2.6.5" edition="rc3"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.6" edition="rc2"/>
        <vers num="2.6.6" edition="rc3"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.7" edition="rc2"/>
        <vers num="2.6.7" edition="rc3"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.8" edition="rc4"/>
        <vers num="2.6.8.1"/>
        <vers num="2.6.9" edition="rc1"/>
        <vers num="2.6.9" edition="rc2"/>
        <vers num="2.6.9" edition="rc3"/>
        <vers num="2.6.9" edition="rc4"/>
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers prev="1" num="3.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0060" published="2012-06-04" name="CVE-2012-0060" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://hermes.opensuse.org/messages/14441362" source="SUSE">openSUSE-SU-2012:0589</ref>
      <ref url="https://hermes.opensuse.org/messages/14440932" source="SUSE">openSUSE-SU-2012:0588</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=744858" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=744858</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74582" source="XF">rpm-loadsigverify-code-execution(74582)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1695-1" source="UBUNTU">USN-1695-1</ref>
      <ref url="http://www.securitytracker.com/id?1026882" source="SECTRACK">1026882</ref>
      <ref url="http://www.securityfocus.com/bid/52865" source="BID">52865</ref>
      <ref url="http://www.osvdb.org/81010" source="OSVDB">81010</ref>
      <ref url="http://secunia.com/advisories/49110" source="SECUNIA" adv="1">49110</ref>
      <ref url="http://secunia.com/advisories/48716" source="SECUNIA" adv="1">48716</ref>
      <ref url="http://secunia.com/advisories/48651" source="SECUNIA" adv="1">48651</ref>
      <ref url="http://rpm.org/wiki/Releases/4.9.1.3" source="CONFIRM">http://rpm.org/wiki/Releases/4.9.1.3</ref>
      <ref url="http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=f23998251992b8ae25faf5113c42fee2c49c7f29" source="CONFIRM">http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=f23998251992b8ae25faf5113c42fee2c49c7f29</ref>
      <ref url="http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=e4eab2bc6d07cfd33f740071de7ddbb2fe2f4190" source="CONFIRM">http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=e4eab2bc6d07cfd33f740071de7ddbb2fe2f4190</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0531.html" source="REDHAT">RHSA-2012:0531</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0451.html" source="REDHAT">RHSA-2012:0451</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078907.html" source="FEDORA">FEDORA-2012-5421</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078819.html" source="FEDORA">FEDORA-2012-5420</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077960.html" source="FEDORA">FEDORA-2012-5298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rpm" name="rpm">
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.2/a"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.3.10"/>
        <vers num="2.2.3.11"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.5"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.6.7"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="4.0."/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.3.3"/>
        <vers num="4.4.2.1"/>
        <vers num="4.4.2.2"/>
        <vers num="4.4.2.3"/>
        <vers num="4.5.90"/>
        <vers num="4.6.0" edition="rc1"/>
        <vers num="4.6.0" edition="rc2"/>
        <vers num="4.6.0" edition="rc3"/>
        <vers num="4.6.0" edition="rc4"/>
        <vers num="4.6.1"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.8.1"/>
        <vers num="4.9.0" edition="alpha"/>
        <vers num="4.9.0" edition="beta1"/>
        <vers num="4.9.0" edition="rc1"/>
        <vers num="4.9.1"/>
        <vers num="4.9.1.1"/>
        <vers prev="1" num="4.9.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0061" published="2012-06-04" name="CVE-2012-0061" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=858a328cd0f7d4bcd8500c78faaf00e4f8033df6" source="CONFIRM" patch="1">http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=858a328cd0f7d4bcd8500c78faaf00e4f8033df6</ref>
      <ref url="http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=472e569562d4c90d7a298080e0052856aa7fa86b" source="CONFIRM" patch="1">http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=472e569562d4c90d7a298080e0052856aa7fa86b</ref>
      <ref url="https://hermes.opensuse.org/messages/14441362" source="SUSE">openSUSE-SU-2012:0589</ref>
      <ref url="https://hermes.opensuse.org/messages/14440932" source="SUSE">openSUSE-SU-2012:0588</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=798585" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=798585</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74583" source="XF">rpm-headerload-code-execution(74583)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1695-1" source="UBUNTU">USN-1695-1</ref>
      <ref url="http://www.securitytracker.com/id?1026882" source="SECTRACK">1026882</ref>
      <ref url="http://www.securityfocus.com/bid/52865" source="BID">52865</ref>
      <ref url="http://www.osvdb.org/81010" source="OSVDB">81010</ref>
      <ref url="http://secunia.com/advisories/49110" source="SECUNIA" adv="1">49110</ref>
      <ref url="http://secunia.com/advisories/48716" source="SECUNIA" adv="1">48716</ref>
      <ref url="http://secunia.com/advisories/48651" source="SECUNIA" adv="1">48651</ref>
      <ref url="http://rpm.org/wiki/Releases/4.9.1.3" source="CONFIRM">http://rpm.org/wiki/Releases/4.9.1.3</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0531.html" source="REDHAT">RHSA-2012:0531</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0451.html" source="REDHAT">RHSA-2012:0451</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078907.html" source="FEDORA">FEDORA-2012-5421</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078819.html" source="FEDORA">FEDORA-2012-5420</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077960.html" source="FEDORA">FEDORA-2012-5298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rpm" name="rpm">
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.2/a"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.3.10"/>
        <vers num="2.2.3.11"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.5"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.6.7"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="4.0."/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.1"/>
        <vers num="4.3.3"/>
        <vers num="4.4.2.1"/>
        <vers num="4.4.2.2"/>
        <vers num="4.4.2.3"/>
        <vers num="4.5.90"/>
        <vers num="4.6.0" edition="rc1"/>
        <vers num="4.6.0" edition="rc2"/>
        <vers num="4.6.0" edition="rc3"/>
        <vers num="4.6.0" edition="rc4"/>
        <vers num="4.6.1"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.8.1"/>
        <vers num="4.9.0" edition="alpha"/>
        <vers num="4.9.0" edition="beta1"/>
        <vers num="4.9.0" edition="rc1"/>
        <vers num="4.9.1"/>
        <vers num="4.9.1.1"/>
        <vers prev="1" num="4.9.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0065" published="2012-10-06" name="CVE-2012-0065" modified="2013-04-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the receive_packet function in libusbmuxd/libusbmuxd.c in usbmuxd 1.0.5 through 1.0.7 allows physically proximate attackers to execute arbitrary code via a long SerialNumber field in a property list.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://openwall.com/lists/oss-security/2012/01/19/25" source="MLIST" patch="1">[oss-security] 20120119 CVE request: usbmuxd 1.0.7 </ref>
      <ref url="http://git.marcansoft.com/?p=usbmuxd.git;a=commitdiff;h=f794991993af56a74795891b4ff9da506bc893e6" source="CONFIRM" patch="1">http://git.marcansoft.com/?p=usbmuxd.git;a=commitdiff;h=f794991993af56a74795891b4ff9da506bc893e6</ref>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=399409" source="MISC">https://bugs.gentoo.org/show_bug.cgi?id=399409</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/72546" source="XF">usbmuxd-libusbmuxd-bo(72546)</ref>
      <ref url="http://www.securityfocus.com/bid/51573" source="BID">51573</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2012:133" source="MANDRIVA">MDVSA-2012:133</ref>
      <ref url="http://secunia.com/advisories/47545" source="SECUNIA" adv="1">47545</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/01/19/26" source="MLIST">[oss-security] 20120119 Re: CVE request: usbmuxd 1.0.7 </ref>
    </refs>
    <vuln_soft>
      <prod vendor="nikias_bassen" name="usbmuxd">
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0066" published="2012-04-11" name="CVE-2012-0066" modified="2013-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a (1) Accellent 5Views (aka .5vw) file, (2) I4B trace file, or (3) NETMON 2 capture file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/20/4" source="MLIST" patch="1">[oss-security] 20120119 Re: CVE request: Wireshark multiple vulnerabilities</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40166" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40166</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40165" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40165</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6669" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6669</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6667" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6667</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6666" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6666</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2012-01.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2012-01.html</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/11/7" source="MLIST">[oss-security] 20120111 Re: CVE request: Wireshark multiple vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/48947" source="SECUNIA">48947</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0125.html" source="REDHAT">RHSA-2013:0125</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15111" source="OVAL">oval:org.mitre.oval:def:15111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.10"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0067" published="2012-04-11" name="CVE-2012-0067" modified="2013-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in an AIX iptrace file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6668" source="CONFIRM" patch="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6668</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40167" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40167</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2012-01.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2012-01.html</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/20/4" source="MLIST">[oss-security] 20120119 Re: CVE request: Wireshark multiple vulnerabilities</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/11/7" source="MLIST">[oss-security] 20120111 Re: CVE request: Wireshark multiple vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/48947" source="SECUNIA">48947</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0125.html" source="REDHAT">RHSA-2013:0125</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15192" source="OVAL">oval:org.mitre.oval:def:15192</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.10"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0068" published="2012-04-11" name="CVE-2012-0068" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a Novell catpure file containing a record that is too small.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6670" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6670</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2012-01.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2012-01.html</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/20/4" source="MLIST">[oss-security] 20120119 Re: CVE request: Wireshark multiple vulnerabilities</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/11/7" source="MLIST">[oss-security] 20120111 Re: CVE request: Wireshark multiple vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15379" source="OVAL">oval:org.mitre.oval:def:15379</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40169" source="CONFIRM">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=40169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.10"/>
        <vers num="1.4.11"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0069" published="2012-01-24" name="CVE-2012-0069" modified="2012-01-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ajax.php in Batavi before 1.2.1 allows remote attackers to execute arbitrary SQL commands via the boxToReload parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72449" source="XF">batavi-ajax-sql-injection(72449)</ref>
      <ref url="http://www.securityfocus.com/bid/51547" source="BID">51547</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/20/6" source="MLIST">[oss-security] 20120119 Re: CVE request - Batavi 1.2.1 Fixes Blind SQL Injection</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/18/9" source="MLIST">[oss-security] 20120118 CVE request - Batavi 1.2.1 Fixes Blind SQL Injection vulnerability in boxToReload parameter of ajax.php</ref>
      <ref url="http://voxel.dl.sourceforge.net/project/batavi/README.txt" source="CONFIRM">http://voxel.dl.sourceforge.net/project/batavi/README.txt</ref>
      <ref url="http://secunia.com/advisories/47582" source="SECUNIA" adv="1">47582</ref>
      <ref url="http://osvdb.org/78362" source="OSVDB">78362</ref>
    </refs>
    <vuln_soft>
      <prod vendor="batavi" name="batavi">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.4"/>
        <vers prev="1" num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0071" published="2012-10-16" name="CVE-2012-0071" modified="2012-10-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote attackers to affect integrity via unknown vectors related to Web.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.3.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0072" published="2012-01-18" name="CVE-2012-0072" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Listener component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.2 allows remote attackers to affect availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72469" source="XF">databaseserver-listener-dos(72469)</ref>
      <ref url="http://www.securitytracker.com/id?1026527" source="SECTRACK">1026527</ref>
      <ref url="http://www.securityfocus.com/bid/51458" source="BID">51458</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78419" source="OSVDB">78419</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.3"/>
        <vers num="10.2.0.4"/>
        <vers num="10.2.0.5"/>
        <vers num="11.1.0.7"/>
        <vers num="11.2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0073" published="2012-01-18" name="CVE-2012-0073" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Forms component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72478" source="XF">ebusiness-forms-cve20120073(72478)</ref>
      <ref url="http://www.securityfocus.com/bid/51473" source="BID">51473</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78439" source="OSVDB">78439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0074" published="2012-01-18" name="CVE-2012-0074" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft Enterprise CRM component in Oracle PeopleSoft Products 8.9 allows remote authenticated users to affect integrity via unknown vectors related to Sales.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72482" source="XF">peoplesoft-enterprisecrm-cve20120074(72482)</ref>
      <ref url="http://www.securityfocus.com/bid/51472" source="BID">51472</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://secunia.com/advisories/47621" source="SECUNIA">47621</ref>
      <ref url="http://osvdb.org/78441" source="OSVDB">78441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="8.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0075" published="2012-01-18" name="CVE-2012-0075" modified="2012-10-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:M/C:N/I:P/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.2" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72539" source="XF">mysql-server-cve20120075(72539)</ref>
      <ref url="http://www.securityfocus.com/bid/51526" source="BID">51526</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78374" source="OSVDB">78374</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00007.html" source="SUSE">SUSE-SU-2012:0984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0"/>
        <vers num="5.0.0" edition="alpha"/>
        <vers num="5.0.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.10"/>
        <vers num="5.0.10a"/>
        <vers num="5.0.11"/>
        <vers num="5.0.12"/>
        <vers num="5.0.13"/>
        <vers num="5.0.14"/>
        <vers num="5.0.15"/>
        <vers num="5.0.15a"/>
        <vers num="5.0.16"/>
        <vers num="5.0.16a"/>
        <vers num="5.0.17"/>
        <vers num="5.0.17a"/>
        <vers num="5.0.18"/>
        <vers num="5.0.19"/>
        <vers num="5.0.1a"/>
        <vers num="5.0.2"/>
        <vers num="5.0.20"/>
        <vers num="5.0.20a"/>
        <vers num="5.0.21"/>
        <vers num="5.0.22"/>
        <vers num="5.0.22.1.0.1"/>
        <vers num="5.0.23"/>
        <vers num="5.0.24"/>
        <vers num="5.0.24a"/>
        <vers num="5.0.25"/>
        <vers num="5.0.26"/>
        <vers num="5.0.27"/>
        <vers num="5.0.3" edition="beta"/>
        <vers num="5.0.30" edition="sp1"/>
        <vers num="5.0.32"/>
        <vers num="5.0.33"/>
        <vers num="5.0.36"/>
        <vers num="5.0.37"/>
        <vers num="5.0.38"/>
        <vers num="5.0.3a"/>
        <vers num="5.0.4"/>
        <vers num="5.0.41"/>
        <vers num="5.0.42"/>
        <vers num="5.0.44"/>
        <vers num="5.0.45" edition="b"/>
        <vers num="5.0.45b"/>
        <vers num="5.0.4a"/>
        <vers num="5.0.5"/>
        <vers num="5.0.5.0.21"/>
        <vers num="5.0.50"/>
        <vers num="5.0.51"/>
        <vers num="5.0.51a"/>
        <vers num="5.0.51b"/>
        <vers num="5.0.52"/>
        <vers num="5.0.54"/>
        <vers num="5.0.56"/>
        <vers num="5.0.6"/>
        <vers num="5.0.60"/>
        <vers num="5.0.66"/>
        <vers num="5.0.67"/>
        <vers num="5.0.7"/>
        <vers num="5.0.75"/>
        <vers num="5.0.77"/>
        <vers num="5.0.8"/>
        <vers num="5.0.81"/>
        <vers num="5.0.82"/>
        <vers num="5.0.83"/>
        <vers num="5.0.84"/>
        <vers num="5.0.85"/>
        <vers num="5.0.86"/>
        <vers num="5.0.87"/>
        <vers num="5.0.88"/>
        <vers num="5.0.89"/>
        <vers num="5.0.9"/>
        <vers num="5.0.90"/>
        <vers num="5.0.91"/>
        <vers num="5.0.92"/>
        <vers num="5.0.93"/>
        <vers num="5.0.94"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.5.0"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0076" published="2012-01-18" name="CVE-2012-0076" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.0 and 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to ePerformance.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72484" source="XF">peoplesoft-enthcm-info-disc(72484)</ref>
      <ref url="http://www.securityfocus.com/bid/51474" source="BID">51474</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78395" source="OSVDB">78395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0077" published="2012-01-18" name="CVE-2012-0077" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4, 10.0.2, 10.3.3, 10.3.4, and 10.3.5 allows remote authenticated users to affect integrity, related to WLS-Console.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72477" source="XF">fusionmiddleware-weblogic-cve20120077(72477)</ref>
      <ref url="http://www.securityfocus.com/bid/51460" source="BID">51460</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78401" source="OSVDB">78401</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-000007.html" source="JVNDB">JVNDB-2012-000007</ref>
      <ref url="http://jvn.jp/en/jp/JVN54779201/index.html" source="JVN">JVN#54779201</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.0.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="9.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0078" published="2012-01-18" name="CVE-2012-0078" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.2 and 12.1.3 allows remote authenticated users to affect confidentiality, related to REST Services (Menu, LOV).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72479" source="XF">ebusiness-aol-info-disc(72479)</ref>
      <ref url="http://www.securityfocus.com/bid/51477" source="BID">51477</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://secunia.com/advisories/47628" source="SECUNIA">47628</ref>
      <ref url="http://osvdb.org/78399" source="OSVDB">78399</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0079" published="2012-01-18" name="CVE-2012-0079" modified="2012-11-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle OpenSSO 7.1 and 8.0 allows remote attackers to affect integrity via unknown vectors related to Administration.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72501" source="XF">sun-opensso-cve20120079(72501)</ref>
      <ref url="http://www.securitytracker.com/id?1026536" source="SECTRACK">1026536</ref>
      <ref url="http://www.securityfocus.com/bid/51492" source="BID">51492</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://secunia.com/advisories/50084" source="SECUNIA">50084</ref>
      <ref url="http://secunia.com/advisories/46646" source="SECUNIA" adv="1">46646</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1232.html" source="REDHAT">RHSA-2012:1232</ref>
      <ref url="http://osvdb.org/78412" source="OSVDB">78412</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="opensso">
        <vers num="7.1"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0080" published="2012-01-18" name="CVE-2012-0080" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Management.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72481" source="XF">peoplesoft-enterprisehcm-cve20120080(72481)</ref>
      <ref url="http://www.securityfocus.com/bid/51466" source="BID">51466</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0081" published="2012-01-18" name="CVE-2012-0081" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle GlassFish Enterprise Server 3.1.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Administration.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72503" source="XF">sun-glassfishenterpriseserver-cve20120081(72503)</ref>
      <ref url="http://www.securityfocus.com/bid/51485" source="BID">51485</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78415" source="OSVDB">78415</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="glassfish_server">
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0082" published="2012-01-18" name="CVE-2012-0082" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72468" source="XF">databaseserver-corerdbms-cve20120082(72468)</ref>
      <ref url="http://www.securitytracker.com/id?1026527" source="SECTRACK">1026527</ref>
      <ref url="http://www.securityfocus.com/bid/51453" source="BID">51453</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.3"/>
        <vers num="10.2.0.4"/>
        <vers num="10.2.0.5"/>
        <vers num="11.1.0.7"/>
        <vers num="11.2.0.2"/>
        <vers num="11.2.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0083" published="2012-01-18" name="CVE-2012-0083" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2, 10.1.3.5.1, 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Search.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72470" source="XF">fusionmiddleware-webcenter-cve20120083(72470)</ref>
      <ref url="http://www.securityfocus.com/bid/51451" source="BID">51451</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.3.5.1"/>
        <vers num="11.1.1.3.0"/>
        <vers num="11.1.1.4.0"/>
        <vers num="11.1.1.5.0"/>
        <vers num="7.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0084" published="2012-01-18" name="CVE-2012-0084" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2, 10.1.3.5.1, 11.1.1.3, 11.1.1.4, and 11.1.1.5 allows remote authenticated users to affect integrity via unknown vectors related to Content Server.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72476" source="XF">fusionmiddleware-webcenter-cve20120084(72476)</ref>
      <ref url="http://www.securityfocus.com/bid/51454" source="BID">51454</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.3.5.1"/>
        <vers num="11.1.1.3.0"/>
        <vers num="11.1.1.4.0"/>
        <vers num="11.1.1.5.0"/>
        <vers num="7.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0085" published="2012-01-18" name="CVE-2012-0085" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2 and 10.1.3.5.1 allows remote attackers to affect integrity via unknown vectors related to Content Server.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72475" source="XF">fusionmiddleware-webcenter-cve20120085(72475)</ref>
      <ref url="http://www.securityfocus.com/bid/51457" source="BID">51457</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.3.5.1"/>
        <vers num="7.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0086" published="2012-10-16" name="CVE-2012-0086" modified="2012-10-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Web.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.3.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0087" published="2012-01-18" name="CVE-2012-0087" modified="2012-10-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0101 and CVE-2012-0102.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72519" source="XF">mysql-serveruns-dos(72519)</ref>
      <ref url="http://www.securityfocus.com/bid/51509" source="BID">51509</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78377" source="OSVDB">78377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00007.html" source="SUSE">SUSE-SU-2012:0984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0"/>
        <vers num="5.0.0" edition="alpha"/>
        <vers num="5.0.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.10"/>
        <vers num="5.0.10a"/>
        <vers num="5.0.11"/>
        <vers num="5.0.12"/>
        <vers num="5.0.13"/>
        <vers num="5.0.14"/>
        <vers num="5.0.15"/>
        <vers num="5.0.15a"/>
        <vers num="5.0.16"/>
        <vers num="5.0.16a"/>
        <vers num="5.0.17"/>
        <vers num="5.0.17a"/>
        <vers num="5.0.18"/>
        <vers num="5.0.19"/>
        <vers num="5.0.1a"/>
        <vers num="5.0.2"/>
        <vers num="5.0.20"/>
        <vers num="5.0.20a"/>
        <vers num="5.0.21"/>
        <vers num="5.0.22"/>
        <vers num="5.0.22.1.0.1"/>
        <vers num="5.0.23"/>
        <vers num="5.0.24"/>
        <vers num="5.0.24a"/>
        <vers num="5.0.25"/>
        <vers num="5.0.26"/>
        <vers num="5.0.27"/>
        <vers num="5.0.3" edition="beta"/>
        <vers num="5.0.30" edition="sp1"/>
        <vers num="5.0.32"/>
        <vers num="5.0.33"/>
        <vers num="5.0.36"/>
        <vers num="5.0.37"/>
        <vers num="5.0.38"/>
        <vers num="5.0.3a"/>
        <vers num="5.0.4"/>
        <vers num="5.0.41"/>
        <vers num="5.0.42"/>
        <vers num="5.0.44"/>
        <vers num="5.0.45" edition="b"/>
        <vers num="5.0.45b"/>
        <vers num="5.0.4a"/>
        <vers num="5.0.5"/>
        <vers num="5.0.5.0.21"/>
        <vers num="5.0.50"/>
        <vers num="5.0.51"/>
        <vers num="5.0.51a"/>
        <vers num="5.0.51b"/>
        <vers num="5.0.52"/>
        <vers num="5.0.54"/>
        <vers num="5.0.56"/>
        <vers num="5.0.6"/>
        <vers num="5.0.60"/>
        <vers num="5.0.66"/>
        <vers num="5.0.67"/>
        <vers num="5.0.7"/>
        <vers num="5.0.75"/>
        <vers num="5.0.77"/>
        <vers num="5.0.8"/>
        <vers num="5.0.81"/>
        <vers num="5.0.82"/>
        <vers num="5.0.83"/>
        <vers num="5.0.84"/>
        <vers num="5.0.85"/>
        <vers num="5.0.86"/>
        <vers num="5.0.87"/>
        <vers num="5.0.88"/>
        <vers num="5.0.89"/>
        <vers num="5.0.9"/>
        <vers num="5.0.90"/>
        <vers num="5.0.91"/>
        <vers num="5.0.92"/>
        <vers num="5.0.93"/>
        <vers num="5.0.94"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0088" published="2012-01-18" name="CVE-2012-0088" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 8.9, 9.0, and 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Benefits Administration.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72483" source="XF">peoplesoft-enterprisehcm-info-disc(72483)</ref>
      <ref url="http://www.securityfocus.com/bid/51480" source="BID">51480</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78397" source="OSVDB">78397</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="8.9"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0089" published="2012-01-18" name="CVE-2012-0089" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to ePerformance.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72485" source="XF">peoplesoft-enterhcm-info-disc(72485)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0090" published="2012-10-16" name="CVE-2012-0090" modified="2012-10-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Web.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.3.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0091" published="2012-01-18" name="CVE-2012-0091" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:A/AC:H/Au:M/C:N/I:P/A:P)" CVSS_score="2.7" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="2.0" CVSS_base_score="2.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52.05 allows remote authenticated users to affect integrity and availability via unknown vectors related to Upgrade Change Assistance.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72486" source="XF">peoplesoft-eptools-cve20120091(72486)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78402" source="OSVDB">78402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="8.52.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0092" published="2012-10-16" name="CVE-2012-0092" modified="2012-10-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect integrity via unknown vectors related to Web.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.3.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0093" published="2012-10-16" name="CVE-2012-0093" modified="2012-10-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote attackers to affect integrity via unknown vectors related to Web.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.3.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0094" published="2012-01-18" name="CVE-2012-0094" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows remote attackers to affect availability, related to TCP/IP.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72495" source="XF">sun-solaris-dos(72495)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78420" source="OSVDB">78420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":express"/>
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0095" published="2012-10-16" name="CVE-2012-0095" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Web.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.3.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0096" published="2012-01-18" name="CVE-2012-0096" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Network.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72498" source="XF">sun-solarisunspec-dos(72498)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78422" source="OSVDB">78422</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":express"/>
        <vers num="5.8"/>
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0097" published="2012-01-18" name="CVE-2012-0097" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect confidentiality via unknown vectors related to ksh93 Shell.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72509" source="XF">sun-solaris-info-disc(72509)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78426" source="OSVDB">78426</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0098" published="2012-01-18" name="CVE-2012-0098" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72510" source="XF">sun-solarisunknown-dos(72510)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78427" source="OSVDB">78427</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":express"/>
        <vers num="5.8"/>
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0099" published="2012-01-18" name="CVE-2012-0099" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to sshd.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72506" source="XF">sun-solarisunsp-dos(72506)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78425" source="OSVDB">78425</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":express"/>
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0100" published="2012-01-18" name="CVE-2012-0100" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kerberos.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72496" source="XF">sun-solaris-cve20120100(72496)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78421" source="OSVDB">78421</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":express"/>
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0101" published="2012-01-18" name="CVE-2012-0101" modified="2012-10-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0087 and CVE-2012-0102.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72520" source="XF">mysql-serveruns1-dos(72520)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78378" source="OSVDB">78378</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00007.html" source="SUSE">SUSE-SU-2012:0984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0"/>
        <vers num="5.0.0" edition="alpha"/>
        <vers num="5.0.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.10"/>
        <vers num="5.0.10a"/>
        <vers num="5.0.11"/>
        <vers num="5.0.12"/>
        <vers num="5.0.13"/>
        <vers num="5.0.14"/>
        <vers num="5.0.15"/>
        <vers num="5.0.15a"/>
        <vers num="5.0.16"/>
        <vers num="5.0.16a"/>
        <vers num="5.0.17"/>
        <vers num="5.0.17a"/>
        <vers num="5.0.18"/>
        <vers num="5.0.19"/>
        <vers num="5.0.1a"/>
        <vers num="5.0.2"/>
        <vers num="5.0.20"/>
        <vers num="5.0.20a"/>
        <vers num="5.0.21"/>
        <vers num="5.0.22"/>
        <vers num="5.0.22.1.0.1"/>
        <vers num="5.0.23"/>
        <vers num="5.0.24"/>
        <vers num="5.0.24a"/>
        <vers num="5.0.25"/>
        <vers num="5.0.26"/>
        <vers num="5.0.27"/>
        <vers num="5.0.3" edition="beta"/>
        <vers num="5.0.30" edition="sp1"/>
        <vers num="5.0.32"/>
        <vers num="5.0.33"/>
        <vers num="5.0.36"/>
        <vers num="5.0.37"/>
        <vers num="5.0.38"/>
        <vers num="5.0.3a"/>
        <vers num="5.0.4"/>
        <vers num="5.0.41"/>
        <vers num="5.0.42"/>
        <vers num="5.0.44"/>
        <vers num="5.0.45" edition="b"/>
        <vers num="5.0.45b"/>
        <vers num="5.0.4a"/>
        <vers num="5.0.5"/>
        <vers num="5.0.5.0.21"/>
        <vers num="5.0.50"/>
        <vers num="5.0.51"/>
        <vers num="5.0.51a"/>
        <vers num="5.0.51b"/>
        <vers num="5.0.52"/>
        <vers num="5.0.54"/>
        <vers num="5.0.56"/>
        <vers num="5.0.6"/>
        <vers num="5.0.60"/>
        <vers num="5.0.66"/>
        <vers num="5.0.67"/>
        <vers num="5.0.7"/>
        <vers num="5.0.75"/>
        <vers num="5.0.77"/>
        <vers num="5.0.8"/>
        <vers num="5.0.81"/>
        <vers num="5.0.82"/>
        <vers num="5.0.83"/>
        <vers num="5.0.84"/>
        <vers num="5.0.85"/>
        <vers num="5.0.86"/>
        <vers num="5.0.87"/>
        <vers num="5.0.88"/>
        <vers num="5.0.89"/>
        <vers num="5.0.9"/>
        <vers num="5.0.90"/>
        <vers num="5.0.91"/>
        <vers num="5.0.92"/>
        <vers num="5.0.93"/>
        <vers num="5.0.94"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0102" published="2012-01-18" name="CVE-2012-0102" modified="2012-10-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0087 and CVE-2012-0101.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72521" source="XF">mysql-serveruns2-dos(72521)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78379" source="OSVDB">78379</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00007.html" source="SUSE">SUSE-SU-2012:0984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0"/>
        <vers num="5.0.0" edition="alpha"/>
        <vers num="5.0.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.10"/>
        <vers num="5.0.10a"/>
        <vers num="5.0.11"/>
        <vers num="5.0.12"/>
        <vers num="5.0.13"/>
        <vers num="5.0.14"/>
        <vers num="5.0.15"/>
        <vers num="5.0.15a"/>
        <vers num="5.0.16"/>
        <vers num="5.0.16a"/>
        <vers num="5.0.17"/>
        <vers num="5.0.17a"/>
        <vers num="5.0.18"/>
        <vers num="5.0.19"/>
        <vers num="5.0.1a"/>
        <vers num="5.0.2"/>
        <vers num="5.0.20"/>
        <vers num="5.0.20a"/>
        <vers num="5.0.21"/>
        <vers num="5.0.22"/>
        <vers num="5.0.22.1.0.1"/>
        <vers num="5.0.23"/>
        <vers num="5.0.24"/>
        <vers num="5.0.24a"/>
        <vers num="5.0.25"/>
        <vers num="5.0.26"/>
        <vers num="5.0.27"/>
        <vers num="5.0.3" edition="beta"/>
        <vers num="5.0.30" edition="sp1"/>
        <vers num="5.0.32"/>
        <vers num="5.0.33"/>
        <vers num="5.0.36"/>
        <vers num="5.0.37"/>
        <vers num="5.0.38"/>
        <vers num="5.0.3a"/>
        <vers num="5.0.4"/>
        <vers num="5.0.41"/>
        <vers num="5.0.42"/>
        <vers num="5.0.44"/>
        <vers num="5.0.45" edition="b"/>
        <vers num="5.0.45b"/>
        <vers num="5.0.4a"/>
        <vers num="5.0.5"/>
        <vers num="5.0.5.0.21"/>
        <vers num="5.0.50"/>
        <vers num="5.0.51"/>
        <vers num="5.0.51a"/>
        <vers num="5.0.51b"/>
        <vers num="5.0.52"/>
        <vers num="5.0.54"/>
        <vers num="5.0.56"/>
        <vers num="5.0.6"/>
        <vers num="5.0.60"/>
        <vers num="5.0.66"/>
        <vers num="5.0.67"/>
        <vers num="5.0.7"/>
        <vers num="5.0.75"/>
        <vers num="5.0.77"/>
        <vers num="5.0.8"/>
        <vers num="5.0.81"/>
        <vers num="5.0.82"/>
        <vers num="5.0.83"/>
        <vers num="5.0.84"/>
        <vers num="5.0.85"/>
        <vers num="5.0.86"/>
        <vers num="5.0.87"/>
        <vers num="5.0.88"/>
        <vers num="5.0.89"/>
        <vers num="5.0.9"/>
        <vers num="5.0.90"/>
        <vers num="5.0.91"/>
        <vers num="5.0.92"/>
        <vers num="5.0.93"/>
        <vers num="5.0.94"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0103" published="2012-01-18" name="CVE-2012-0103" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability via unknown vectors related to Kernel.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72499" source="XF">sun-solarisunspecified-dos(72499)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78423" source="OSVDB">78423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0104" published="2012-01-18" name="CVE-2012-0104" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle GlassFish Enterprise Server 3.0.1 and 3.1.1 allows remote attackers to affect availability via unknown vectors related to Web Container.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72497" source="XF">sun-glassfishenterpriseserver-dos(72497)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78417" source="OSVDB">78417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="glassfish_server">
        <vers num="3.0.1"/>
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0105" published="2012-01-18" name="CVE-2012-0105" modified="2013-04-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization 4.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Windows Guest Additions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72511" source="XF">virtualization-vmvirtualbox-cve20120105(72511)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201204-01.xml" source="GENTOO">GLSA-201204-01</ref>
      <ref url="http://secunia.com/advisories/50897" source="SECUNIA">50897</ref>
      <ref url="http://secunia.com/advisories/48755" source="SECUNIA">48755</ref>
      <ref url="http://osvdb.org/78442" source="OSVDB">78442</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2012-10/msg00041.html" source="SUSE">openSUSE-SU-2012:1323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="virtualization">
        <vers num="4.1"/>
      </prod>
      <prod vendor="oracle" name="vm_virtualbox">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0106" published="2012-10-16" name="CVE-2012-0106" modified="2012-10-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)" CVSS_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Web.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.3.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0107" published="2012-10-16" name="CVE-2012-0107" modified="2012-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote attackers to affect availability via unknown vectors related to Web.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.3.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0108" published="2012-10-16" name="CVE-2012-0108" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Web.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.3.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0109" published="2012-01-18" name="CVE-2012-0109" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect confidentiality and availability, related to TCP/IP.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72504" source="XF">sun-solaris-cve20120109(72504)</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://osvdb.org/78424" source="OSVDB">78424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":express"/>
        <vers num="5.8"/>
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0110" published="2012-01-18" name="CVE-2012-0110" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect confidentiality, integrity, and availability, related to Outside In Image Export SDK.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/51452" source="BID">51452</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="8.3.5.0"/>
        <vers num="8.3.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0111" published="2012-01-18" name="CVE-2012-0111" modified="2013-04-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization 4.1 allows local users to affect confidentiality and integrity via unknown vectors related to Shared Folders.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201204-01.xml" source="GENTOO">GLSA-201204-01</ref>
      <ref url="http://secunia.com/advisories/50897" source="SECUNIA">50897</ref>
      <ref url="http://secunia.com/advisories/48755" source="SECUNIA">48755</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2012-10/msg00041.html" source="SUSE">openSUSE-SU-2012:1323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="virtualization">
        <vers num="4.1"/>
      </prod>
      <prod vendor="oracle" name="vm_virtualbox">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0112" published="2012-01-18" name="CVE-2012-0112" modified="2012-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.5.0"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0113" published="2012-01-18" name="CVE-2012-0113" modified="2012-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:P)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality and availability via unknown vectors, a different vulnerability than CVE-2012-0118.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.5.0"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0114" published="2012-01-18" name="CVE-2012-0114" modified="2012-10-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:N)" CVSS_score="3.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="2.7" CVSS_base_score="3.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows local users to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00007.html" source="SUSE">SUSE-SU-2012:0984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0"/>
        <vers num="5.0.0" edition="alpha"/>
        <vers num="5.0.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.10"/>
        <vers num="5.0.10a"/>
        <vers num="5.0.11"/>
        <vers num="5.0.12"/>
        <vers num="5.0.13"/>
        <vers num="5.0.14"/>
        <vers num="5.0.15"/>
        <vers num="5.0.15a"/>
        <vers num="5.0.16"/>
        <vers num="5.0.16a"/>
        <vers num="5.0.17"/>
        <vers num="5.0.17a"/>
        <vers num="5.0.18"/>
        <vers num="5.0.19"/>
        <vers num="5.0.1a"/>
        <vers num="5.0.2"/>
        <vers num="5.0.20"/>
        <vers num="5.0.20a"/>
        <vers num="5.0.21"/>
        <vers num="5.0.22"/>
        <vers num="5.0.22.1.0.1"/>
        <vers num="5.0.23"/>
        <vers num="5.0.24"/>
        <vers num="5.0.24a"/>
        <vers num="5.0.25"/>
        <vers num="5.0.26"/>
        <vers num="5.0.27"/>
        <vers num="5.0.3" edition="beta"/>
        <vers num="5.0.30" edition="sp1"/>
        <vers num="5.0.32"/>
        <vers num="5.0.33"/>
        <vers num="5.0.36"/>
        <vers num="5.0.37"/>
        <vers num="5.0.38"/>
        <vers num="5.0.3a"/>
        <vers num="5.0.4"/>
        <vers num="5.0.41"/>
        <vers num="5.0.42"/>
        <vers num="5.0.44"/>
        <vers num="5.0.45" edition="b"/>
        <vers num="5.0.45b"/>
        <vers num="5.0.4a"/>
        <vers num="5.0.5"/>
        <vers num="5.0.5.0.21"/>
        <vers num="5.0.50"/>
        <vers num="5.0.51"/>
        <vers num="5.0.51a"/>
        <vers num="5.0.51b"/>
        <vers num="5.0.52"/>
        <vers num="5.0.54"/>
        <vers num="5.0.56"/>
        <vers num="5.0.6"/>
        <vers num="5.0.60"/>
        <vers num="5.0.66"/>
        <vers num="5.0.67"/>
        <vers num="5.0.7"/>
        <vers num="5.0.75"/>
        <vers num="5.0.77"/>
        <vers num="5.0.8"/>
        <vers num="5.0.81"/>
        <vers num="5.0.82"/>
        <vers num="5.0.83"/>
        <vers num="5.0.84"/>
        <vers num="5.0.85"/>
        <vers num="5.0.86"/>
        <vers num="5.0.87"/>
        <vers num="5.0.88"/>
        <vers num="5.0.89"/>
        <vers num="5.0.9"/>
        <vers num="5.0.90"/>
        <vers num="5.0.91"/>
        <vers num="5.0.92"/>
        <vers num="5.0.93"/>
        <vers num="5.0.94"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.5.0"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0115" published="2012-01-18" name="CVE-2012-0115" modified="2012-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0119, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.5.0"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0116" published="2012-01-18" name="CVE-2012-0116" modified="2012-01-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)" CVSS_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.5.0"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0117" published="2012-01-18" name="CVE-2012-0117" modified="2012-01-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.5.0"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0118" published="2012-01-18" name="CVE-2012-0118" modified="2012-01-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:P)" CVSS_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality and availability via unknown vectors, a different vulnerability than CVE-2012-0113.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.5.0"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0119" published="2012-01-18" name="CVE-2012-0119" modified="2012-01-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.5.0"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0120" published="2012-01-18" name="CVE-2012-0120" modified="2012-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0485, and CVE-2012-0492.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.5.0"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0121" published="2012-03-13" name="CVE-2012-0121" modified="2012-03-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1392.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/521944" source="HP">HPSBMU02746</ref>
      <ref url="http://www.securityfocus.com/archive/1/521944" source="HP">SSRT100781</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="data_protector_express">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0122" published="2012-03-13" name="CVE-2012-0122" modified="2012-03-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1393.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/521944" source="HP">HPSBMU02746</ref>
      <ref url="http://www.securityfocus.com/archive/1/521944" source="HP">SSRT100781</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="data_protector_express">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0123" published="2012-03-13" name="CVE-2012-0123" modified="2012-03-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1498.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/521944" source="HP">SSRT100781</ref>
      <ref url="http://www.securityfocus.com/archive/1/521944" source="HP">HPSBMU02746</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="data_protector_express">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0124" published="2012-03-13" name="CVE-2012-0124" modified="2012-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/521944" source="HP">SSRT100781</ref>
      <ref url="http://www.securityfocus.com/archive/1/521944" source="HP">HPSBMU02746</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="data_protector_express">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0125" published="2012-03-28" name="CVE-2012-0125" modified="2012-08-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.31 allows local users to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0126.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74391" source="XF">hpux-wbem-sec-bypass(74391)</ref>
      <ref url="http://www.securityfocus.com/bid/52733" source="BID">52733</ref>
      <ref url="http://secunia.com/advisories/48593" source="SECUNIA">48593</ref>
      <ref url="http://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03221589" source="HP" adv="1">HPSBUX02755</ref>
      <ref url="http://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03221589" source="HP" adv="1">SSRT100667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0126" published="2012-03-28" name="CVE-2012-0126" modified="2012-06-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.11 and 11.23 allows remote attackers to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0125.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74390" source="XF">hpux-wbem-security-bypass(74390)</ref>
      <ref url="http://www.securityfocus.com/bid/52734" source="BID">52734</ref>
      <ref url="http://secunia.com/advisories/48593" source="SECUNIA">48593</ref>
      <ref url="http://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03221589" source="HP" adv="1">HPSBUX02755</ref>
      <ref url="http://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03221589" source="HP" adv="1">SSRT100667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.11"/>
        <vers num="11.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0127" published="2012-03-31" name="CVE-2012-0127" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Performance Manager 9.00 allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/522101" source="HP">HPSBMU02756</ref>
      <ref url="http://www.securityfocus.com/archive/1/522101" source="HP">SSRT100596</ref>
      <ref url="http://osvdb.org/80657" source="OSVDB">80657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="performance_manager">
        <vers num="9.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0128" published="2012-04-05" name="CVE-2012-0128" modified="2012-12-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">HP Onboard Administrator (OA) before 3.50 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74575" source="XF">hpoa-unspecified-open-redirect(74575)</ref>
      <ref url="http://www.securitytracker.com/id?1026889" source="SECTRACK">1026889</ref>
      <ref url="http://www.securityfocus.com/bid/52862" source="BID">52862</ref>
      <ref url="http://www.securityfocus.com/archive/1/522176" source="HP">SSRT100817</ref>
      <ref url="http://www.securityfocus.com/archive/1/522176" source="HP">HPSBMU02759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="onboard_administrator">
        <vers num="1.00"/>
        <vers num="1.01"/>
        <vers num="1.10"/>
        <vers num="1.11"/>
        <vers num="1.12"/>
        <vers num="1.20"/>
        <vers num="1.30"/>
        <vers num="2.01"/>
        <vers num="2.02" edition="a"/>
        <vers num="2.04"/>
        <vers num="2.10"/>
        <vers num="2.11"/>
        <vers num="2.12"/>
        <vers num="2.13"/>
        <vers num="2.20"/>
        <vers num="2.21"/>
        <vers num="2.25"/>
        <vers num="2.31"/>
        <vers num="2.32"/>
        <vers num="2.41"/>
        <vers num="2.50"/>
        <vers num="2.51"/>
        <vers num="2.52"/>
        <vers num="2.60"/>
        <vers num="3.00"/>
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers num="3.20" edition="a"/>
        <vers num="3.21"/>
        <vers num="3.30"/>
        <vers num="3.31"/>
        <vers prev="1" num="3.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0129" published="2012-04-05" name="CVE-2012-0129" modified="2012-12-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">HP Onboard Administrator (OA) before 3.50 allows remote attackers to bypass intended access restrictions and execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74576" source="XF">hpoa-unspecified-unauth-access(74576)</ref>
      <ref url="http://www.securitytracker.com/id?1026889" source="SECTRACK">1026889</ref>
      <ref url="http://www.securityfocus.com/bid/52862" source="BID">52862</ref>
      <ref url="http://www.securityfocus.com/archive/1/522176" source="HP">HPSBMU02759</ref>
      <ref url="http://www.securityfocus.com/archive/1/522176" source="HP">SSRT100817</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="onboard_administrator">
        <vers num="1.00"/>
        <vers num="1.01"/>
        <vers num="1.10"/>
        <vers num="1.11"/>
        <vers num="1.12"/>
        <vers num="1.20"/>
        <vers num="1.30"/>
        <vers num="2.01"/>
        <vers num="2.02" edition="a"/>
        <vers num="2.04"/>
        <vers num="2.10"/>
        <vers num="2.11"/>
        <vers num="2.12"/>
        <vers num="2.13"/>
        <vers num="2.20"/>
        <vers num="2.21"/>
        <vers num="2.25"/>
        <vers num="2.31"/>
        <vers num="2.32"/>
        <vers num="2.41"/>
        <vers num="2.50"/>
        <vers num="2.51"/>
        <vers num="2.52"/>
        <vers num="2.60"/>
        <vers num="3.00"/>
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers num="3.20" edition="a"/>
        <vers num="3.21"/>
        <vers num="3.30"/>
        <vers num="3.31"/>
        <vers prev="1" num="3.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0130" published="2012-04-05" name="CVE-2012-0130" modified="2012-12-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HP Onboard Administrator (OA) before 3.50 allows remote attackers to obtain sensitive information via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74577" source="XF">hpoa-unspecified-info-disclosure(74577)</ref>
      <ref url="http://www.securitytracker.com/id?1026889" source="SECTRACK">1026889</ref>
      <ref url="http://www.securityfocus.com/bid/52862" source="BID">52862</ref>
      <ref url="http://www.securityfocus.com/archive/1/522176" source="HP">HPSBMU02759</ref>
      <ref url="http://www.securityfocus.com/archive/1/522176" source="HP">SSRT100817</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="onboard_administrator">
        <vers num="1.00"/>
        <vers num="1.01"/>
        <vers num="1.10"/>
        <vers num="1.11"/>
        <vers num="1.12"/>
        <vers num="1.20"/>
        <vers num="1.30"/>
        <vers num="2.01"/>
        <vers num="2.02" edition="a"/>
        <vers num="2.04"/>
        <vers num="2.10"/>
        <vers num="2.11"/>
        <vers num="2.12"/>
        <vers num="2.13"/>
        <vers num="2.20"/>
        <vers num="2.21"/>
        <vers num="2.25"/>
        <vers num="2.31"/>
        <vers num="2.32"/>
        <vers num="2.41"/>
        <vers num="2.50"/>
        <vers num="2.51"/>
        <vers num="2.52"/>
        <vers num="2.60"/>
        <vers num="3.00"/>
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers num="3.20" edition="a"/>
        <vers num="3.21"/>
        <vers num="3.30"/>
        <vers num="3.31"/>
        <vers prev="1" num="3.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0131" published="2012-04-05" name="CVE-2012-0131" modified="2012-12-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Distributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74800" source="XF">hpux-unspec-dce-dos(74800)</ref>
      <ref url="http://www.securitytracker.com/id?1026885" source="SECTRACK">1026885</ref>
      <ref url="http://www.securityfocus.com/bid/52860" source="BID">52860</ref>
      <ref url="http://secunia.com/advisories/48687" source="SECUNIA">48687</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03261413" source="HP" adv="1">SSRT100774</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03261413" source="HP" adv="1">HPSBUX02758</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="distributed_computing_environment">
        <vers num="1.8"/>
        <vers num="1.9"/>
      </prod>
      <prod vendor="hp" name="hp-ux">
        <vers num="b.11.11"/>
        <vers num="b.11.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0132" published="2012-04-05" name="CVE-2012-0132" modified="2012-12-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 9.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74640" source="XF">hp-bac-unspec-xss(74640)</ref>
      <ref url="http://www.securityfocus.com/bid/52880" source="BID">52880</ref>
      <ref url="http://www.securityfocus.com/archive/1/522204" source="HP">HPSBMU02749</ref>
      <ref url="http://www.securityfocus.com/archive/1/522204" source="HP">SSRT100793</ref>
      <ref url="http://secunia.com/advisories/48677" source="SECUNIA">48677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="business_availability_center">
        <vers num="9.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0133" published="2012-04-12" name="CVE-2012-0133" modified="2013-01-03" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">HP ProCurve 5400 zl switches with certain serial numbers include a compact flash card that contains an unspecified virus, which might allow user-assisted remote attackers to execute arbitrary code on a PC by leveraging manual transfer of this card.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74819" source="XF">hpprocurve-flashcards-weak-security(74819)</ref>
      <ref url="http://www.securitytracker.com/id?1026916" source="SECTRACK">1026916</ref>
      <ref url="http://www.securityfocus.com/archive/1/522288" source="HP">HPSBPV02754</ref>
      <ref url="http://www.securityfocus.com/archive/1/522288" source="HP">SSRT100803</ref>
      <ref url="http://secunia.com/advisories/48738" source="SECUNIA">48738</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="procurve_switch_5400zl">
        <vers num=""/>
      </prod>
      <prod vendor="hp" name="procurve_switch_5400zl_management_module">
        <vers num="id116as04p"/>
        <vers num="id116as0hr"/>
        <vers num="id117as00h"/>
        <vers num="id126as0fb"/>
      </prod>
      <prod vendor="hp" name="procurve_switch_5406-44g-poe+-4sfpzl">
        <vers num="-"/>
      </prod>
      <prod vendor="hp" name="procurve_switch_5406-48gzl">
        <vers num="-"/>
      </prod>
      <prod vendor="hp" name="procurve_switch_5406zl-44g-poe+/2xg_sfp+_v2">
        <vers num="-"/>
      </prod>
      <prod vendor="hp" name="procurve_switch_5406zl-44g-poe+/4g_sfp+_v2">
        <vers num="-"/>
      </prod>
      <prod vendor="hp" name="procurve_switch_5412-92g-poe+-4sfpzl">
        <vers num="-"/>
      </prod>
      <prod vendor="hp" name="procurve_switch_5412-96gzl">
        <vers num="-"/>
      </prod>
      <prod vendor="hp" name="procurve_switch_5412zl-92g-poe+/4g_sfp+_v2">
        <vers num="-"/>
      </prod>
      <prod vendor="hp" name="procurve_switch_5412zl-92gg-poe+/2xg_sfp+_v2">
        <vers num="-"/>
      </prod>
      <prod vendor="hp" name="procurve_switch_chassis_e5406zl">
        <vers num="-"/>
      </prod>
      <prod vendor="hp" name="procurve_switch_chassis_e5412zl">
        <vers num="-"/>
      </prod>
      <prod vendor="hp" name="procurve_switch_e5406zl">
        <vers num="-"/>
      </prod>
      <prod vendor="hp" name="procurve_switch_e5412zl">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0134" published="2012-04-19" name="CVE-2012-0134" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP OpenVMS 7.3-2 on the Alpha platform, 8.3 and 8.4 on the Alpha and IA64 platforms, and 8.3-1h1 on the IA64 platform allows local users to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1026935" source="SECTRACK">1026935</ref>
      <ref url="http://www.securityfocus.com/archive/1/522386" source="HP">SSRT100828</ref>
      <ref url="http://www.securityfocus.com/archive/1/522386" source="HP">HPSBOV02765</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openvms">
        <vers num="8.3-1h1" edition=""/>
        <vers num="8.3-1h1" edition=":ia64"/>
      </prod>
      <prod vendor="hp" name="openvms">
        <vers num="7.3-2" edition=""/>
        <vers num="7.3-2" edition=":alpha"/>
        <vers num="8.3" edition=""/>
        <vers num="8.3" edition=":alpha"/>
        <vers num="8.3" edition=":ia64"/>
        <vers num="8.4" edition=""/>
        <vers num="8.4" edition=":alpha"/>
        <vers num="8.4" edition=":ia64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0135" published="2012-04-18" name="CVE-2012-0135" modified="2013-01-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP System Management Homepage (SMH) before 7.0 allows remote authenticated users to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74917" source="XF">hp-system-homepage-dos(74917)</ref>
      <ref url="http://www.securitytracker.com/id?1026925" source="SECTRACK">1026925</ref>
      <ref url="http://www.securityfocus.com/archive/1/522374" source="HP">SSRT100827</ref>
      <ref url="http://www.securityfocus.com/archive/1/522374" source="HP">HPSBMU02764</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="system_management_homepage">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.1.104"/>
        <vers num="2.0.2"/>
        <vers num="2.0.2.106"/>
        <vers num="2.1"/>
        <vers num="2.1.0-103"/>
        <vers num="2.1.0-103(a)"/>
        <vers num="2.1.0-109"/>
        <vers num="2.1.0-118"/>
        <vers num="2.1.0.121"/>
        <vers num="2.1.1"/>
        <vers num="2.1.10"/>
        <vers num="2.1.10-186"/>
        <vers num="2.1.10.186" edition="b"/>
        <vers num="2.1.10.186" edition="c"/>
        <vers num="2.1.11"/>
        <vers num="2.1.11-197"/>
        <vers num="2.1.11.197" edition="a"/>
        <vers num="2.1.12-118"/>
        <vers num="2.1.12-200"/>
        <vers num="2.1.12.201"/>
        <vers num="2.1.14.20"/>
        <vers num="2.1.15-210"/>
        <vers num="2.1.15.210"/>
        <vers num="2.1.2"/>
        <vers num="2.1.2-127"/>
        <vers num="2.1.2.127"/>
        <vers num="2.1.3"/>
        <vers num="2.1.3.132"/>
        <vers num="2.1.4"/>
        <vers num="2.1.4-143"/>
        <vers num="2.1.4.143"/>
        <vers num="2.1.5"/>
        <vers num="2.1.5-146"/>
        <vers num="2.1.5.146" edition="b"/>
        <vers num="2.1.6"/>
        <vers num="2.1.6-156"/>
        <vers num="2.1.6.156"/>
        <vers num="2.1.7"/>
        <vers num="2.1.7-168"/>
        <vers num="2.1.7.168"/>
        <vers num="2.1.8"/>
        <vers num="2.1.8-177"/>
        <vers num="2.1.8.179"/>
        <vers num="2.1.9"/>
        <vers num="2.1.9-178"/>
        <vers num="2.2.6"/>
        <vers num="2.2.8"/>
        <vers num="3.0.0-68"/>
        <vers num="3.0.0.64"/>
        <vers num="3.0.1-73"/>
        <vers num="3.0.1.73"/>
        <vers num="3.0.2-77"/>
        <vers num="3.0.2.77" edition="b"/>
        <vers num="6.0"/>
        <vers num="6.0.0-95"/>
        <vers num="6.0.0.96"/>
        <vers num="6.1"/>
        <vers prev="1" num="6.1.0-103"/>
        <vers num="6.1.0.102"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0136" published="2012-02-14" name="CVE-2012-0136" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0137, and CVE-2012-0138.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-015" source="MS" patch="1" adv="1">MS12-015</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14924" source="OVAL">oval:org.mitre.oval:def:14924</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio_viewer">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0137" published="2012-02-14" name="CVE-2012-0137" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0138.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-015" source="MS" patch="1" adv="1">MS12-015</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14602" source="OVAL">oval:org.mitre.oval:def:14602</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio_viewer">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0138" published="2012-02-14" name="CVE-2012-0138" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0137.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-015" source="MS" patch="1" adv="1">MS12-015</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14811" source="OVAL">oval:org.mitre.oval:def:14811</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio_viewer">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0141" published="2012-05-08" name="CVE-2012-0141" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel File Format Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-030" source="MS" patch="1" adv="1">MS12-030</ref>
      <ref url="http://www.securitytracker.com/id?1027041" source="SECTRACK">1027041</ref>
      <ref url="http://www.securityfocus.com/bid/53342" source="BID">53342</ref>
      <ref url="http://secunia.com/advisories/49112" source="SECUNIA" adv="1">49112</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15152" source="OVAL">oval:org.mitre.oval:def:15152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2011" edition=""/>
        <vers num="2011" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0142" published="2012-05-08" name="CVE-2012-0142" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel File Format Memory Corruption in OBJECTLINK Record Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securitytracker.com/id?1027041" source="SECTRACK">1027041</ref>
      <ref url="http://www.securityfocus.com/bid/53373" source="BID">53373</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-030" source="MS" adv="1">MS12-030</ref>
      <ref url="http://secunia.com/advisories/49112" source="SECUNIA">49112</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15543" source="OVAL">oval:org.mitre.oval:def:15543</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0143" published="2012-05-08" name="CVE-2012-0143" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Memory Corruption Using Various Modified Bytes Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securitytracker.com/id?1027041" source="SECTRACK">1027041</ref>
      <ref url="http://www.securityfocus.com/bid/53374" source="BID">53374</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-030" source="MS" adv="1">MS12-030</ref>
      <ref url="http://secunia.com/advisories/49112" source="SECUNIA">49112</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15064" source="OVAL">oval:org.mitre.oval:def:15064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2003" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0144" published="2012-02-14" name="CVE-2012-0144" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-011" source="MS" patch="1" adv="1">MS12-011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14386" source="OVAL">oval:org.mitre.oval:def:14386</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_foundation">
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="sharepoint_server">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0145" published="2012-02-14" name="CVE-2012-0145" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-011" source="MS" patch="1" adv="1">MS12-011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14826" source="OVAL">oval:org.mitre.oval:def:14826</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_foundation">
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="sharepoint_server">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0146" published="2012-04-10" name="CVE-2012-0146" modified="2012-12-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-026" source="MS" patch="1" adv="1">MS12-026</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74367" source="XF">ms-forefront-spoofing(74367)</ref>
      <ref url="http://www.securitytracker.com/id?1026909" source="SECTRACK">1026909</ref>
      <ref url="http://www.securityfocus.com/bid/52903" source="BID">52903</ref>
      <ref url="http://secunia.com/advisories/48787" source="SECUNIA">48787</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15476" source="OVAL">oval:org.mitre.oval:def:15476</ref>
      <ref url="http://osvdb.org/81131" source="OSVDB">81131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="forefront_unified_access_gateway">
        <vers num="2010" edition="sp1"/>
        <vers num="2010" edition="sp1_update1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0147" published="2012-04-10" name="CVE-2012-0147" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-101A.html" source="CERT">TA12-101A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-026" source="MS" patch="1" adv="1">MS12-026</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74368" source="XF">ms-forefront-uag-info-disclosure(74368)</ref>
      <ref url="http://www.securitytracker.com/id?1026909" source="SECTRACK">1026909</ref>
      <ref url="http://www.securityfocus.com/bid/52909" source="BID">52909</ref>
      <ref url="http://secunia.com/advisories/48787" source="SECUNIA">48787</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15557" source="OVAL">oval:org.mitre.oval:def:15557</ref>
      <ref url="http://osvdb.org/81132" source="OSVDB">81132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="forefront_unified_access_gateway">
        <vers num="2010" edition="sp1"/>
        <vers num="2010" edition="sp1_update1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0148" published="2012-02-14" name="CVE-2012-0148" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "AfdPoll Elevation of Privilege Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://technet.microsoft.com/en-us/security/bulletin/ms12-009

'This vulnerability is not exploitable on 32-bit editions of Microsoft Windows.'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-009" source="MS" patch="1" adv="1">MS12-009</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14852" source="OVAL">oval:org.mitre.oval:def:14852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0149" published="2012-02-14" name="CVE-2012-0149" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-009" source="MS" patch="1" adv="1">MS12-009</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14958" source="OVAL">oval:org.mitre.oval:def:14958</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0150" published="2012-02-14" name="CVE-2012-0150" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, aka "Msvcrt.dll Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-013" source="MS" patch="1" adv="1">MS12-013</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14631" source="OVAL">oval:org.mitre.oval:def:14631</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x86"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0151" published="2012-04-10" name="CVE-2012-0151" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-101A.html" source="CERT">TA12-101A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-024" source="MS" patch="1" adv="1">MS12-024</ref>
      <ref url="http://www.securitytracker.com/id?1026906" source="SECTRACK">1026906</ref>
      <ref url="http://secunia.com/advisories/48581" source="SECUNIA">48581</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15594" source="OVAL">oval:org.mitre.oval:def:15594</ref>
      <ref url="http://osvdb.org/81135" source="OSVDB">81135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0152" published="2012-03-13" name="CVE-2012-0152" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-073A.html" source="CERT">TA12-073A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-020" source="MS" patch="1" adv="1">MS12-020</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14626" source="OVAL">oval:org.mitre.oval:def:14626</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x86"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0154" published="2012-02-14" name="CVE-2012-0154" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers keyboard layout errors, aka "Keyboard Layout Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-008" source="MS" patch="1" adv="1">MS12-008</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14928" source="OVAL">oval:org.mitre.oval:def:14928</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x86"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0155" published="2012-02-14" name="CVE-2012-0155" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-010" source="MS" patch="1" adv="1">MS12-010</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14781" source="OVAL">oval:org.mitre.oval:def:14781</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0156" published="2012-03-13" name="CVE-2012-0156" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant message or (2) web site, aka "DirectWrite Application Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-019" source="MS" patch="1" adv="1">MS12-019</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14807" source="OVAL">oval:org.mitre.oval:def:14807</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x86"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0157" published="2012-03-13" name="CVE-2012-0157" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to gain privileges via a crafted application that calls the PostMessage function, aka "PostMessage Function Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-073A.html" source="CERT">TA12-073A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-018" source="MS" patch="1" adv="1">MS12-018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14217" source="OVAL">oval:org.mitre.oval:def:14217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x86"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0158" published="2012-04-10" name="CVE-2012-0158" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in the wild in April 2012, aka "MSCOMCTL.OCX RCE Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-101A.html" source="CERT">TA12-101A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-027" source="MS" patch="1" adv="1">MS12-027</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74372" source="XF">ms-activex-control-code-execution(74372)</ref>
      <ref url="http://www.securitytracker.com/id?1026905" source="SECTRACK">1026905</ref>
      <ref url="http://www.securitytracker.com/id?1026904" source="SECTRACK">1026904</ref>
      <ref url="http://www.securitytracker.com/id?1026903" source="SECTRACK">1026903</ref>
      <ref url="http://www.securitytracker.com/id?1026902" source="SECTRACK">1026902</ref>
      <ref url="http://www.securitytracker.com/id?1026900" source="SECTRACK">1026900</ref>
      <ref url="http://www.securitytracker.com/id?1026899" source="SECTRACK">1026899</ref>
      <ref url="http://www.securityfocus.com/bid/52911" source="BID">52911</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15462" source="OVAL">oval:org.mitre.oval:def:15462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="biztalk_server">
        <vers num="2002" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="commerce_server">
        <vers num="2002" edition="sp4"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2009" edition="r2"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition=""/>
        <vers num="2010" edition=":x86"/>
        <vers num="2010" edition="sp1"/>
        <vers num="2010" edition="sp1:x86"/>
      </prod>
      <prod vendor="microsoft" name="office_web_components">
        <vers num="2003" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="sql_server">
        <vers num="2000" edition="sp4"/>
        <vers num="2000" edition="sp4:analysis_services"/>
        <vers num="2005" edition="sp4"/>
        <vers num="2005" edition="sp4:express_advanced_services"/>
        <vers num="2005" edition="sp4:x64"/>
        <vers num="2005" edition="sp4:x86"/>
        <vers num="2005" edition="sp4:itanium"/>
        <vers num="2008" edition="r2"/>
        <vers num="2008" edition="r2:itanium"/>
        <vers num="2008" edition="r2:x64"/>
        <vers num="2008" edition="r2:x86"/>
        <vers num="2008" edition="sp2"/>
        <vers num="2008" edition="sp2:itanium"/>
        <vers num="2008" edition="sp2:x64"/>
        <vers num="2008" edition="sp2:x86"/>
        <vers num="2008" edition="sp3"/>
        <vers num="2008" edition="sp3:x64"/>
        <vers num="2008" edition="sp3:itanium"/>
        <vers num="2008" edition="sp3:x86"/>
      </prod>
      <prod vendor="microsoft" name="visual_basic">
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":runtime_extended_files"/>
      </prod>
      <prod vendor="microsoft" name="visual_foxpro">
        <vers num="8.0" edition="sp1"/>
        <vers num="9.0" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0159" published="2012-05-08" name="CVE-2012-0159" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview; Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Silverlight 4 before 4.1.10329; and Silverlight 5 before 5.1.10411 allow remote attackers to execute arbitrary code via a crafted TrueType font (TTF) file, aka "TrueType Font Parsing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-164A.html" source="CERT">TA12-164A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securitytracker.com/id?1027039" source="SECTRACK">1027039</ref>
      <ref url="http://www.securityfocus.com/bid/53335" source="BID">53335</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-039" source="MS">MS12-039</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-034" source="MS" adv="1">MS12-034</ref>
      <ref url="http://secunia.com/advisories/49122" source="SECUNIA">49122</ref>
      <ref url="http://secunia.com/advisories/49121" source="SECUNIA">49121</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15667" source="OVAL">oval:org.mitre.oval:def:15667</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15388" source="OVAL">oval:org.mitre.oval:def:15388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="silverlight">
        <vers num="4.0.50401.0"/>
        <vers num="4.0.50524.00"/>
        <vers num="4.0.50826.0"/>
        <vers num="4.0.50917.0"/>
        <vers num="4.0.51204.0"/>
        <vers num="4.0.60129.0"/>
        <vers num="4.0.60310.0"/>
        <vers num="4.0.60531.0"/>
        <vers num="4.0.60831.0"/>
        <vers num="4.1.10111.0"/>
        <vers num="5.0.60401.0"/>
        <vers num="5.0.60818.0" edition="rc"/>
        <vers num="5.0.61118.0"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x86"/>
        <vers num="-" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_8">
        <vers num="consumer_preview"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="-" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0160" published="2012-05-08" name="CVE-2012-0160" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-035" source="MS" patch="1" adv="1">MS12-035</ref>
      <ref url="http://www.securitytracker.com/id?1027036" source="SECTRACK">1027036</ref>
      <ref url="http://www.securityfocus.com/bid/53356" source="BID">53356</ref>
      <ref url="http://secunia.com/advisories/49117" source="SECUNIA" adv="1">49117</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15554" source="OVAL">oval:org.mitre.oval:def:15554</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp3"/>
        <vers num="1.1" edition="sp1"/>
        <vers num="2.0" edition="sp2"/>
        <vers num="3.0" edition="sp2"/>
        <vers num="3.5" edition="sp1"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0161" published="2012-05-08" name="CVE-2012-0161" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securitytracker.com/id?1027036" source="SECTRACK">1027036</ref>
      <ref url="http://www.securityfocus.com/bid/53357" source="BID">53357</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-035" source="MS" adv="1">MS12-035</ref>
      <ref url="http://secunia.com/advisories/49117" source="SECUNIA">49117</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14951" source="OVAL">oval:org.mitre.oval:def:14951</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp3"/>
        <vers num="1.1" edition="sp1"/>
        <vers num="2.0" edition="sp2"/>
        <vers num="3.0" edition="sp2"/>
        <vers num="3.5" edition="sp1"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0162" published="2012-05-08" name="CVE-2012-0162" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft .NET Framework 4 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Buffer Allocation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securityfocus.com/bid/53358" source="BID">53358</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-034" source="MS" adv="1">MS12-034</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14655" source="OVAL">oval:org.mitre.oval:def:14655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0163" published="2012-04-10" name="CVE-2012-0163" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Parameter Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-101A.html" source="CERT">TA12-101A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-025" source="MS" patch="1" adv="1">MS12-025</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74377" source="XF">ms-dotnet-parameter-code-exec(74377)</ref>
      <ref url="http://www.securitytracker.com/id?1026907" source="SECTRACK">1026907</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15495" source="OVAL">oval:org.mitre.oval:def:15495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp3"/>
        <vers num="1.1" edition="sp1"/>
        <vers num="2.0" edition="sp2"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0164" published="2012-05-08" name="CVE-2012-0164" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft .NET Framework 4 does not properly compare index values, which allows remote attackers to cause a denial of service (application hang) via crafted requests to a Windows Presentation Foundation (WPF) application, aka ".NET Framework Index Comparison Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/53363" source="BID">53363</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-034" source="MS" adv="1">MS12-034</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15580" source="OVAL">oval:org.mitre.oval:def:15580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0165" published="2012-05-08" name="CVE-2012-0165" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securitytracker.com/id?1027038" source="SECTRACK">1027038</ref>
      <ref url="http://www.securityfocus.com/bid/53347" source="BID">53347</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-034" source="MS" adv="1">MS12-034</ref>
      <ref url="http://secunia.com/advisories/49121" source="SECUNIA">49121</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15621" source="OVAL">oval:org.mitre.oval:def:15621</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="-" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="-" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0167" published="2012-05-08" name="CVE-2012-0167" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka "GDI+ Heap Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securitytracker.com/id?1027038" source="SECTRACK">1027038</ref>
      <ref url="http://www.securityfocus.com/bid/53351" source="BID">53351</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-034" source="MS" adv="1">MS12-034</ref>
      <ref url="http://secunia.com/advisories/49121" source="SECUNIA">49121</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15628" source="OVAL">oval:org.mitre.oval:def:15628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0168" published="2012-04-10" name="CVE-2012-0168" modified="2012-12-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 9 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document that is not properly handled during a "Print table of links" print operation, aka "Print Feature Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-023" source="MS" patch="1" adv="1">MS12-023</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74379" source="XF">ie-html-page-code-exec(74379)</ref>
      <ref url="http://www.securitytracker.com/id?1026901" source="SECTRACK">1026901</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15577" source="OVAL">oval:org.mitre.oval:def:15577</ref>
      <ref url="http://osvdb.org/81126" source="OSVDB">81126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0169" published="2012-04-10" name="CVE-2012-0169" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "JScript9 Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-101A.html" source="CERT">TA12-101A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-023" source="MS" patch="1" adv="1">MS12-023</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74380" source="XF">ms-ie-jscript9-code-exec(74380)</ref>
      <ref url="http://www.securitytracker.com/id?1026901" source="SECTRACK">1026901</ref>
      <ref url="http://www.securityfocus.com/bid/52902" source="BID">52902</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15611" source="OVAL">oval:org.mitre.oval:def:15611</ref>
      <ref url="http://osvdb.org/81127" source="OSVDB">81127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0170" published="2012-04-10" name="CVE-2012-0170" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnReadyStateChange Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-101A.html" source="CERT">TA12-101A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-023" source="MS" patch="1" adv="1">MS12-023</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74381" source="XF">ms-ie-onreadystatechange-code-exec(74381)</ref>
      <ref url="http://www.securitytracker.com/id?1026901" source="SECTRACK">1026901</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15573" source="OVAL">oval:org.mitre.oval:def:15573</ref>
      <ref url="http://osvdb.org/81128" source="OSVDB">81128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6"/>
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0171" published="2012-04-10" name="CVE-2012-0171" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "SelectAll Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-101A.html" source="CERT">TA12-101A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-023" source="MS" patch="1" adv="1">MS12-023</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74382" source="XF">ms-ie-selectall-code-exec(74382)</ref>
      <ref url="http://www.securitytracker.com/id?1026901" source="SECTRACK">1026901</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15313" source="OVAL">oval:org.mitre.oval:def:15313</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0172" published="2012-04-10" name="CVE-2012-0172" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Style Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-101A.html" source="CERT">TA12-101A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-023" source="MS" patch="1" adv="1">MS12-023</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74383" source="XF">ms-ie-vml-code-exec(74383)</ref>
      <ref url="http://www.securitytracker.com/id?1026901" source="SECTRACK">1026901</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15550" source="OVAL">oval:org.mitre.oval:def:15550</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0173" published="2012-06-12" name="CVE-2012-0173" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability," a different vulnerability than CVE-2012-0002.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-164A.html" source="CERT">TA12-164A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-036" source="MS" patch="1" adv="1">MS12-036</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15116" source="OVAL">oval:org.mitre.oval:def:15116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x86"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0174" published="2012-05-08" name="CVE-2012-0174" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly enforce firewall rules for outbound broadcast packets, which allows remote attackers to obtain potentially sensitive information by observing broadcast traffic on a local network, aka "Windows Firewall Bypass Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://technet.microsoft.com/en-us/security/bulletin/ms12-032 "An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability." "In order to use this vulnerability, an attacker would first have to gain access to the local subnet of the target computer. An attacker could then use another vulnerability to acquire information about the target system or execute code on the target system."</impact>
    </impacts>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securitytracker.com/id?1027044" source="SECTRACK">1027044</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-032" source="MS" adv="1">MS12-032</ref>
      <ref url="http://secunia.com/advisories/49114" source="SECUNIA">49114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15160" source="OVAL">oval:org.mitre.oval:def:15160</ref>
      <ref url="http://osvdb.org/81730" source="OSVDB">81730</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp1:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="-" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0175" published="2012-07-10" name="CVE-2012-0175" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted name for a (1) file or (2) directory, aka "Command Injection Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-192A.html" source="CERT">TA12-192A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-048" source="MS" adv="1">MS12-048</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14897" source="OVAL">oval:org.mitre.oval:def:14897</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x86"/>
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x86"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x86"/>
        <vers num="-" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="r2:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0176" published="2012-05-08" name="CVE-2012-0176" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Double free vulnerability in Microsoft Silverlight 4 before 4.1.10329 on Windows allows remote attackers to execute arbitrary code via vectors involving crafted XAML glyphs, aka "Silverlight Double-Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securitytracker.com/id?1027040" source="SECTRACK">1027040</ref>
      <ref url="http://www.securityfocus.com/bid/53360" source="BID">53360</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-034" source="MS" adv="1">MS12-034</ref>
      <ref url="http://secunia.com/advisories/49122" source="SECUNIA">49122</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15574" source="OVAL">oval:org.mitre.oval:def:15574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="silverlight">
        <vers num="4.0.50401.0"/>
        <vers num="4.0.50524.00"/>
        <vers num="4.0.50826.0"/>
        <vers num="4.0.50917.0"/>
        <vers num="4.0.51204.0"/>
        <vers num="4.0.60129.0"/>
        <vers num="4.0.60310.0"/>
        <vers num="4.0.603310.0"/>
        <vers num="4.0.60531.0"/>
        <vers num="4.0.60831.0"/>
        <vers num="4.1.10111"/>
        <vers num="4.1.10111.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0177" published="2012-04-10" name="CVE-2012-0177" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works (aka .wps) file, aka "Office WPS Converter Heap Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-101A.html" source="CERT">TA12-101A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-028" source="MS" patch="1" adv="1">MS12-028</ref>
      <ref url="http://www.securitytracker.com/id?1026911" source="SECTRACK">1026911</ref>
      <ref url="http://www.securitytracker.com/id?1026910" source="SECTRACK">1026910</ref>
      <ref url="http://www.securityfocus.com/bid/52867" source="BID">52867</ref>
      <ref url="http://secunia.com/advisories/48723" source="SECUNIA">48723</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15598" source="OVAL">oval:org.mitre.oval:def:15598</ref>
      <ref url="http://osvdb.org/81134" source="OSVDB">81134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2007" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="9.0"/>
      </prod>
      <prod vendor="microsoft" name="works_6-9_file_converter">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0178" published="2012-05-08" name="CVE-2012-0178" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that makes multiple simultaneous Plug and Play (PnP) Configuration Manager function calls, aka "Plug and Play (PnP) Configuration Manager Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-033" source="MS" patch="1" adv="1">MS12-033</ref>
      <ref url="http://www.securitytracker.com/id?1027043" source="SECTRACK">1027043</ref>
      <ref url="http://secunia.com/advisories/49115" source="SECUNIA" adv="1">49115</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15229" source="OVAL">oval:org.mitre.oval:def:15229</ref>
      <ref url="http://osvdb.org/81735" source="OSVDB">81735</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp1:x32"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x32"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition="-"/>
        <vers num="r2" edition="-:itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0179" published="2012-05-08" name="CVE-2012-0179" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Double free vulnerability in tcpip.sys in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that binds an IPv6 address to a local interface, aka "TCP/IP Double Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-032" source="MS" patch="1" adv="1">MS12-032</ref>
      <ref url="http://www.securitytracker.com/id?1027044" source="SECTRACK">1027044</ref>
      <ref url="http://secunia.com/advisories/49114" source="SECUNIA">49114</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14908" source="OVAL">oval:org.mitre.oval:def:14908</ref>
      <ref url="http://osvdb.org/81729" source="OSVDB">81729</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="r2" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0180" published="2012-05-08" name="CVE-2012-0180" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode for (1) windows and (2) messages, which allows local users to gain privileges via a crafted application, aka "Windows and Messages Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securitytracker.com/id?1027039" source="SECTRACK">1027039</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-034" source="MS" adv="1">MS12-034</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15466" source="OVAL">oval:org.mitre.oval:def:15466</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0181" published="2012-05-08" name="CVE-2012-0181" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout File Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-034" source="MS" patch="1" adv="1">MS12-034</ref>
      <ref url="http://www.securitytracker.com/id?1027039" source="SECTRACK">1027039</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15355" source="OVAL">oval:org.mitre.oval:def:15355</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="-" edition="sp2"/>
        <vers num="r2" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0182" published="2012-10-09" name="CVE-2012-0182" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-283A.html" source="CERT">TA12-283A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-064" source="MS" patch="1" adv="1">MS12-064</ref>
      <ref url="http://www.securityfocus.com/bid/55780" source="BID">55780</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0183" published="2012-05-08" name="CVE-2012-0183" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-029" source="MS" patch="1" adv="1">MS12-029</ref>
      <ref url="http://www.securitytracker.com/id?1027035" source="SECTRACK">1027035</ref>
      <ref url="http://www.securityfocus.com/bid/53344" source="BID">53344</ref>
      <ref url="http://secunia.com/advisories/49111" source="SECUNIA">49111</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15327" source="OVAL">oval:org.mitre.oval:def:15327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0184" published="2012-05-08" name="CVE-2012-0184" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SXLI Record Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securitytracker.com/id?1027041" source="SECTRACK">1027041</ref>
      <ref url="http://www.securityfocus.com/bid/53375" source="BID">53375</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-030" source="MS" adv="1">MS12-030</ref>
      <ref url="http://secunia.com/advisories/49112" source="SECUNIA">49112</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14789" source="OVAL">oval:org.mitre.oval:def:14789</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2008"/>
        <vers num="2011" edition=""/>
        <vers num="2011" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0185" published="2012-05-08" name="CVE-2012-0185" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka "Excel MergeCells Record Heap Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-129A.html" source="CERT">TA12-129A</ref>
      <ref url="http://www.securitytracker.com/id?1027041" source="SECTRACK">1027041</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-030" source="MS" adv="1">MS12-030</ref>
      <ref url="http://secunia.com/advisories/49112" source="SECUNIA">49112</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14738" source="OVAL">oval:org.mitre.oval:def:14738</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0186" published="2012-06-22" name="CVE-2012-0186" modified="2012-06-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Eclipse Help component in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows remote attackers to discover the locations of files via a crafted URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72096" source="XF">lotusexpeditor-ehelp-dir-traversal(72096)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg21575642" source="CONFIRM" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21575642</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_expeditor">
        <vers num="6.1"/>
        <vers num="6.1.1"/>
        <vers num="6.2"/>
        <vers num="6.2.1"/>
        <vers num="6.2.2"/>
        <vers num="6.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0187" published="2012-06-22" name="CVE-2012-0187" modified="2012-06-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows local users to gain privileges via a Trojan horse DLL in the current working directory.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html 'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72097" source="XF">lotusexpeditor-dll-code-execution(72097)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg21575642" source="CONFIRM">http://www.ibm.com/support/docview.wss?uid=swg21575642</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_expeditor">
        <vers num="6.1"/>
        <vers num="6.1.1"/>
        <vers num="6.2"/>
        <vers num="6.2.1"/>
        <vers num="6.2.2"/>
        <vers num="6.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0188" published="2012-01-18" name="CVE-2012-0188" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SetLicenseInfoEx method in an ActiveX control in mraboutb.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.6, 6.0, and 6.0.1 allows remote attackers to execute arbitrary code via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72118" source="XF">spss-mraboutb-activex-code-execution(72118)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21577956" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21577956</ref>
      <ref url="http://secunia.com/advisories/47565" source="SECUNIA" adv="1">47565</ref>
      <ref url="http://osvdb.org/78329" source="OSVDB">78329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="spss_data_collection">
        <vers num="5.6"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
      </prod>
      <prod vendor="ibm" name="spss_dimensions">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0189" published="2012-01-18" name="CVE-2012-0189" modified="2012-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the (1) PrintFile and (2) SaveDoc methods in the VsVIEW6 ActiveX control in VsVIEW6.ocx in IBM SPSS SamplePower 3.0 allow remote attackers to execute arbitrary code via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72119" source="XF">spss-vsview6-activex-code-execution(72119)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg21577951" source="CONFIRM" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21577951</ref>
      <ref url="http://secunia.com/advisories/47605" source="SECUNIA" adv="1">47605</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="spss_samplepower">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0190" published="2012-01-18" name="CVE-2012-0190" modified="2012-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Render method in the ExportHTML.ocx ActiveX control in ExportHTML.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.6, 6.0, and 6.0.1 allows remote attackers to execute arbitrary code via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72121" source="XF">spss-wxporthtml-activex-code-execution(72121)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21577956" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21577956</ref>
      <ref url="http://secunia.com/advisories/47565" source="SECUNIA" adv="1">47565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="spss_data_collection">
        <vers num="5.6"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
      </prod>
      <prod vendor="ibm" name="spss_dimensions">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0191" published="2012-06-22" name="CVE-2012-0191" modified="2012-06-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which allows remote attackers to spoof a localhost request origin via crafted headers.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72156" source="XF">lotusexpeditor-acm-security-bypass(72156)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg21575642" source="CONFIRM" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21575642</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_expeditor">
        <vers num="6.1"/>
        <vers num="6.1.1"/>
        <vers num="6.2"/>
        <vers num="6.2.1"/>
        <vers num="6.2.2"/>
        <vers num="6.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0192" published="2012-01-23" name="CVE-2012-0192" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72424" source="XF">lotus-symphony-vclmi-bo(72424)</ref>
      <ref url="http://www.securityfocus.com/bid/51591" source="BID">51591</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21578684" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21578684</ref>
      <ref url="http://secunia.com/advisories/47245" source="SECUNIA" adv="1">47245</ref>
      <ref url="http://osvdb.org/78345" source="OSVDB">78345</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_symphony">
        <vers num="1.3"/>
        <vers num="3.0.0.1"/>
        <vers num="3.0.0.2"/>
        <vers prev="1" num="3.0.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0193" published="2012-01-19" name="CVE-2012-0193" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.43, 6.1 before 6.1.0.43, 7.0 before 7.0.0.23, and 8.0 before 8.0.0.3 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24031821" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg24031821</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21577532" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21577532</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM53930" source="AIXAPAR">PM53930</ref>
      <ref url="http://osvdb.org/78321" source="OSVDB">78321</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0.0.0"/>
        <vers num="6.0.0.2"/>
        <vers num="6.0.0.3"/>
        <vers num="6.0.1.0"/>
        <vers num="6.0.1.11"/>
        <vers num="6.0.1.12"/>
        <vers num="6.0.2.0"/>
        <vers num="6.0.2.1"/>
        <vers num="6.0.2.11"/>
        <vers num="6.0.2.13"/>
        <vers num="6.0.2.15"/>
        <vers num="6.0.2.17"/>
        <vers num="6.0.2.19"/>
        <vers num="6.0.2.2"/>
        <vers num="6.0.2.21"/>
        <vers num="6.0.2.23"/>
        <vers num="6.0.2.25"/>
        <vers num="6.0.2.27"/>
        <vers num="6.0.2.29"/>
        <vers num="6.0.2.3"/>
        <vers num="6.0.2.31"/>
        <vers num="6.0.2.33"/>
        <vers num="6.0.2.35"/>
        <vers num="6.0.2.37"/>
        <vers num="6.0.2.4"/>
        <vers num="6.0.2.43"/>
        <vers num="6.0.2.5"/>
        <vers num="6.0.2.6"/>
        <vers num="6.0.2.7"/>
        <vers num="6.0.2.8"/>
        <vers num="6.0.2.9"/>
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.11"/>
        <vers num="6.1.0.13"/>
        <vers num="6.1.0.14"/>
        <vers num="6.1.0.15"/>
        <vers num="6.1.0.17"/>
        <vers num="6.1.0.19"/>
        <vers num="6.1.0.21"/>
        <vers num="6.1.0.23"/>
        <vers num="6.1.0.25"/>
        <vers num="6.1.0.27"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.33"/>
        <vers num="6.1.0.35"/>
        <vers num="6.1.0.37"/>
        <vers num="6.1.0.39"/>
        <vers num="6.1.0.41"/>
        <vers num="6.1.0.5"/>
        <vers num="6.1.0.7"/>
        <vers num="6.1.0.9"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.15"/>
        <vers num="7.0.0.17"/>
        <vers num="7.0.0.19"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.21"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.9"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0194" published="2012-02-06" name="CVE-2012-0194" modified="2012-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The TCP implementation in IBM AIX 5.3, 6.1, and 7.1, when the Large Send Offload option is enabled, allows remote attackers to cause a denial of service (assertion failure and panic) via an unspecified series of packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/large_send_advisory.asc" source="CONFIRM" patch="1" adv="1">http://aix.software.ibm.com/aix/efixes/security/large_send_advisory.asc</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/72562" source="XF">aix-tcpstack-dos(72562)</ref>
      <ref url="http://www.securityfocus.com/bid/51864" source="BID">51864</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IV14211" source="AIXAPAR">IV14211</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IV14210" source="AIXAPAR">IV14210</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IV14209" source="AIXAPAR">IV14209</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IV13827" source="AIXAPAR">IV13827</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IV13820" source="AIXAPAR">IV13820</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IV13751" source="AIXAPAR">IV13751</ref>
      <ref url="http://securitytracker.com/id?1026640" source="SECTRACK">1026640</ref>
      <ref url="http://secunia.com/advisories/47865" source="SECUNIA" adv="1">47865</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3"/>
        <vers num="6.1"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0195" published="2012-03-12" name="CVE-2012-0195" modified="2012-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Start Center Layout and Configuration component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows remote attackers to inject arbitrary web script or HTML via the display name.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72612" source="XF">mam-sclc-xss(72612)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg21584666" source="CONFIRM" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21584666</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IV09198" source="AIXAPAR">IV09198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="maximo_asset_management">
        <vers num="6.2"/>
        <vers num="7.1"/>
        <vers num="7.5"/>
      </prod>
      <prod vendor="ibm" name="maximo_asset_management_essentials">
        <vers num="6.2"/>
        <vers num="7.1"/>
        <vers num="7.5"/>
      </prod>
      <prod vendor="ibm" name="maximo_service_desk">
        <vers num="6.2"/>
      </prod>
      <prod vendor="ibm" name="tivoli_asset_management_for_it">
        <vers num="6.2"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod vendor="ibm" name="tivoli_change_and_configuration_management_database">
        <vers num="6.2"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod vendor="ibm" name="trivoli_service_request_manager">
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0198" published="2012-03-05" name="CVE-2012-0198" modified="2012-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allows remote attackers to execute arbitrary code via vectors related to an Asset Information file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/73033" source="XF">tpme-isigisigctl1-bo(73033)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-12-040/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-12-040/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_provisioning_manager_express_for_software_distribution">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0199" published="2012-03-05" name="CVE-2012-0199" modified="2012-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allow remote attackers to execute arbitrary SQL commands via (1) a SOAP message to the Printer.getPrinterAgentKey function in the SoapServlet servlet, (2) the User.updateUserValue function in the register.do servlet, (3) the User.isExistingUser function in the logon.do servlet, (4) the Asset.getHWKey function in the CallHomeExec servlet, (5) the Asset.getMimeType function in the getAttachment (aka GetAttachmentServlet) servlet, (6) the addAsset.do servlet, or (7) a crafted EG2 file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/73034" source="XF">tpme-multiple-sql-injection(73034)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-12-040/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-12-040/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_provisioning_manager_express_for_software_distribution">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0200" published="2012-02-21" name="CVE-2012-0200" modified="2012-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The server in IBM solidDB 6.5 before Interim Fix 6 does not properly initialize data structures, which allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a redundant WHERE condition.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/73126" source="XF">soliddb-redundant-where-dos(73126)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg27021052" source="CONFIRM">http://www.ibm.com/support/docview.wss?uid=swg27021052</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC81244" source="AIXAPAR" adv="1">IC81244</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="soliddb">
        <vers num="6.5.0.0"/>
        <vers num="6.5.0.1"/>
        <vers num="6.5.0.2"/>
        <vers num="6.5.0.3"/>
        <vers num="6.5.0.4"/>
        <vers num="6.5.0.5"/>
        <vers num="6.5.0.6"/>
        <vers num="6.5.0.7"/>
        <vers prev="1" num="6.5.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0201" published="2012-03-02" name="CVE-2012-0201" modified="2012-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x before 6.0.4 might allow remote attackers to execute arbitrary code via a long profile string in a WorkStation (aka .ws) file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/73127" source="XF">pcom-pcspref-bo(73127)</ref>
      <ref url="http://www.stratsec.net/Research/Advisories/IBM-Personal-Communications-I-Series-Access-WorkSt" source="MISC">http://www.stratsec.net/Research/Advisories/IBM-Personal-Communications-I-Series-Access-WorkSt</ref>
      <ref url="http://www.metasploit.com/modules/exploit/windows/fileformat/ibm_pcm_ws" source="MISC">http://www.metasploit.com/modules/exploit/windows/fileformat/ibm_pcm_ws</ref>
      <ref url="http://www.exploit-db.com/exploits/18539/" source="EXPLOIT-DB">18539</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21586166" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21586166</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC81539" source="AIXAPAR">IC81539</ref>
      <ref url="http://dev.metasploit.com/redmine/projects/framework/repository/entry/modules/exploits/windows/fileformat/ibm_pcm_ws.rb" source="MISC">http://dev.metasploit.com/redmine/projects/framework/repository/entry/modules/exploits/windows/fileformat/ibm_pcm_ws.rb</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="personal_communications">
        <vers num="5.9.7.0"/>
        <vers num="5.9.7.1"/>
        <vers num="6.0.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0202" published="2012-05-04" name="CVE-2012-0202" modified="2012-05-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2 FP2 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/73182" source="XF">cognos-tm1admsd-bo(73182)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24032166" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg24032166</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24032165" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg24032165</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24032164" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg24032164</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21590314" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21590314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="cognos_tm1">
        <vers num="9.4.1"/>
        <vers num="9.4.1.3"/>
        <vers num="9.5.1"/>
        <vers num="9.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0203" published="2013-01-31" name="CVE-2012-0203" modified="2013-01-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/73254" source="XF">infosphere-mw-xss(73254)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21623501" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21623501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="infosphere_information_server">
        <vers num="8.1"/>
        <vers num="8.5"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.0.2"/>
      </prod>
      <prod vendor="ibm" name="infosphere_metadata_workbench">
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.1.2"/>
        <vers num="8.5"/>
        <vers num="8.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0204" published="2013-01-31" name="CVE-2012-0204" modified="2013-01-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers &amp; Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426 Untrusted Search Path'</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per:  http://www-01.ibm.com/support/docview.wss?uid=swg21623501

"CVSS Base Score: 9.3  / CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C)

a malicious user who has access to a machine with the Import Export Manager installed could execute arbitrary commands in the context of any user who accesses the Import Export Manager application. "</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/73255" source="XF">infosphere-is-dll-code-execution(73255)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21623501" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21623501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="infosphere_import_export_manager">
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.1.2"/>
        <vers num="8.5"/>
        <vers num="8.7"/>
        <vers num="9.1"/>
      </prod>
      <prod vendor="ibm" name="infosphere_information_server">
        <vers num="8.1"/>
        <vers num="8.5"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.0.2"/>
        <vers num="8.7"/>
        <vers num="9.1"/>
      </prod>
      <prod vendor="ibm" name="infosphere_information_server_metabrokers_&amp;_bridges">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0205" published="2013-01-31" name="CVE-2012-0205" modified="2013-01-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly restrict use of the troubleshooting feature, which allows remote authenticated users to bypass intended access restrictions or cause a denial of service (workbench outage) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/73265" source="XF">infosphere-mw-ts-security-bypass(73265)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21623501" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21623501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="infosphere_information_server">
        <vers num="8.1"/>
        <vers num="8.5"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.0.2"/>
        <vers num="8.7"/>
      </prod>
      <prod vendor="ibm" name="infosphere_metadata_workbench">
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.1.2"/>
        <vers num="8.5"/>
        <vers num="8.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0206" published="2012-02-17" name="CVE-2012-0206" modified="2012-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://doc.powerdns.com/powerdns-advisory-2012-01.html" source="CONFIRM" patch="1" adv="1">http://doc.powerdns.com/powerdns-advisory-2012-01.html</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=772570" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=772570</ref>
      <ref url="http://doc.powerdns.com/changelog.html" source="CONFIRM">http://doc.powerdns.com/changelog.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerdns" name="powerdns">
        <vers num="1.99.1"/>
        <vers num="1.99.10"/>
        <vers num="1.99.11"/>
        <vers num="1.99.12"/>
        <vers num="1.99.2"/>
        <vers num="1.99.3"/>
        <vers num="1.99.4"/>
        <vers num="1.99.5"/>
        <vers num="1.99.6"/>
        <vers num="1.99.7"/>
        <vers num="1.99.8"/>
        <vers num="1.99.9"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.5.1"/>
        <vers num="2.6"/>
        <vers num="2.6.1"/>
        <vers num="2.7"/>
        <vers num="2.7.1"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
        <vers num="2.9.1"/>
        <vers num="2.9.10"/>
        <vers num="2.9.11"/>
        <vers num="2.9.12"/>
        <vers num="2.9.13"/>
        <vers num="2.9.14"/>
        <vers num="2.9.15"/>
        <vers num="2.9.16"/>
        <vers num="2.9.17"/>
        <vers num="2.9.18"/>
        <vers num="2.9.19"/>
        <vers num="2.9.2"/>
        <vers num="2.9.20"/>
        <vers num="2.9.21"/>
        <vers num="2.9.21.1"/>
        <vers num="2.9.21.2"/>
        <vers prev="1" num="2.9.22"/>
        <vers num="2.9.3a"/>
        <vers num="2.9.4"/>
        <vers num="2.9.5"/>
        <vers num="2.9.6"/>
        <vers num="2.9.7"/>
        <vers num="2.9.8"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0207" published="2012-05-17" name="CVE-2012-0207" modified="2012-05-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and panic) via IGMP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/a8c1f65c79cbbb2f7da782d4c9d15639a9b94b27" source="CONFIRM">https://github.com/torvalds/linux/commit/a8c1f65c79cbbb2f7da782d4c9d15639a9b94b27</ref>
      <ref url="https://github.com/torvalds/linux/commit/25c413ad0029ea86008234be28aee33456e53e5b" source="CONFIRM">https://github.com/torvalds/linux/commit/25c413ad0029ea86008234be28aee33456e53e5b</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=772867" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=772867</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/01/10/5" source="MLIST">[oss-security] 20120110 CVE-2012-0207 kernel: igmp: Avoid zero delay when receiving odd mixture of IGMP queries</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.1</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a8c1f65c79cbbb2f7da782d4c9d15639a9b94b27" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a8c1f65c79cbbb2f7da782d4c9d15639a9b94b27</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=654876" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=654876</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="1.2.0"/>
        <vers num="1.3.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.2"/>
        <vers num="2.0.20"/>
        <vers num="2.0.21"/>
        <vers num="2.0.22"/>
        <vers num="2.0.23"/>
        <vers num="2.0.24"/>
        <vers num="2.0.25"/>
        <vers num="2.0.26"/>
        <vers num="2.0.27"/>
        <vers num="2.0.28"/>
        <vers num="2.0.29"/>
        <vers num="2.0.3"/>
        <vers num="2.0.30"/>
        <vers num="2.0.31"/>
        <vers num="2.0.32"/>
        <vers num="2.0.33"/>
        <vers num="2.0.34"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1.132"/>
        <vers num="2.1.89"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13" edition="pre15"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15" edition="pre16"/>
        <vers num="2.2.16" edition="pre5"/>
        <vers num="2.2.16" edition="pre6"/>
        <vers num="2.2.17" edition="pre14"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.2.2"/>
        <vers num="2.2.20"/>
        <vers num="2.2.21" edition="pre1"/>
        <vers num="2.2.21" edition="pre2"/>
        <vers num="2.2.21" edition="pre3"/>
        <vers num="2.2.21" edition="pre4"/>
        <vers num="2.2.21" edition="rc1"/>
        <vers num="2.2.21" edition="rc2"/>
        <vers num="2.2.21" edition="rc3"/>
        <vers num="2.2.21" edition="rc4"/>
        <vers num="2.2.22" edition="rc1"/>
        <vers num="2.2.22" edition="rc2"/>
        <vers num="2.2.22" edition="rc3"/>
        <vers num="2.2.23" edition="rc1"/>
        <vers num="2.2.23" edition="rc2"/>
        <vers num="2.2.24" edition="rc2"/>
        <vers num="2.2.24" edition="rc3"/>
        <vers num="2.2.24" edition="rc4"/>
        <vers num="2.2.24" edition="rc5"/>
        <vers num="2.2.25"/>
        <vers num="2.2.26"/>
        <vers num="2.2.27" edition="pre1"/>
        <vers num="2.2.27" edition="pre2"/>
        <vers num="2.2.27" edition="rc1"/>
        <vers num="2.2.27" edition="rc2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4" edition="rc1"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.3.15"/>
        <vers num="2.3.16"/>
        <vers num="2.3.17"/>
        <vers num="2.3.18"/>
        <vers num="2.3.19"/>
        <vers num="2.3.2"/>
        <vers num="2.3.20"/>
        <vers num="2.3.21"/>
        <vers num="2.3.22"/>
        <vers num="2.3.23"/>
        <vers num="2.3.24"/>
        <vers num="2.3.25"/>
        <vers num="2.3.26"/>
        <vers num="2.3.27"/>
        <vers num="2.3.28"/>
        <vers num="2.3.29"/>
        <vers num="2.3.3"/>
        <vers num="2.3.30"/>
        <vers num="2.3.31"/>
        <vers num="2.3.32"/>
        <vers num="2.3.33"/>
        <vers num="2.3.34"/>
        <vers num="2.3.35"/>
        <vers num="2.3.36"/>
        <vers num="2.3.37"/>
        <vers num="2.3.38"/>
        <vers num="2.3.39"/>
        <vers num="2.3.4"/>
        <vers num="2.3.40"/>
        <vers num="2.3.41"/>
        <vers num="2.3.42"/>
        <vers num="2.3.43"/>
        <vers num="2.3.44"/>
        <vers num="2.3.45"/>
        <vers num="2.3.46"/>
        <vers num="2.3.47"/>
        <vers num="2.3.48"/>
        <vers num="2.3.49"/>
        <vers num="2.3.5"/>
        <vers num="2.3.50"/>
        <vers num="2.3.51"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.3.99" edition="pre1"/>
        <vers num="2.3.99" edition="pre2"/>
        <vers num="2.3.99" edition="pre3"/>
        <vers num="2.3.99" edition="pre4"/>
        <vers num="2.3.99" edition="pre5"/>
        <vers num="2.3.99" edition="pre6"/>
        <vers num="2.3.99" edition="pre7"/>
        <vers num="2.3.99" edition="pre8"/>
        <vers num="2.3.99" edition="pre9"/>
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11" edition="pre3"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.18" edition="pre9"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22" edition="pre10"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.24"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27" edition="pre1"/>
        <vers num="2.4.27" edition="pre2"/>
        <vers num="2.4.27" edition="pre3"/>
        <vers num="2.4.27" edition="pre4"/>
        <vers num="2.4.27" edition="pre5"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29" edition="rc1"/>
        <vers num="2.4.29" edition="rc2"/>
        <vers num="2.4.3" edition="pre3"/>
        <vers num="2.4.30" edition="rc2"/>
        <vers num="2.4.30" edition="rc3"/>
        <vers num="2.4.31" edition="pre1"/>
        <vers num="2.4.32" edition="pre1"/>
        <vers num="2.4.32" edition="pre2"/>
        <vers num="2.4.33" edition="pre1"/>
        <vers num="2.4.33.2"/>
        <vers num="2.4.33.3"/>
        <vers num="2.4.33.4"/>
        <vers num="2.4.33.5"/>
        <vers num="2.4.34" edition="rc3"/>
        <vers num="2.4.34.1"/>
        <vers num="2.4.34.2"/>
        <vers num="2.4.35"/>
        <vers num="2.4.35.2"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.12"/>
        <vers num="2.5.13"/>
        <vers num="2.5.14"/>
        <vers num="2.5.15"/>
        <vers num="2.5.16"/>
        <vers num="2.5.17"/>
        <vers num="2.5.18"/>
        <vers num="2.5.19"/>
        <vers num="2.5.2"/>
        <vers num="2.5.20"/>
        <vers num="2.5.21"/>
        <vers num="2.5.22"/>
        <vers num="2.5.23"/>
        <vers num="2.5.24"/>
        <vers num="2.5.25"/>
        <vers num="2.5.26"/>
        <vers num="2.5.27"/>
        <vers num="2.5.28"/>
        <vers num="2.5.29"/>
        <vers num="2.5.3"/>
        <vers num="2.5.30"/>
        <vers num="2.5.31"/>
        <vers num="2.5.32"/>
        <vers num="2.5.33"/>
        <vers num="2.5.34"/>
        <vers num="2.5.35"/>
        <vers num="2.5.36"/>
        <vers num="2.5.37"/>
        <vers num="2.5.38"/>
        <vers num="2.5.39"/>
        <vers num="2.5.4"/>
        <vers num="2.5.40"/>
        <vers num="2.5.41"/>
        <vers num="2.5.42"/>
        <vers num="2.5.43"/>
        <vers num="2.5.44"/>
        <vers num="2.5.45"/>
        <vers num="2.5.46"/>
        <vers num="2.5.47"/>
        <vers num="2.5.48"/>
        <vers num="2.5.49"/>
        <vers num="2.5.5"/>
        <vers num="2.5.50"/>
        <vers num="2.5.51"/>
        <vers num="2.5.52"/>
        <vers num="2.5.53"/>
        <vers num="2.5.54"/>
        <vers num="2.5.55"/>
        <vers num="2.5.56"/>
        <vers num="2.5.57"/>
        <vers num="2.5.58"/>
        <vers num="2.5.59"/>
        <vers num="2.5.6"/>
        <vers num="2.5.60"/>
        <vers num="2.5.61"/>
        <vers num="2.5.62"/>
        <vers num="2.5.63"/>
        <vers num="2.5.64"/>
        <vers num="2.5.65"/>
        <vers num="2.5.66"/>
        <vers num="2.5.67"/>
        <vers num="2.5.68"/>
        <vers num="2.5.69"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.1" edition="rc3"/>
        <vers num="2.6.10" edition="rc1"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.10" edition="rc3"/>
        <vers num="2.6.11" edition="rc1"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
        <vers num="2.6.11" edition="rc4"/>
        <vers num="2.6.11" edition="rc5"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.10"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.11.9"/>
        <vers num="2.6.12" edition="rc1"/>
        <vers num="2.6.12" edition="rc2"/>
        <vers num="2.6.12" edition="rc3"/>
        <vers num="2.6.12" edition="rc4"/>
        <vers num="2.6.12" edition="rc5"/>
        <vers num="2.6.12" edition="rc6"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13" edition="rc1"/>
        <vers num="2.6.13" edition="rc2"/>
        <vers num="2.6.13" edition="rc3"/>
        <vers num="2.6.13" edition="rc4"/>
        <vers num="2.6.13" edition="rc5"/>
        <vers num="2.6.13" edition="rc6"/>
        <vers num="2.6.13" edition="rc7"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.13.5"/>
        <vers num="2.6.14" edition="rc1"/>
        <vers num="2.6.14" edition="rc2"/>
        <vers num="2.6.14" edition="rc3"/>
        <vers num="2.6.14" edition="rc4"/>
        <vers num="2.6.14" edition="rc5"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.14.5"/>
        <vers num="2.6.14.6"/>
        <vers num="2.6.14.7"/>
        <vers num="2.6.15" edition="rc1"/>
        <vers num="2.6.15" edition="rc2"/>
        <vers num="2.6.15" edition="rc3"/>
        <vers num="2.6.15" edition="rc4"/>
        <vers num="2.6.15" edition="rc5"/>
        <vers num="2.6.15" edition="rc6"/>
        <vers num="2.6.15" edition="rc7"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.10"/>
        <vers num="2.6.15.11"/>
        <vers num="2.6.15.2"/>
        <vers num="2.6.15.3"/>
        <vers num="2.6.15.4"/>
        <vers num="2.6.15.5"/>
        <vers num="2.6.15.6"/>
        <vers num="2.6.15.7"/>
        <vers num="2.6.15.8"/>
        <vers num="2.6.15.9"/>
        <vers num="2.6.16" edition="rc1"/>
        <vers num="2.6.16" edition="rc2"/>
        <vers num="2.6.16" edition="rc3"/>
        <vers num="2.6.16" edition="rc4"/>
        <vers num="2.6.16" edition="rc5"/>
        <vers num="2.6.16" edition="rc6"/>
        <vers num="2.6.16" edition="rc7"/>
        <vers num="2.6.16.1"/>
        <vers num="2.6.16.10"/>
        <vers num="2.6.16.11"/>
        <vers num="2.6.16.12"/>
        <vers num="2.6.16.13"/>
        <vers num="2.6.16.14"/>
        <vers num="2.6.16.15"/>
        <vers num="2.6.16.16"/>
        <vers num="2.6.16.17"/>
        <vers num="2.6.16.18"/>
        <vers num="2.6.16.19"/>
        <vers num="2.6.16.2"/>
        <vers num="2.6.16.20"/>
        <vers num="2.6.16.21"/>
        <vers num="2.6.16.22"/>
        <vers num="2.6.16.23"/>
        <vers num="2.6.16.24"/>
        <vers num="2.6.16.25"/>
        <vers num="2.6.16.26"/>
        <vers num="2.6.16.27"/>
        <vers num="2.6.16.28"/>
        <vers num="2.6.16.29"/>
        <vers num="2.6.16.3"/>
        <vers num="2.6.16.30"/>
        <vers num="2.6.16.31"/>
        <vers num="2.6.16.32"/>
        <vers num="2.6.16.33"/>
        <vers num="2.6.16.34"/>
        <vers num="2.6.16.35"/>
        <vers num="2.6.16.36"/>
        <vers num="2.6.16.37"/>
        <vers num="2.6.16.38"/>
        <vers num="2.6.16.39"/>
        <vers num="2.6.16.4"/>
        <vers num="2.6.16.40"/>
        <vers num="2.6.16.41"/>
        <vers num="2.6.16.42"/>
        <vers num="2.6.16.43"/>
        <vers num="2.6.16.44"/>
        <vers num="2.6.16.45"/>
        <vers num="2.6.16.46"/>
        <vers num="2.6.16.47"/>
        <vers num="2.6.16.48"/>
        <vers num="2.6.16.49"/>
        <vers num="2.6.16.5"/>
        <vers num="2.6.16.50"/>
        <vers num="2.6.16.51"/>
        <vers num="2.6.16.52"/>
        <vers num="2.6.16.53"/>
        <vers num="2.6.16.54"/>
        <vers num="2.6.16.55"/>
        <vers num="2.6.16.56"/>
        <vers num="2.6.16.57"/>
        <vers num="2.6.16.58"/>
        <vers num="2.6.16.59"/>
        <vers num="2.6.16.6"/>
        <vers num="2.6.16.60"/>
        <vers num="2.6.16.61"/>
        <vers num="2.6.16.62"/>
        <vers num="2.6.16.7"/>
        <vers num="2.6.16.8"/>
        <vers num="2.6.16.9"/>
        <vers num="2.6.17" edition="rc1"/>
        <vers num="2.6.17" edition="rc2"/>
        <vers num="2.6.17" edition="rc3"/>
        <vers num="2.6.17" edition="rc4"/>
        <vers num="2.6.17" edition="rc5"/>
        <vers num="2.6.17" edition="rc6"/>
        <vers num="2.6.17.1"/>
        <vers num="2.6.17.10"/>
        <vers num="2.6.17.11"/>
        <vers num="2.6.17.12"/>
        <vers num="2.6.17.13"/>
        <vers num="2.6.17.14"/>
        <vers num="2.6.17.2"/>
        <vers num="2.6.17.3"/>
        <vers num="2.6.17.4"/>
        <vers num="2.6.17.5"/>
        <vers num="2.6.17.6"/>
        <vers num="2.6.17.7"/>
        <vers num="2.6.17.8"/>
        <vers num="2.6.17.9"/>
        <vers num="2.6.18" edition="rc1"/>
        <vers num="2.6.18" edition="rc2"/>
        <vers num="2.6.18" edition="rc3"/>
        <vers num="2.6.18" edition="rc4"/>
        <vers num="2.6.18" edition="rc5"/>
        <vers num="2.6.18" edition="rc6"/>
        <vers num="2.6.18" edition="rc7"/>
        <vers num="2.6.18.1"/>
        <vers num="2.6.18.2"/>
        <vers num="2.6.18.3"/>
        <vers num="2.6.18.4"/>
        <vers num="2.6.18.5"/>
        <vers num="2.6.18.6"/>
        <vers num="2.6.18.7"/>
        <vers num="2.6.18.8"/>
        <vers num="2.6.19" edition="rc1"/>
        <vers num="2.6.19" edition="rc2"/>
        <vers num="2.6.19" edition="rc3"/>
        <vers num="2.6.19" edition="rc4"/>
        <vers num="2.6.19.1"/>
        <vers num="2.6.19.2"/>
        <vers num="2.6.19.3"/>
        <vers num="2.6.19.4"/>
        <vers num="2.6.19.5"/>
        <vers num="2.6.19.6"/>
        <vers num="2.6.19.7"/>
        <vers num="2.6.2" edition="rc1"/>
        <vers num="2.6.2" edition="rc2"/>
        <vers num="2.6.2" edition="rc3"/>
        <vers num="2.6.20" edition="rc2"/>
        <vers num="2.6.20.1"/>
        <vers num="2.6.20.10"/>
        <vers num="2.6.20.11"/>
        <vers num="2.6.20.12"/>
        <vers num="2.6.20.13"/>
        <vers num="2.6.20.14"/>
        <vers num="2.6.20.15"/>
        <vers num="2.6.20.16"/>
        <vers num="2.6.20.17"/>
        <vers num="2.6.20.18"/>
        <vers num="2.6.20.19"/>
        <vers num="2.6.20.2"/>
        <vers num="2.6.20.20"/>
        <vers num="2.6.20.21"/>
        <vers num="2.6.20.3"/>
        <vers num="2.6.20.4"/>
        <vers num="2.6.20.5"/>
        <vers num="2.6.20.6"/>
        <vers num="2.6.20.7"/>
        <vers num="2.6.20.8"/>
        <vers num="2.6.20.9"/>
        <vers num="2.6.21" edition="git1"/>
        <vers num="2.6.21" edition="git2"/>
        <vers num="2.6.21" edition="git3"/>
        <vers num="2.6.21" edition="git4"/>
        <vers num="2.6.21" edition="git5"/>
        <vers num="2.6.21" edition="git6"/>
        <vers num="2.6.21" edition="git7"/>
        <vers num="2.6.21" edition="rc3"/>
        <vers num="2.6.21" edition="rc4"/>
        <vers num="2.6.21" edition="rc5"/>
        <vers num="2.6.21" edition="rc6"/>
        <vers num="2.6.21" edition="rc7"/>
        <vers num="2.6.21.1"/>
        <vers num="2.6.21.2"/>
        <vers num="2.6.21.3"/>
        <vers num="2.6.21.4"/>
        <vers num="2.6.21.5"/>
        <vers num="2.6.21.6"/>
        <vers num="2.6.21.7"/>
        <vers num="2.6.22"/>
        <vers num="2.6.22.1"/>
        <vers num="2.6.22.10"/>
        <vers num="2.6.22.11"/>
        <vers num="2.6.22.12"/>
        <vers num="2.6.22.13"/>
        <vers num="2.6.22.14"/>
        <vers num="2.6.22.15"/>
        <vers num="2.6.22.16"/>
        <vers num="2.6.22.17"/>
        <vers num="2.6.22.18"/>
        <vers num="2.6.22.19"/>
        <vers num="2.6.22.2"/>
        <vers num="2.6.22.20"/>
        <vers num="2.6.22.3"/>
        <vers num="2.6.22.4"/>
        <vers num="2.6.22.5"/>
        <vers num="2.6.22.6"/>
        <vers num="2.6.22.7"/>
        <vers num="2.6.22.8"/>
        <vers num="2.6.27.41"/>
        <vers num="2.6.27.42"/>
        <vers num="2.6.27.43"/>
        <vers num="2.6.27.44"/>
        <vers num="2.6.27.45"/>
        <vers num="2.6.27.46"/>
        <vers num="2.6.27.47"/>
        <vers num="2.6.27.48"/>
        <vers num="2.6.27.49"/>
        <vers num="2.6.27.5"/>
        <vers num="2.6.27.50"/>
        <vers num="2.6.27.51"/>
        <vers num="2.6.27.52"/>
        <vers num="2.6.27.53"/>
        <vers num="2.6.27.54"/>
        <vers num="2.6.27.55"/>
        <vers num="2.6.27.56"/>
        <vers num="2.6.27.57"/>
        <vers num="2.6.27.58"/>
        <vers num="2.6.27.59"/>
        <vers num="2.6.27.6"/>
        <vers num="2.6.27.60"/>
        <vers num="2.6.27.61"/>
        <vers num="2.6.27.62"/>
        <vers num="2.6.27.7"/>
        <vers num="2.6.27.8"/>
        <vers num="2.6.27.9"/>
        <vers num="2.6.28"/>
        <vers num="2.6.28.1"/>
        <vers num="2.6.28.10"/>
        <vers num="2.6.28.2"/>
        <vers num="2.6.28.3"/>
        <vers num="2.6.28.4"/>
        <vers num="2.6.28.5"/>
        <vers num="2.6.28.6"/>
        <vers num="2.6.28.7"/>
        <vers num="2.6.28.8"/>
        <vers num="2.6.28.9"/>
        <vers num="2.6.29"/>
        <vers num="2.6.29.1"/>
        <vers num="2.6.29.2"/>
        <vers num="2.6.29.3"/>
        <vers num="2.6.29.4"/>
        <vers num="2.6.29.5"/>
        <vers num="2.6.29.6"/>
        <vers num="2.6.3" edition="rc1"/>
        <vers num="2.6.3" edition="rc2"/>
        <vers num="2.6.3" edition="rc3"/>
        <vers num="2.6.3" edition="rc4"/>
        <vers num="2.6.32"/>
        <vers num="2.6.32.1"/>
        <vers num="2.6.32.10"/>
        <vers num="2.6.32.11"/>
        <vers num="2.6.32.12"/>
        <vers num="2.6.32.13"/>
        <vers num="2.6.32.14"/>
        <vers num="2.6.32.15"/>
        <vers num="2.6.32.16"/>
        <vers num="2.6.32.17"/>
        <vers num="2.6.32.18"/>
        <vers num="2.6.32.2"/>
        <vers num="2.6.32.28"/>
        <vers num="2.6.32.29"/>
        <vers num="2.6.32.3"/>
        <vers num="2.6.32.30"/>
        <vers num="2.6.32.31"/>
        <vers num="2.6.32.32"/>
        <vers num="2.6.32.33"/>
        <vers num="2.6.32.34"/>
        <vers num="2.6.32.35"/>
        <vers num="2.6.32.36"/>
        <vers num="2.6.32.37"/>
        <vers num="2.6.32.38"/>
        <vers num="2.6.32.39"/>
        <vers num="2.6.32.4"/>
        <vers num="2.6.32.40"/>
        <vers num="2.6.32.41"/>
        <vers num="2.6.32.42"/>
        <vers num="2.6.32.43"/>
        <vers num="2.6.32.44"/>
        <vers num="2.6.32.45"/>
        <vers num="2.6.32.46"/>
        <vers num="2.6.32.47"/>
        <vers num="2.6.32.48"/>
        <vers num="2.6.32.49"/>
        <vers num="2.6.32.5"/>
        <vers num="2.6.32.50"/>
        <vers num="2.6.32.51"/>
        <vers num="2.6.32.52"/>
        <vers num="2.6.32.53"/>
        <vers num="2.6.32.54"/>
        <vers num="2.6.32.55"/>
        <vers num="2.6.32.56"/>
        <vers num="2.6.32.57"/>
        <vers num="2.6.32.58"/>
        <vers num="2.6.32.6"/>
        <vers num="2.6.32.7"/>
        <vers num="2.6.32.8"/>
        <vers num="2.6.32.9"/>
        <vers num="2.6.33.10"/>
        <vers num="2.6.33.11"/>
        <vers num="2.6.33.12"/>
        <vers num="2.6.33.13"/>
        <vers num="2.6.33.14"/>
        <vers num="2.6.33.15"/>
        <vers num="2.6.33.16"/>
        <vers num="2.6.33.17"/>
        <vers num="2.6.33.18"/>
        <vers num="2.6.33.19"/>
        <vers num="2.6.33.20"/>
        <vers num="2.6.33.8"/>
        <vers num="2.6.33.9"/>
        <vers num="2.6.34.1"/>
        <vers num="2.6.34.10"/>
        <vers num="2.6.34.2"/>
        <vers num="2.6.34.3"/>
        <vers num="2.6.34.8"/>
        <vers num="2.6.34.9"/>
        <vers num="2.6.35.1"/>
        <vers num="2.6.35.10"/>
        <vers num="2.6.35.11"/>
        <vers num="2.6.35.12"/>
        <vers num="2.6.35.13"/>
        <vers num="2.6.37" edition="rc1"/>
        <vers num="2.6.37" edition="rc2"/>
        <vers num="2.6.37" edition="rc3"/>
        <vers num="2.6.37" edition="rc4"/>
        <vers num="2.6.37" edition="rc5"/>
        <vers num="2.6.38" edition="rc1"/>
        <vers num="2.6.38" edition="rc2"/>
        <vers num="2.6.38" edition="rc3"/>
        <vers num="2.6.38" edition="rc4"/>
        <vers num="2.6.38" edition="rc5"/>
        <vers num="2.6.38" edition="rc6"/>
        <vers num="2.6.38" edition="rc7"/>
        <vers num="2.6.38" edition="rc8"/>
        <vers num="2.6.39" edition="rc1"/>
        <vers num="2.6.39" edition="rc2"/>
        <vers num="2.6.39" edition="rc3"/>
        <vers num="2.6.39" edition="rc4"/>
        <vers num="2.6.39" edition="rc5"/>
        <vers num="2.6.39" edition="rc6"/>
        <vers num="2.6.39" edition="rc7"/>
        <vers num="2.6.4" edition="rc1"/>
        <vers num="2.6.4" edition="rc2"/>
        <vers num="2.6.4" edition="rc3"/>
        <vers num="2.6.5" edition="rc1"/>
        <vers num="2.6.5" edition="rc2"/>
        <vers num="2.6.5" edition="rc3"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.6" edition="rc2"/>
        <vers num="2.6.6" edition="rc3"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.7" edition="rc2"/>
        <vers num="2.6.7" edition="rc3"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.8" edition="rc4"/>
        <vers num="2.6.8.1"/>
        <vers num="2.6.9" edition="rc1"/>
        <vers num="2.6.9" edition="rc2"/>
        <vers num="2.6.9" edition="rc3"/>
        <vers num="2.6.9" edition="rc4"/>
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers prev="1" num="3.2" edition="rc2"/>
        <vers prev="1" num="3.2" edition="rc3"/>
        <vers prev="1" num="3.2" edition="rc4"/>
        <vers prev="1" num="3.2" edition="rc5"/>
        <vers prev="1" num="3.2" edition="rc6"/>
        <vers prev="1" num="3.2" edition="rc7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0208" published="2012-05-03" name="CVE-2012-0208" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Grid Engine component in Oracle Sun Products Suite 6.1 and 6.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to qrsh.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1026950" source="SECTRACK">1026950</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2472" source="DEBIAN">DSA-2472</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_products_suite">
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0209" published="2012-09-25" name="CVE-2012-0209" modified="2012-09-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote attackers to execute arbitrary PHP code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=790877" source="MISC" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=790877</ref>
      <ref url="http://lists.horde.org/archives/announce/2012/000751.html" source="MLIST" patch="1">[horde-announce] 20120213 [SECURITY] Remote execution backdoor after server hack (CVE-2012-0209)</ref>
      <ref url="http://dev.horde.org/h/jonah/stories/view.php?channel_id=1&amp;id=155" source="CONFIRM" patch="1" adv="1">http://dev.horde.org/h/jonah/stories/view.php?channel_id=1&amp;id=155</ref>
      <ref url="http://packetstormsecurity.org/files/109874/Horde-3.3.12-Backdoor-Arbitrary-PHP-Code-Execution.html" source="MISC">http://packetstormsecurity.org/files/109874/Horde-3.3.12-Backdoor-Arbitrary-PHP-Code-Execution.html</ref>
      <ref url="http://eromang.zataz.com/2012/02/15/cve-2012-0209-horde-backdoor-analysis/" source="MISC">http://eromang.zataz.com/2012/02/15/cve-2012-0209-horde-backdoor-analysis/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="groupware">
        <vers num="1.2.10" edition=""/>
        <vers num="1.2.10" edition=":webmail"/>
      </prod>
      <prod vendor="horde" name="horde">
        <vers num="3.3.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0210" published="2012-06-15" name="CVE-2012-0210" modified="2012-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the file name in a (1) .dsc or (2) .changes file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git;a=commitdiff;h=797ddc961532eb0aeb46153e3f28c8e9ea0500d2" source="CONFIRM" patch="1">http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git;a=commitdiff;h=797ddc961532eb0aeb46153e3f28c8e9ea0500d2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/73215" source="XF">devscripts-dsc-code-execution(73215)</ref>
      <ref url="http://www.securityfocus.com/bid/52029" source="BID">52029</ref>
      <ref url="http://www.osvdb.org/79319" source="OSVDB">79319</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2409" source="DEBIAN">DSA-2409</ref>
      <ref url="http://ubuntu.com/usn/usn-1366-1" source="UBUNTU" adv="1">USN-1366-1</ref>
      <ref url="http://secunia.com/advisories/48039" source="SECUNIA" adv="1">48039</ref>
      <ref url="http://secunia.com/advisories/47955" source="SECUNIA" adv="1">47955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devscripts_devel_team" name="devscripts">
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.10"/>
        <vers num="2.10.11"/>
        <vers num="2.10.12"/>
        <vers num="2.10.13"/>
        <vers num="2.10.14"/>
        <vers num="2.10.15"/>
        <vers num="2.10.16"/>
        <vers num="2.10.17"/>
        <vers num="2.10.18"/>
        <vers num="2.10.18.1"/>
        <vers num="2.10.19"/>
        <vers num="2.10.20"/>
        <vers num="2.10.21"/>
        <vers num="2.10.22"/>
        <vers num="2.10.23"/>
        <vers num="2.10.24"/>
        <vers num="2.10.25"/>
        <vers num="2.10.26"/>
        <vers num="2.10.27"/>
        <vers num="2.10.28"/>
        <vers num="2.10.29"/>
        <vers num="2.10.3"/>
        <vers num="2.10.30"/>
        <vers num="2.10.31"/>
        <vers num="2.10.32"/>
        <vers num="2.10.33"/>
        <vers num="2.10.34"/>
        <vers num="2.10.35"/>
        <vers num="2.10.36"/>
        <vers num="2.10.38"/>
        <vers num="2.10.39"/>
        <vers num="2.10.40"/>
        <vers num="2.10.41"/>
        <vers num="2.10.42"/>
        <vers num="2.10.43"/>
        <vers num="2.10.44"/>
        <vers num="2.10.45"/>
        <vers num="2.10.46"/>
        <vers num="2.10.47"/>
        <vers num="2.10.48"/>
        <vers num="2.10.49"/>
        <vers num="2.10.50"/>
        <vers num="2.10.51"/>
        <vers num="2.10.52"/>
        <vers num="2.10.53"/>
        <vers num="2.10.54"/>
        <vers num="2.10.55"/>
        <vers num="2.10.56"/>
        <vers num="2.10.57"/>
        <vers num="2.10.58"/>
        <vers num="2.10.59"/>
        <vers num="2.10.6"/>
        <vers num="2.10.60"/>
        <vers num="2.10.61"/>
        <vers num="2.10.62"/>
        <vers num="2.10.63"/>
        <vers num="2.10.64"/>
        <vers num="2.10.65.1"/>
        <vers num="2.10.66"/>
        <vers num="2.10.67"/>
        <vers num="2.10.68"/>
        <vers num="2.10.7"/>
        <vers num="2.10.8"/>
        <vers num="2.10.9"/>
        <vers num="2.11.0"/>
        <vers num="2.11.1"/>
        <vers num="2.11.2"/>
        <vers num="2.11.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0211" published="2012-06-15" name="CVE-2012-0211" modified="2012-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level directory of an original (.orig) source tarball of a source package.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git;a=commitdiff;h=87f88232eb643f0c118c6ba38db8e966915b450f" source="CONFIRM" patch="1">http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git;a=commitdiff;h=87f88232eb643f0c118c6ba38db8e966915b450f</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/73216" source="XF">devscripts-commands-code-execution(73216)</ref>
      <ref url="http://www.securityfocus.com/bid/52029" source="BID">52029</ref>
      <ref url="http://www.osvdb.org/79320" source="OSVDB">79320</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2409" source="DEBIAN">DSA-2409</ref>
      <ref url="http://ubuntu.com/usn/usn-1366-1" source="UBUNTU">USN-1366-1</ref>
      <ref url="http://secunia.com/advisories/48039" source="SECUNIA" adv="1">48039</ref>
      <ref url="http://secunia.com/advisories/47955" source="SECUNIA" adv="1">47955</ref>
      <ref url="http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git;a=commitdiff;h=9cbe605d3eab4f9e67525f69b676c55b273b7a03" source="CONFIRM">http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git;a=commitdiff;h=9cbe605d3eab4f9e67525f69b676c55b273b7a03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devscripts_devel_team" name="devscripts">
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.10"/>
        <vers num="2.10.11"/>
        <vers num="2.10.12"/>
        <vers num="2.10.13"/>
        <vers num="2.10.14"/>
        <vers num="2.10.15"/>
        <vers num="2.10.16"/>
        <vers num="2.10.17"/>
        <vers num="2.10.18"/>
        <vers num="2.10.18.1"/>
        <vers num="2.10.19"/>
        <vers num="2.10.20"/>
        <vers num="2.10.21"/>
        <vers num="2.10.22"/>
        <vers num="2.10.23"/>
        <vers num="2.10.24"/>
        <vers num="2.10.25"/>
        <vers num="2.10.26"/>
        <vers num="2.10.27"/>
        <vers num="2.10.28"/>
        <vers num="2.10.29"/>
        <vers num="2.10.3"/>
        <vers num="2.10.30"/>
        <vers num="2.10.31"/>
        <vers num="2.10.32"/>
        <vers num="2.10.33"/>
        <vers num="2.10.34"/>
        <vers num="2.10.35"/>
        <vers num="2.10.36"/>
        <vers num="2.10.38"/>
        <vers num="2.10.39"/>
        <vers num="2.10.40"/>
        <vers num="2.10.41"/>
        <vers num="2.10.42"/>
        <vers num="2.10.43"/>
        <vers num="2.10.44"/>
        <vers num="2.10.45"/>
        <vers num="2.10.46"/>
        <vers num="2.10.47"/>
        <vers num="2.10.48"/>
        <vers num="2.10.49"/>
        <vers num="2.10.50"/>
        <vers num="2.10.51"/>
        <vers num="2.10.52"/>
        <vers num="2.10.53"/>
        <vers num="2.10.54"/>
        <vers num="2.10.55"/>
        <vers num="2.10.56"/>
        <vers num="2.10.57"/>
        <vers num="2.10.58"/>
        <vers num="2.10.59"/>
        <vers num="2.10.6"/>
        <vers num="2.10.60"/>
        <vers num="2.10.61"/>
        <vers num="2.10.62"/>
        <vers num="2.10.63"/>
        <vers num="2.10.64"/>
        <vers num="2.10.65.1"/>
        <vers num="2.10.66"/>
        <vers num="2.10.67"/>
        <vers num="2.10.68"/>
        <vers num="2.10.7"/>
        <vers num="2.10.8"/>
        <vers num="2.10.9"/>
        <vers num="2.11.0"/>
        <vers num="2.11.1"/>
        <vers num="2.11.2"/>
        <vers num="2.11.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0212" published="2012-06-15" name="CVE-2012-0212" modified="2012-10-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file name argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/73217" source="XF">devscripts-debdiff-code-execution(73217)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1593-1" source="UBUNTU">USN-1593-1</ref>
      <ref url="http://www.securityfocus.com/bid/52029" source="BID">52029</ref>
      <ref url="http://www.osvdb.org/79322" source="OSVDB">79322</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2409" source="DEBIAN">DSA-2409</ref>
      <ref url="http://ubuntu.com/usn/usn-1366-1" source="UBUNTU">USN-1366-1</ref>
      <ref url="http://secunia.com/advisories/48039" source="SECUNIA" adv="1">48039</ref>
      <ref url="http://secunia.com/advisories/47955" source="SECUNIA" adv="1">47955</ref>
      <ref url="http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git;a=commitdiff;h=9cbe605d3eab4f9e67525f69b676c55b273b7a03" source="CONFIRM">http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git;a=commitdiff;h=9cbe605d3eab4f9e67525f69b676c55b273b7a03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devscripts_devel_team" name="devscripts">
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.10"/>
        <vers num="2.10.11"/>
        <vers num="2.10.12"/>
        <vers num="2.10.13"/>
        <vers num="2.10.14"/>
        <vers num="2.10.15"/>
        <vers num="2.10.16"/>
        <vers num="2.10.17"/>
        <vers num="2.10.18"/>
        <vers num="2.10.18.1"/>
        <vers num="2.10.19"/>
        <vers num="2.10.20"/>
        <vers num="2.10.21"/>
        <vers num="2.10.22"/>
        <vers num="2.10.23"/>
        <vers num="2.10.24"/>
        <vers num="2.10.25"/>
        <vers num="2.10.26"/>
        <vers num="2.10.27"/>
        <vers num="2.10.28"/>
        <vers num="2.10.29"/>
        <vers num="2.10.3"/>
        <vers num="2.10.30"/>
        <vers num="2.10.31"/>
        <vers num="2.10.32"/>
        <vers num="2.10.33"/>
        <vers num="2.10.34"/>
        <vers num="2.10.35"/>
        <vers num="2.10.36"/>
        <vers num="2.10.38"/>
        <vers num="2.10.39"/>
        <vers num="2.10.40"/>
        <vers num="2.10.41"/>
        <vers num="2.10.42"/>
        <vers num="2.10.43"/>
        <vers num="2.10.44"/>
        <vers num="2.10.45"/>
        <vers num="2.10.46"/>
        <vers num="2.10.47"/>
        <vers num="2.10.48"/>
        <vers num="2.10.49"/>
        <vers num="2.10.50"/>
        <vers num="2.10.51"/>
        <vers num="2.10.52"/>
        <vers num="2.10.53"/>
        <vers num="2.10.54"/>
        <vers num="2.10.55"/>
        <vers num="2.10.56"/>
        <vers num="2.10.57"/>
        <vers num="2.10.58"/>
        <vers num="2.10.59"/>
        <vers num="2.10.6"/>
        <vers num="2.10.60"/>
        <vers num="2.10.61"/>
        <vers num="2.10.62"/>
        <vers num="2.10.63"/>
        <vers num="2.10.64"/>
        <vers num="2.10.65.1"/>
        <vers num="2.10.66"/>
        <vers num="2.10.67"/>
        <vers num="2.10.68"/>
        <vers num="2.10.7"/>
        <vers num="2.10.8"/>
        <vers num="2.10.9"/>
        <vers num="2.11.0"/>
        <vers num="2.11.1"/>
        <vers num="2.11.2"/>
        <vers num="2.11.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0213" published="2012-08-07" name="CVE-2012-0213" modified="2012-11-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial of service (OutOfMemoryError exception and possibly JVM destabilization) via a crafted length value in a Channel Definition Format (CDF) or Compound File Binary Format (CFBF) document.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=799078" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=799078</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2468" source="DEBIAN">DSA-2468</ref>
      <ref url="http://secunia.com/advisories/50549" source="SECUNIA">50549</ref>
      <ref url="http://secunia.com/advisories/49040" source="SECUNIA" adv="1">49040</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1232.html" source="REDHAT">RHSA-2012:1232</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-August/084609.html" source="FEDORA">FEDORA-2012-10835</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="poi">
        <vers num="0.1"/>
        <vers num="0.10.0"/>
        <vers num="0.11.0"/>
        <vers num="0.12.0"/>
        <vers num="0.13.0"/>
        <vers num="0.14.0"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.10" edition="dev"/>
        <vers num="1.2.0"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.7" edition="dev"/>
        <vers num="1.8" edition="dev"/>
        <vers num="2.0" edition="pre1"/>
        <vers num="2.0" edition="pre2"/>
        <vers num="2.0" edition="pre3"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.5"/>
        <vers num="2.5.1"/>
        <vers num="3.0" edition="alpha1"/>
        <vers num="3.0" edition="alpha2"/>
        <vers num="3.0" edition="alpha3"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2" edition="beta1"/>
        <vers num="3.0.2" edition="beta2"/>
        <vers num="3.1" edition="beta1"/>
        <vers num="3.1" edition="beta2"/>
        <vers num="3.2"/>
        <vers num="3.5" edition="beta1"/>
        <vers num="3.5" edition="beta2"/>
        <vers num="3.5" edition="beta3"/>
        <vers num="3.5" edition="beta4"/>
        <vers num="3.5" edition="beta5"/>
        <vers num="3.5" edition="beta6"/>
        <vers num="3.6"/>
        <vers num="3.7" edition="beta1"/>
        <vers num="3.7" edition="beta2"/>
        <vers num="3.7" edition="beta3"/>
        <vers prev="1" num="3.8" edition="beta1"/>
        <vers prev="1" num="3.8" edition="beta2"/>
        <vers prev="1" num="3.8" edition="beta3"/>
        <vers prev="1" num="3.8" edition="beta4"/>
        <vers prev="1" num="3.8" edition="beta5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0215" published="2012-07-12" name="CVE-2012-0215" modified="2012-08-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://hg.tryton.org/trytond/rev/8e64d52ecea4" source="CONFIRM" patch="1">http://hg.tryton.org/trytond/rev/8e64d52ecea4</ref>
      <ref url="https://bugs.tryton.org/issue2476" source="CONFIRM">https://bugs.tryton.org/issue2476</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2444" source="DEBIAN">DSA-2444</ref>
      <ref url="http://news.tryton.org/2012/03/security-releases-for-all-supported.html" source="CONFIRM" adv="1">http://news.tryton.org/2012/03/security-releases-for-all-supported.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tryton" name="trytond">
        <vers num="1.4.13"/>
        <vers num="1.6.8"/>
        <vers num="1.8.7"/>
        <vers num="2.0.5"/>
        <vers prev="1" num="2.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0216" published="2012-04-22" name="CVE-2012-0216" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/75211" source="XF">gnulinux-apache2-xss(75211)</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2452" source="DEBIAN">DSA-2452</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="apache2">
        <vers prev="1" num="2.2.16-6" edition="squeeze6"/>
        <vers prev="1" num="2.2.22-1" edition="wheezy"/>
        <vers prev="1" num="2.22-3" edition="sid"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0217" published="2012-06-12" name="CVE-2012-0217" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application.  NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://technet.microsoft.com/en-us/security/bulletin/ms12-042

'This vulnerability only affects Intel x64-based versions of Windows 7 and Windows Server 2008 R2.  Systems with AMD or ARM-based CPUs are not affected by this vulnerability.'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA12-164A.html" source="CERT">TA12-164A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/649219" source="CERT-VN">VU#649219</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS12-042" source="MS" patch="1" adv="1">MS12-042</ref>
      <ref url="https://www.illumos.org/issues/2873" source="CONFIRM">https://www.illumos.org/issues/2873</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=813428" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=813428</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2508" source="DEBIAN">DSA-2508</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2501" source="DEBIAN">DSA-2501</ref>
      <ref url="http://wiki.smartos.org/display/DOC/SmartOS+Change+Log#SmartOSChangeLog-June14%2C2012" source="CONFIRM">http://wiki.smartos.org/display/DOC/SmartOS+Change+Log#SmartOSChangeLog-June14%2C2012</ref>
      <ref url="http://support.citrix.com/article/CTX133161" source="CONFIRM">http://support.citrix.com/article/CTX133161</ref>
      <ref url="http://smartos.org/2012/06/15/smartos-news-3/" source="CONFIRM">http://smartos.org/2012/06/15/smartos-news-3/</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-12:04.sysret.asc" source="FREEBSD">FreeBSD-SA-12:04</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15596" source="OVAL">oval:org.mitre.oval:def:15596</ref>
      <ref url="http://lists.xen.org/archives/html/xen-devel/2012-06/msg01072.html" source="MLIST">[xen-devel] 20120619 Security vulnerability process, and CVE-2012-0217</ref>
      <ref url="http://lists.xen.org/archives/html/xen-announce/2012-06/msg00001.html" source="MLIST">[xen-announce] 20120612 Xen Security Advisory 7 (CVE-2012-0217) - PV privilege escalation</ref>
      <ref url="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2012-003.txt.asc" source="NETBSD">NetBSD-SA2012-003</ref>
      <ref url="http://blog.xen.org/index.php/2012/06/13/the-intel-sysret-privilege-escalation/" source="CONFIRM">http://blog.xen.org/index.php/2012/06/13/the-intel-sysret-privilege-escalation/</ref>
      <ref url="http://blog.illumos.org/2012/06/14/illumos-vulnerability-patched/" source="CONFIRM">http://blog.illumos.org/2012/06/14/illumos-vulnerability-patched/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0218" published="2012-12-03" name="CVE-2012-0218" modified="2012-12-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception injection when injecting a General Protection Fault, which allows local PV guest OS users to cause a denial of service (guest crash) by later triggering an exception that would normally be handled within Xen.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://lists.xen.org/archives/html/xen-announce/2012-06/msg00003.html" source="MLIST" patch="1" adv="1">[Xen-announce] 20120612 Xen Security Advisory 8 (CVE-2012-0218) - syscall/enter guest DoS</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2501" source="DEBIAN">DSA-2501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xen" name="xen">
        <vers num="3.4.0"/>
        <vers num="4.0.0"/>
        <vers num="4.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0219" published="2012-06-21" name="CVE-2012-0219" modified="2013-04-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0-b1 through 2.0.0-b4 allows local users to execute arbitrary code via the READLINE address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.dest-unreach.org/socat/contrib/socat-secadv3.html" source="CONFIRM" patch="1" adv="1">http://www.dest-unreach.org/socat/contrib/socat-secadv3.html</ref>
      <ref url="http://www.securitytracker.com/id?1027064" source="SECTRACK">1027064</ref>
      <ref url="http://www.securityfocus.com/bid/53510" source="BID">53510</ref>
      <ref url="http://www.osvdb.org/81969" source="OSVDB">81969</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/05/14/2" source="MLIST">[oss-security] 20120514 socat security advisory</ref>
      <ref url="http://www.lwn.net/Articles/504742/" source="SUSE">openSUSE-SU-2012:0809</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201208-01.xml" source="GENTOO">GLSA-201208-01</ref>
      <ref url="http://secunia.com/advisories/49746" source="SECUNIA">49746</ref>
      <ref url="http://secunia.com/advisories/49105" source="SECUNIA" adv="1">49105</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081882.html" source="FEDORA">FEDORA-2012-8328</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081619.html" source="FEDORA">FEDORA-2012-8274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dest-unreach" name="socat">
        <vers num="1.4.0.0"/>
        <vers num="1.4.0.1"/>
        <vers num="1.4.0.2"/>
        <vers num="1.4.0.3"/>
        <vers num="1.4.1.0"/>
        <vers num="1.4.2.0"/>
        <vers num="1.4.3.1"/>
        <vers num="1.5.0.0"/>
        <vers num="1.6.0.0"/>
        <vers num="1.6.0.1"/>
        <vers num="1.7.0.0"/>
        <vers num="1.7.0.1"/>
        <vers num="1.7.1.0"/>
        <vers num="1.7.1.1"/>
        <vers num="1.7.1.2"/>
        <vers num="1.7.1.3"/>
        <vers num="1.7.2.0"/>
        <vers num="2.0.0" edition="b1"/>
        <vers num="2.0.0" edition="b2"/>
        <vers num="2.0.0" edition="b3"/>
        <vers num="2.0.0" edition="b4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0220" published="2012-05-29" name="CVE-2012-0220" modified="2012-05-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the meta plugin (Plugin/meta.pm) in ikiwiki before 3.20120516 allow remote attackers to inject arbitrary web script or HTML via the (1) author or (2) authorurl meta tags.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/75702" source="XF">ikiwiki-unspecified-xss(75702)</ref>
      <ref url="http://www.securityfocus.com/bid/53599" source="BID">53599</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2474" source="DEBIAN">DSA-2474</ref>
      <ref url="http://source.ikiwiki.branchable.com/?p=source.git;a=commitdiff;h=fbfcea89f8e06426c73ab8ea369ca4cdc566db6f" source="CONFIRM">http://source.ikiwiki.branchable.com/?p=source.git;a=commitdiff;h=fbfcea89f8e06426c73ab8ea369ca4cdc566db6f</ref>
      <ref url="http://secunia.com/advisories/49232" source="SECUNIA" adv="1">49232</ref>
      <ref url="http://secunia.com/advisories/49199" source="SECUNIA" adv="1">49199</ref>
      <ref url="http://osvdb.org/81995" source="OSVDB">81995</ref>
      <ref url="http://ikiwiki.info/news/version_3.20120516/" source="CONFIRM">http://ikiwiki.info/news/version_3.20120516/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ikiwiki" name="ikiwiki">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.47"/>
        <vers num="1.10"/>
        <vers num="1.11"/>
        <vers num="1.12"/>
        <vers num="1.13"/>
        <vers num="1.14"/>
        <vers num="1.15"/>
        <vers num="1.16"/>
        <vers num="1.17"/>
        <vers num="1.18"/>
        <vers num="1.19"/>
        <vers num="1.2"/>
        <vers num="1.20"/>
        <vers num="1.21"/>
        <vers num="1.22"/>
        <vers num="1.23"/>
        <vers num="1.24"/>
        <vers num="1.25"/>
        <vers num="1.26"/>
        <vers num="1.27"/>
        <vers num="1.28"/>
        <vers num="1.29"/>
        <vers num="1.3"/>
        <vers num="1.30"/>
        <vers num="1.31"/>
        <vers num="1.32"/>
        <vers num="1.33.3"/>
        <vers num="1.34"/>
        <vers num="1.34.1"/>
        <vers num="1.34.2"/>
        <vers num="1.35"/>
        <vers num="1.36"/>
        <vers num="1.37"/>
        <vers num="1.38"/>
        <vers num="1.39"/>
        <vers num="1.4"/>
        <vers num="1.40"/>
        <vers num="1.41"/>
        <vers num="1.42"/>
        <vers num="1.43"/>
        <vers num="1.44"/>
        <vers num="1.45"/>
        <vers num="1.46"/>
        <vers num="1.47"/>
        <vers num="1.48"/>
        <vers num="1.49"/>
        <vers num="1.5"/>
        <vers num="1.50"/>
        <vers num="1.51"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.9"/>
        <vers num="2.0"/>
        <vers num="2.00"/>
        <vers num="2.1"/>
        <vers num="2.10"/>
        <vers num="2.11"/>
        <vers num="2.12"/>
        <vers num="2.13"/>
        <vers num="2.14"/>
        <vers num="2.15"/>
        <vers num="2.16"/>
        <vers num="2.17"/>
        <vers num="2.18"/>
        <vers num="2.19"/>
        <vers num="2.2"/>
        <vers num="2.20"/>
        <vers num="2.3"/>
        <vers num="2.30"/>
        <vers num="2.31"/>
        <vers num="2.31.1"/>
        <vers num="2.31.2"/>
        <vers num="2.31.3"/>
        <vers num="2.4"/>
        <vers num="2.40"/>
        <vers num="2.41"/>
        <vers num="2.42"/>
        <vers num="2.43"/>
        <vers num="2.44"/>
        <vers num="2.45"/>
        <vers num="2.46"/>
        <vers num="2.47"/>
        <vers num="2.48"/>
        <vers num="2.49"/>
        <vers num="2.5"/>
        <vers num="2.50"/>
        <vers num="2.51"/>
        <vers num="2.52"/>
        <vers num="2.53"/>
        <vers num="2.54"/>
        <vers num="2.55"/>
        <vers num="2.56"/>
        <vers num="2.6"/>
        <vers num="2.6.1"/>
        <vers num="2.60"/>
        <vers num="2.61"/>
        <vers num="2.62"/>
        <vers num="2.62.1"/>
        <vers num="2.63"/>
        <vers num="2.64"/>
        <vers num="2.65"/>
        <vers num="2.66"/>
        <vers num="2.67"/>
        <vers num="2.68"/>
        <vers num="2.69"/>
        <vers num="2.7"/>
        <vers num="2.70"/>
        <vers num="2.71"/>
        <vers num="2.72"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
        <vers num="3.0"/>
        <vers num="3.00"/>
        <vers num="3.01"/>
        <vers num="3.02"/>
        <vers num="3.03"/>
        <vers num="3.04"/>
        <vers num="3.05"/>
        <vers num="3.06"/>
        <vers num="3.07"/>
        <vers num="3.08"/>
        <vers num="3.09"/>
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers num="3.12"/>
        <vers num="3.13"/>
        <vers num="3.14"/>
        <vers num="3.141"/>
        <vers num="3.1415"/>
        <vers num="3.14159"/>
        <vers num="3.141592"/>
        <vers num="3.1415926"/>
        <vers num="3.14159265"/>
        <vers num="3.20091009"/>
        <vers num="3.20091017"/>
        <vers num="3.20091022"/>
        <vers num="3.20091023"/>
        <vers num="3.20091031"/>
        <vers num="3.20091113"/>
        <vers num="3.20091202"/>
        <vers num="3.20091218"/>
        <vers num="3.20100102.3"/>
        <vers num="3.20100122"/>
        <vers num="3.20100212"/>
        <vers num="3.20100302"/>
        <vers num="3.20100312"/>
        <vers num="3.20100403"/>
        <vers num="3.20100427"/>
        <vers num="3.20100501"/>
        <vers num="3.20100504"/>
        <vers num="3.20100515"/>
        <vers num="3.20100518"/>
        <vers num="3.20100518.2"/>
        <vers num="3.20100610"/>
        <vers num="3.20100623"/>
        <vers num="3.20100722"/>
        <vers num="3.20100804"/>
        <vers num="3.20100815"/>
        <vers num="3.20100831"/>
        <vers num="3.20100926"/>
        <vers num="3.20101019"/>
        <vers num="3.20101023"/>
        <vers num="3.20101112"/>
        <vers num="3.20101129"/>
        <vers num="3.20101201"/>
        <vers num="3.20101231"/>
        <vers num="3.20110105"/>
        <vers num="3.20110123"/>
        <vers num="3.20110124"/>
        <vers num="3.20110225"/>
        <vers num="3.20110321"/>
        <vers num="3.20120115"/>
        <vers num="3.20120202"/>
        <vers num="3.20120203"/>
        <vers prev="1" num="3.20120419"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0221" published="2012-04-02" name="CVE-2012-0221" modified="2012-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause a denial of service (service outage) via a crafted packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-088-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-088-01.pdf</ref>
      <ref url="http://rockwellautomation.custhelp.com/app/answers/detail/a_id/469937" source="MISC">http://rockwellautomation.custhelp.com/app/answers/detail/a_id/469937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockwellautomation" name="factorytalk">
        <vers num="cpr9"/>
        <vers num="cpr9_sr5"/>
      </prod>
      <prod vendor="rockwellautomation" name="rslogix_5000">
        <vers num="17"/>
        <vers num="18"/>
        <vers num="19"/>
        <vers num="20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0222" published="2012-04-02" name="CVE-2012-0222" modified="2012-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-088-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-088-01.pdf</ref>
      <ref url="http://rockwellautomation.custhelp.com/app/answers/detail/a_id/469937" source="MISC">http://rockwellautomation.custhelp.com/app/answers/detail/a_id/469937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockwellautomation" name="factorytalk">
        <vers num="cpr9"/>
        <vers num="cpr9_sr5"/>
      </prod>
      <prod vendor="rockwellautomation" name="rslogix_5000">
        <vers num="17"/>
        <vers num="18"/>
        <vers num="19"/>
        <vers num="20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0223" published="2012-02-22" nvd_name="CWE-426: Untrusted Search Path" name="CVE-2012-0223" modified="2012-02-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in 7-Technologies (7T) TERMIS 2.10 and earlier allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2012-0224.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html 

'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.us-cert.gov/control_systems/pdf/ICSA-12-025-02A.pdf

'This vulnerability may be exploitable from a remote machine.'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-025-02A.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-025-02A.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="7t" name="termis">
        <vers num="2.0"/>
        <vers prev="1" num="2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0224" published="2012-02-21" nvd_name="CWE-426: Untrusted Search Path" name="CVE-2012-0224" modified="2012-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in 7-Technologies (7T) AQUIS 1.5 and earlier allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2012-0223.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.us-cert.gov/control_systems/pdf/ICSA-12-025-02.pdf

'This vulnerability may be exploitable from a remote machine'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-025-01.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-025-01.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="7t" name="aquis">
        <vers prev="1" num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0225" published="2012-04-02" name="CVE-2012-0225" modified="2012-12-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-062-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-062-01.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74549" source="XF">wis-unspecified-xss(74549)</ref>
      <ref url="http://secunia.com/advisories/48603" source="SECUNIA">48603</ref>
      <ref url="http://osvdb.org/80888" source="OSVDB">80888</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invensys" name="wonderware_information_server">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0226" published="2012-04-02" name="CVE-2012-0226" modified="2012-12-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-062-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-062-01.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74550" source="XF">wis-unspecified-sql-injection(74550)</ref>
      <ref url="http://secunia.com/advisories/48603" source="SECUNIA">48603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invensys" name="wonderware_information_server">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0227" published="2012-10-12" name="CVE-2012-0227" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the VSFlex7.VSFlexGrid ActiveX control in ComponentOne FlexGrid 7.1, as used in Open Automation Software OPC Systems.NET, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long archive file name argument to the Archive method.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.us-cert.gov/control_systems/pdf/ICSA-12-012-01A.pdf

'AFFECTED PRODUCTS
All versions of OPC Sytems.NET prior to Version 5.0 are affected.'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-012-01A.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-012-01A.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/72604" source="XF">flexgrid-activex-bo(72604)</ref>
      <ref url="http://www.securityfocus.com/bid/51601" source="BID">51601</ref>
      <ref url="http://dsecrg.com/pages/vul/show.php?id=406" source="MISC">http://dsecrg.com/pages/vul/show.php?id=406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="componentone" name="flexgrid">
        <vers num="7.1"/>
      </prod>
      <prod vendor="opcsystems" name="opcsystems.net">
        <vers num="-"/>
        <vers prev="1" num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0228" published="2012-04-02" name="CVE-2012-0228" modified="2012-12-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass intended access restrictions via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-062-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-062-01.pdf</ref>
      <ref url="http://secunia.com/advisories/48603" source="SECUNIA">48603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invensys" name="wonderware_information_server">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0229" published="2012-03-15" name="CVE-2012-0229" modified="2012-03-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted session on TCP port 14000 to (1) ihDataArchiver.exe or (2) ihDataArchiver_x64.exe.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-032-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-032-01.pdf</ref>
      <ref url="http://support.ge-ip.com/support/index?page=kbchannel&amp;id=S:KB14767" source="MISC" adv="1">http://support.ge-ip.com/support/index?page=kbchannel&amp;id=S:KB14767</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ge" name="intelligent_platforms_proficy_historian">
        <vers num="1.0"/>
        <vers num="2.0" edition="beta"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.5"/>
        <vers num="4.0"/>
        <vers prev="1" num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0230" published="2012-03-15" name="CVE-2012-0230" modified="2012-03-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PRRDS.exe in the Proficy Remote Data Service in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted TCP session on port 12299.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-032-02.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-032-02.pdf</ref>
      <ref url="http://support.ge-ip.com/support/index?page=kbchannel&amp;id=S:KB14766" source="MISC" adv="1">http://support.ge-ip.com/support/index?page=kbchannel&amp;id=S:KB14766</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ge" name="intelligent_platforms_proficy_plant_applications">
        <vers num="215.8"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4.1"/>
        <vers prev="1" num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0231" published="2012-03-15" name="CVE-2012-0231" modified="2012-03-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PRLicenseMgr.exe in the Proficy Server License Manager in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted TCP session on port 12401.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-032-02.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-032-02.pdf</ref>
      <ref url="http://support.ge-ip.com/support/index?page=kbchannel&amp;id=S:KB14766" source="MISC" adv="1">http://support.ge-ip.com/support/index?page=kbchannel&amp;id=S:KB14766</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ge" name="intelligent_platforms_proficy_plant_applications">
        <vers num="215.8"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.3.1"/>
        <vers num="4.4.1"/>
        <vers prev="1" num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0232" published="2012-03-15" name="CVE-2012-0232" modified="2012-11-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6, 3.0, 3.0 SP1, and 3.5 allows remote attackers to modify the configuration via crafted strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-032-03.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-032-03.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/52439" source="BID">52439</ref>
      <ref url="http://support.ge-ip.com/support/index?page=kbchannel&amp;id=S:KB14768" source="MISC" adv="1">http://support.ge-ip.com/support/index?page=kbchannel&amp;id=S:KB14768</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ge" name="intelligent_platforms_proficy_real-time_information_portal">
        <vers num="2.6"/>
        <vers num="3.0" edition="sp1"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0233" published="2012-02-21" name="CVE-2012-0233" modified="2012-02-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_webaccess">
        <vers num="5.0"/>
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0234" published="2012-02-21" name="CVE-2012-0234" modified="2012-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_webaccess">
        <vers num="5.0"/>
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0235" published="2012-02-21" name="CVE-2012-0235" modified="2012-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_webaccess">
        <vers num="5.0"/>
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0236" published="2012-02-21" name="CVE-2012-0236" modified="2012-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL.  NOTE: the vendor reportedly "does not consider it to be a security risk."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_webaccess">
        <vers num="5.0"/>
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0237" published="2012-02-21" name="CVE-2012-0237" modified="2012-02-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_webaccess">
        <vers num="5.0"/>
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0238" published="2012-02-21" name="CVE-2012-0238" modified="2012-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_webaccess">
        <vers num="5.0"/>
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0239" published="2012-02-21" name="CVE-2012-0239" modified="2012-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an administrative password via a password-change request.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_webaccess">
        <vers num="5.0"/>
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0240" published="2012-02-21" name="CVE-2012-0240" modified="2012-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_webaccess">
        <vers num="5.0"/>
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0241" published="2012-02-21" name="CVE-2012-0241" modified="2012-10-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/73281" source="XF">webaccess-stream-code-execution(73281)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_webaccess">
        <vers num="5.0"/>
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0242" published="2012-02-21" name="CVE-2012-0242" modified="2012-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_webaccess">
        <vers num="5.0"/>
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0243" published="2012-02-21" name="CVE-2012-0243" modified="2012-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code by leveraging the ability to write arbitrary content to any pathname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_webaccess">
        <vers num="5.0"/>
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0244" published="2012-02-21" name="CVE-2012-0244" modified="2012-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafted string input.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-047-01.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_webaccess">
        <vers num="5.0"/>
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0245" published="2012-03-09" name="CVE-2012-0245" modified="2012-10-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Module, IRC5 OPC Server, PC SDK, PickMaster 3 and 5, RobView 5, RobotStudio, WebWare SDK, and WebWare Server, allow remote attackers to execute arbitrary code via a crafted (1) 0xA or (2) 0xE Netscan packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-059-01.pdf" source="MISC" patch="1">http://www.us-cert.gov/control_systems/pdf/ICSA-12-059-01.pdf</ref>
      <ref url="http://www05.abb.com/global/scot/scot348.nsf/veritydisplay/f261be074480dc24c12579a00049ecd5/$file/si10227a1%20vulnerability%20security%20advisory.pdf" source="CONFIRM" patch="1" adv="1">http://www05.abb.com/global/scot/scot348.nsf/veritydisplay/f261be074480dc24c12579a00049ecd5/$file/si10227a1%20vulnerability%20security%20advisory.pdf</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-12-033/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-12-033/</ref>
      <ref url="http://www.securityfocus.com/bid/52123" source="BID">52123</ref>
      <ref url="http://secunia.com/advisories/48090" source="SECUNIA" adv="1">48090</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-02/0125.html" source="BUGTRAQ">20120222 ZDI-12-033 : ABB WebWare RobNetScanHost.exe Remote Code Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abb" name="interlink_module">
        <vers num="-"/>
      </prod>
      <prod vendor="abb" name="irc5_opc_server">
        <vers num="-"/>
      </prod>
      <prod vendor="abb" name="pc_sdk">
        <vers num="-"/>
      </prod>
      <prod vendor="abb" name="pickmaster_3">
        <vers num="-"/>
      </prod>
      <prod vendor="abb" name="pickmaster_5">
        <vers num="-"/>
      </prod>
      <prod vendor="abb" name="robot_communications_runtime">
        <vers prev="1" num="5.14.01"/>
      </prod>
      <prod vendor="abb" name="robotstudio">
        <vers num="-"/>
      </prod>
      <prod vendor="abb" name="robview_5">
        <vers num="-"/>
      </prod>
      <prod vendor="abb" name="webware_sdk">
        <vers num="-"/>
      </prod>
      <prod vendor="abb" name="webware_server">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0246" published="2012-04-02" name="CVE-2012-0246" modified="2012-08-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute arbitrary code via vectors involving an HTML document on the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-083-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-083-01.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74388" source="XF">integraxor-activex-directory-traversal(74388)</ref>
      <ref url="http://osvdb.org/80650" source="OSVDB">80650</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecava" name="integraxor">
        <vers num="3.5.3900.10"/>
        <vers num="3.5.3900.5"/>
        <vers num="3.6.4000.0"/>
        <vers num="3.60"/>
        <vers prev="1" num="3.60.4061"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0247" published="2012-06-05" name="CVE-2012-0247" modified="2012-11-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&amp;t=20286" source="CONFIRM" patch="1">http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&amp;t=20286</ref>
      <ref url="http://www.securitytracker.com/id?1027032" source="SECTRACK">1027032</ref>
      <ref url="http://www.osvdb.org/79003" source="OSVDB">79003</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-201203-09.xml" source="GENTOO">GLSA-201203-09</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2427" source="DEBIAN">DSA-2427</ref>
      <ref url="http://www.cert.fi/en/reports/2012/vulnerability595210.html" source="MISC">http://www.cert.fi/en/reports/2012/vulnerability595210.html</ref>
      <ref url="http://ubuntu.com/usn/usn-1435-1" source="UBUNTU">USN-1435-1</ref>
      <ref url="http://secunia.com/advisories/49068" source="SECUNIA" adv="1">49068</ref>
      <ref url="http://secunia.com/advisories/49063" source="SECUNIA" adv="1">49063</ref>
      <ref url="http://secunia.com/advisories/49043" source="SECUNIA" adv="1">49043</ref>
      <ref url="http://secunia.com/advisories/48259" source="SECUNIA" adv="1">48259</ref>
      <ref url="http://secunia.com/advisories/48247" source="SECUNIA" adv="1">48247</ref>
      <ref url="http://secunia.com/advisories/47926" source="SECUNIA" adv="1">47926</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0545.html" source="REDHAT">RHSA-2012:0545</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0544.html" source="REDHAT">RHSA-2012:0544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="4.2.7"/>
        <vers num="4.2.9"/>
        <vers num="5.2"/>
        <vers num="5.2.0"/>
        <vers num="5.2.4.3"/>
        <vers num="5.2.6"/>
        <vers num="5.3"/>
        <vers num="5.3.0"/>
        <vers num="5.3.1"/>
        <vers num="5.3.2"/>
        <vers num="5.3.3"/>
        <vers num="5.3.4"/>
        <vers num="5.3.5"/>
        <vers num="5.3.6"/>
        <vers num="5.3.7"/>
        <vers num="5.3.8"/>
        <vers num="5.3.8.2"/>
        <vers num="5.3.9"/>
        <vers num="5.4"/>
        <vers num="5.4.0.5"/>
        <vers num="5.4.1.2"/>
        <vers num="5.4.2.3"/>
        <vers num="5.4.3"/>
        <vers num="5.4.3.11"/>
        <vers num="5.4.4.5"/>
        <vers num="5.4.5.1"/>
        <vers num="5.4.6.3"/>
        <vers num="5.4.7"/>
        <vers num="5.4.7.4"/>
        <vers num="5.4.8"/>
        <vers num="5.4.8.3"/>
        <vers num="5.4.9.1"/>
        <vers num="5.5"/>
        <vers num="5.5.1.4"/>
        <vers num="5.5.2.5"/>
        <vers num="5.5.3.2"/>
        <vers num="5.5.3.2.1.2.0"/>
        <vers num="5.5.4"/>
        <vers num="5.5.4.4"/>
        <vers num="5.5.5.3"/>
        <vers num="5.5.6"/>
        <vers num="5.5.6.0_2003-04-09"/>
        <vers num="5.5.6.0_20030409"/>
        <vers num="5.5.7"/>
        <vers num="5.5.7.15"/>
        <vers num="5.5.7.31"/>
        <vers num="5.5.7.35"/>
        <vers num="5.5.7q16"/>
        <vers num="5.5.7q8"/>
        <vers num="6.0"/>
        <vers num="6.0.0.7"/>
        <vers num="6.0.1"/>
        <vers num="6.0.1.4"/>
        <vers num="6.0.2"/>
        <vers num="6.0.2.5"/>
        <vers num="6.0.2.7"/>
        <vers num="6.0.3"/>
        <vers num="6.0.3.5"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.4"/>
        <vers num="6.0.5"/>
        <vers num="6.0.5.3"/>
        <vers num="6.0.6"/>
        <vers num="6.0.6.1"/>
        <vers num="6.0.6.2"/>
        <vers num="6.0.7"/>
        <vers num="6.0.7.3"/>
        <vers num="6.0.8"/>
        <vers num="6.0.8.3"/>
        <vers num="6.1"/>
        <vers num="6.1.0.9"/>
        <vers num="6.1.1"/>
        <vers num="6.1.1.6"/>
        <vers num="6.1.2"/>
        <vers num="6.1.2.7"/>
        <vers num="6.1.3"/>
        <vers num="6.1.3.7"/>
        <vers num="6.1.4"/>
        <vers num="6.1.4.5"/>
        <vers num="6.1.5"/>
        <vers num="6.1.5.8"/>
        <vers num="6.1.6"/>
        <vers num="6.1.6.9"/>
        <vers num="6.1.7"/>
        <vers num="6.1.7.5"/>
        <vers num="6.1.8"/>
        <vers num="6.1.8.7"/>
        <vers num="6.1.9.4"/>
        <vers num="6.2"/>
        <vers num="6.2.0.3"/>
        <vers num="6.2.0.4"/>
        <vers num="6.2.0.7"/>
        <vers num="6.2.0.8"/>
        <vers num="6.2.1"/>
        <vers num="6.2.1.7"/>
        <vers num="6.2.2"/>
        <vers num="6.2.2.5"/>
        <vers num="6.2.3"/>
        <vers num="6.2.3.4"/>
        <vers num="6.2.3.6"/>
        <vers num="6.2.4"/>
        <vers num="6.2.4.3"/>
        <vers num="6.2.4.5"/>
        <vers num="6.2.5"/>
        <vers num="6.2.6"/>
        <vers num="6.2.7"/>
        <vers num="6.2.8"/>
        <vers num="6.2.8.0"/>
        <vers num="6.2.8.1"/>
        <vers num="6.2.8.2"/>
        <vers num="6.2.8.3"/>
        <vers num="6.2.9"/>
        <vers num="6.2.9.2"/>
        <vers num="6.3.0.0"/>
        <vers num="6.3.0.1"/>
        <vers num="6.3.0.2"/>
        <vers num="6.3.0.3"/>
        <vers num="6.3.0.4"/>
        <vers num="6.3.0.5"/>
        <vers num="6.3.0.7"/>
        <vers num="6.3.0.8"/>
        <vers num="6.3.1"/>
        <vers num="6.3.1-6"/>
        <vers num="6.3.1-7"/>
        <vers num="6.3.1.0"/>
        <vers num="6.3.1.1"/>
        <vers num="6.3.1.2."/>
        <vers num="6.3.1.3"/>
        <vers num="6.3.1.4"/>
        <vers num="6.3.1.5"/>
        <vers num="6.3.1.6"/>
        <vers num="6.3.1.7"/>
        <vers num="6.3.2"/>
        <vers num="6.3.2-1"/>
        <vers num="6.3.2-2"/>
        <vers num="6.3.2-3"/>
        <vers num="6.3.2-4"/>
        <vers num="6.3.2-5"/>
        <vers num="6.3.2-6"/>
        <vers num="6.3.2-7"/>
        <vers num="6.3.2-8"/>
        <vers num="6.3.2.0"/>
        <vers num="6.3.2.1"/>
        <vers num="6.3.2.2"/>
        <vers num="6.3.2.3"/>
        <vers num="6.3.2.4"/>
        <vers num="6.3.2.5"/>
        <vers num="6.3.2.6"/>
        <vers num="6.3.2.7"/>
        <vers num="6.3.2.8"/>
        <vers num="6.3.3"/>
        <vers num="6.3.3-1"/>
        <vers num="6.3.3-2"/>
        <vers num="6.3.3-3"/>
        <vers num="6.3.3-4"/>
        <vers num="6.3.3-5"/>
        <vers num="6.3.3-6"/>
        <vers num="6.3.3-7"/>
        <vers num="6.3.3-8"/>
        <vers num="6.3.3-9"/>
        <vers num="6.3.3.0"/>
        <vers num="6.3.3.1"/>
        <vers num="6.3.3.2"/>
        <vers num="6.3.3.3"/>
        <vers num="6.3.3.4"/>
        <vers num="6.3.3_3"/>
        <vers num="6.3.3_5"/>
        <vers num="6.3.3_6"/>
        <vers num="6.3.4"/>
        <vers num="6.3.4-1"/>
        <vers num="6.3.4-10"/>
        <vers num="6.3.4-2"/>
        <vers num="6.3.4-3"/>
        <vers num="6.3.4-4"/>
        <vers num="6.3.4-5"/>
        <vers num="6.3.4-6"/>
        <vers num="6.3.4-8"/>
        <vers num="6.3.4-9"/>
        <vers num="6.3.5"/>
        <vers num="6.3.5-10"/>
        <vers num="6.3.5-4"/>
        <vers num="6.3.5-5"/>
        <vers num="6.3.5-6"/>
        <vers num="6.3.5-7"/>
        <vers num="6.3.5-9"/>
        <vers num="6.3.6"/>
        <vers num="6.3.6-1"/>
        <vers num="6.3.6-10"/>
        <vers num="6.3.6-2"/>
        <vers num="6.3.6-3"/>
        <vers num="6.3.6-4"/>
        <vers num="6.3.6-5"/>
        <vers num="6.3.6-6"/>
        <vers num="6.3.6-7"/>
        <vers num="6.3.6-8"/>
        <vers num="6.3.6-9"/>
        <vers num="6.3.7"/>
        <vers num="6.3.7-1"/>
        <vers num="6.3.7-10"/>
        <vers num="6.3.7-2"/>
        <vers num="6.3.7-3"/>
        <vers num="6.3.7-4"/>
        <vers num="6.3.7-5"/>
        <vers num="6.3.7-7"/>
        <vers num="6.3.7-9"/>
        <vers num="6.3.8"/>
        <vers num="6.3.8-1"/>
        <vers num="6.3.8-10"/>
        <vers num="6.3.8-2"/>
        <vers num="6.3.8-3"/>
        <vers num="6.3.8-5"/>
        <vers num="6.3.8-6"/>
        <vers num="6.3.8-7"/>
        <vers num="6.3.8-9"/>
        <vers num="6.3.9"/>
        <vers num="6.3.9-1"/>
        <vers num="6.3.9-10"/>
        <vers num="6.3.9-2"/>
        <vers num="6.3.9-4"/>
        <vers num="6.3.9-5"/>
        <vers num="6.3.9-6"/>
        <vers num="6.3.9-7"/>
        <vers num="6.3.9-8"/>
        <vers num="6.3.9-9"/>
        <vers num="6.4.0"/>
        <vers num="6.4.0-1"/>
        <vers num="6.4.0-10"/>
        <vers num="6.4.0-11"/>
        <vers num="6.4.0-4"/>
        <vers num="6.4.0-5"/>
        <vers num="6.4.0-6"/>
        <vers num="6.4.0-7"/>
        <vers num="6.4.0-8"/>
        <vers num="6.4.1"/>
        <vers num="6.4.1-1"/>
        <vers num="6.4.1-2"/>
        <vers num="6.4.1-3"/>
        <vers num="6.4.1-4"/>
        <vers num="6.4.1-5"/>
        <vers num="6.4.1-6"/>
        <vers num="6.4.1-7"/>
        <vers num="6.4.1-8"/>
        <vers num="6.4.1-9"/>
        <vers num="6.4.2"/>
        <vers num="6.4.2-1"/>
        <vers num="6.4.2-10"/>
        <vers num="6.4.2-2"/>
        <vers num="6.4.2-4"/>
        <vers num="6.4.2-5"/>
        <vers num="6.4.2-6"/>
        <vers num="6.4.2-7"/>
        <vers num="6.4.2-8"/>
        <vers num="6.4.2-9"/>
        <vers num="6.4.3"/>
        <vers num="6.4.3-1"/>
        <vers num="6.4.3-10"/>
        <vers num="6.4.3-2"/>
        <vers num="6.4.3-3"/>
        <vers num="6.4.3-5"/>
        <vers num="6.4.3-6"/>
        <vers num="6.4.3-7"/>
        <vers num="6.4.3-8"/>
        <vers num="6.4.4"/>
        <vers num="6.4.4-1"/>
        <vers num="6.4.4-3"/>
        <vers num="6.4.4-5"/>
        <vers num="6.4.4-7"/>
        <vers num="6.4.4-8"/>
        <vers num="6.4.5"/>
        <vers num="6.4.5-1"/>
        <vers num="6.4.5-2"/>
        <vers num="6.4.5-3"/>
        <vers num="6.4.5-4"/>
        <vers num="6.4.5-6"/>
        <vers num="6.4.5-7"/>
        <vers num="6.4.5-9"/>
        <vers num="6.4.6"/>
        <vers num="6.4.6-1"/>
        <vers num="6.4.6-2"/>
        <vers num="6.4.6-3"/>
        <vers num="6.4.6-4"/>
        <vers num="6.4.6-5"/>
        <vers num="6.4.6-6"/>
        <vers num="6.4.6-8"/>
        <vers num="6.4.6-9"/>
        <vers num="6.4.7-1"/>
        <vers num="6.4.7-10"/>
        <vers num="6.4.7-2"/>
        <vers num="6.4.7-3"/>
        <vers num="6.4.7-4"/>
        <vers num="6.4.7-5"/>
        <vers num="6.4.7-6"/>
        <vers num="6.4.7-7"/>
        <vers num="6.4.7-8"/>
        <vers num="6.4.7-9"/>
        <vers num="6.4.8"/>
        <vers num="6.4.8-1"/>
        <vers num="6.4.8-10"/>
        <vers num="6.4.8-2"/>
        <vers num="6.4.8-3"/>
        <vers num="6.4.8-4"/>
        <vers num="6.4.8-5"/>
        <vers num="6.4.8-6"/>
        <vers num="6.4.8-7"/>
        <vers num="6.4.8-8"/>
        <vers num="6.4.8-9"/>
        <vers num="6.4.9"/>
        <vers num="6.4.9-10"/>
        <vers num="6.4.9-2"/>
        <vers num="6.4.9-3"/>
        <vers num="6.4.9-5"/>
        <vers num="6.4.9-7"/>
        <vers num="6.4.9-8"/>
        <vers num="6.4.9-9"/>
        <vers num="6.5.0"/>
        <vers num="6.5.0-1"/>
        <vers num="6.5.0-10"/>
        <vers num="6.5.0-2"/>
        <vers num="6.5.0-3"/>
        <vers num="6.5.0-4"/>
        <vers num="6.5.0-5"/>
        <vers num="6.5.0-6"/>
        <vers num="6.5.0-7"/>
        <vers num="6.5.0-8"/>
        <vers num="6.5.0-9"/>
        <vers num="6.5.1"/>
        <vers num="6.5.1-1"/>
        <vers num="6.5.1-10"/>
        <vers num="6.5.1-2"/>
        <vers num="6.5.1-3"/>
        <vers num="6.5.1-4"/>
        <vers num="6.5.1-5"/>
        <vers num="6.5.1-6"/>
        <vers num="6.5.1-7"/>
        <vers num="6.5.1-9"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2-1"/>
        <vers num="6.5.2-10"/>
        <vers num="6.5.2-2"/>
        <vers num="6.5.2-3"/>
        <vers num="6.5.2-4"/>
        <vers num="6.5.2-5"/>
        <vers num="6.5.2-6"/>
        <vers num="6.5.2-7"/>
        <vers num="6.5.2-8"/>
        <vers num="6.5.2-9"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3-1"/>
        <vers num="6.5.3-10"/>
        <vers num="6.5.3-3"/>
        <vers num="6.5.3-4"/>
        <vers num="6.5.3-5"/>
        <vers num="6.5.3-6"/>
        <vers num="6.5.3-7"/>
        <vers num="6.5.3-8"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4-1"/>
        <vers num="6.5.4-10"/>
        <vers num="6.5.4-2"/>
        <vers num="6.5.4-3"/>
        <vers num="6.5.4-4"/>
        <vers num="6.5.4-5"/>
        <vers num="6.5.4-6"/>
        <vers num="6.5.4-7"/>
        <vers num="6.5.4-8"/>
        <vers num="6.5.4-9"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5-1"/>
        <vers num="6.5.5-10"/>
        <vers num="6.5.5-2"/>
        <vers num="6.5.5-3"/>
        <vers num="6.5.5-4"/>
        <vers num="6.5.5-5"/>
        <vers num="6.5.5-6"/>
        <vers num="6.5.5-7"/>
        <vers num="6.5.5-8"/>
        <vers num="6.5.5-9"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6-10"/>
        <vers num="6.5.6-2"/>
        <vers num="6.5.6-3"/>
        <vers num="6.5.6-4"/>
        <vers num="6.5.6-5"/>
        <vers num="6.5.6-6"/>
        <vers num="6.5.6-7"/>
        <vers num="6.5.6-8"/>
        <vers num="6.5.6-9"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7-1"/>
        <vers num="6.5.7-2"/>
        <vers num="6.5.7-3"/>
        <vers num="6.5.7-4"/>
        <vers num="6.5.7-5"/>
        <vers num="6.5.7-6"/>
        <vers num="6.5.7-7"/>
        <vers num="6.5.7-8"/>
        <vers num="6.5.7-9"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8-1"/>
        <vers num="6.5.8-2"/>
        <vers num="6.5.8-3"/>
        <vers num="6.5.8-4"/>
        <vers num="6.5.8-5"/>
        <vers num="6.5.8-6"/>
        <vers num="6.5.8-7"/>
        <vers num="6.5.8-8"/>
        <vers num="6.5.8-9"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9-1"/>
        <vers num="6.5.9-10"/>
        <vers num="6.5.9-2"/>
        <vers num="6.5.9-3"/>
        <vers num="6.5.9-4"/>
        <vers num="6.5.9-5"/>
        <vers num="6.5.9-6"/>
        <vers num="6.5.9-7"/>
        <vers num="6.5.9-8"/>
        <vers num="6.6.0"/>
        <vers num="6.6.0-1"/>
        <vers num="6.6.0-10"/>
        <vers num="6.6.0-2"/>
        <vers num="6.6.0-4"/>
        <vers num="6.6.0-5"/>
        <vers num="6.6.0-6"/>
        <vers num="6.6.0-7"/>
        <vers num="6.6.0-8"/>
        <vers num="6.6.0-9"/>
        <vers num="6.6.1"/>
        <vers num="6.6.1-1"/>
        <vers num="6.6.1-10"/>
        <vers num="6.6.1-2"/>
        <vers num="6.6.1-3"/>
        <vers num="6.6.1-4"/>
        <vers num="6.6.1-5"/>
        <vers num="6.6.1-6"/>
        <vers num="6.6.1-7"/>
        <vers num="6.6.1-8"/>
        <vers num="6.6.1-9"/>
        <vers num="6.6.2"/>
        <vers num="6.6.2-1"/>
        <vers num="6.6.2-10"/>
        <vers num="6.6.2-2"/>
        <vers num="6.6.2-3"/>
        <vers num="6.6.2-4"/>
        <vers num="6.6.2-5"/>
        <vers num="6.6.2-6"/>
        <vers num="6.6.2-7"/>
        <vers num="6.6.2-8"/>
        <vers num="6.6.2-9"/>
        <vers num="6.6.3"/>
        <vers num="6.6.3-1"/>
        <vers num="6.6.3-10"/>
        <vers num="6.6.3-2"/>
        <vers num="6.6.3-3"/>
        <vers num="6.6.3-4"/>
        <vers num="6.6.3-5"/>
        <vers num="6.6.3-6"/>
        <vers num="6.6.3-7"/>
        <vers num="6.6.4"/>
        <vers num="6.6.4-1"/>
        <vers num="6.6.4-10"/>
        <vers num="6.6.4-2"/>
        <vers num="6.6.4-4"/>
        <vers num="6.6.4-5"/>
        <vers num="6.6.4-6"/>
        <vers num="6.6.4-7"/>
        <vers num="6.6.4-8"/>
        <vers num="6.6.4-9"/>
        <vers num="6.6.5"/>
        <vers num="6.6.5-1"/>
        <vers num="6.6.5-10"/>
        <vers num="6.6.5-2"/>
        <vers num="6.6.5-3"/>
        <vers num="6.6.5-4"/>
        <vers num="6.6.5-5"/>
        <vers num="6.6.5-6"/>
        <vers num="6.6.5-7"/>
        <vers num="6.6.5-8"/>
        <vers num="6.6.5-9"/>
        <vers num="6.6.6-0"/>
        <vers num="6.6.6-1"/>
        <vers num="6.6.6-10"/>
        <vers num="6.6.6-2"/>
        <vers num="6.6.6-3"/>
        <vers num="6.6.6-4"/>
        <vers num="6.6.6-5"/>
        <vers num="6.6.6-6"/>
        <vers num="6.6.6-7"/>
        <vers num="6.6.6-8"/>
        <vers num="6.6.6-9"/>
        <vers num="6.6.7-0"/>
        <vers num="6.6.7-1"/>
        <vers num="6.6.7-10"/>
        <vers num="6.6.7-2"/>
        <vers num="6.6.7-3"/>
        <vers num="6.6.7-4"/>
        <vers num="6.6.7-5"/>
        <vers num="6.6.7-6"/>
        <vers num="6.6.7-7"/>
        <vers num="6.6.7-8"/>
        <vers num="6.6.7-9"/>
        <vers num="6.6.8-0"/>
        <vers num="6.6.9-0"/>
        <vers num="6.6.9-1"/>
        <vers num="6.6.9-10"/>
        <vers num="6.6.9-2"/>
        <vers num="6.6.9-3"/>
        <vers num="6.6.9-4"/>
        <vers num="6.6.9-5"/>
        <vers num="6.6.9-6"/>
        <vers num="6.6.9-7"/>
        <vers num="6.6.9-8"/>
        <vers num="6.6.9-9"/>
        <vers num="6.7.0-0"/>
        <vers num="6.7.0-1"/>
        <vers num="6.7.0-10"/>
        <vers num="6.7.0-2"/>
        <vers num="6.7.0-3"/>
        <vers num="6.7.0-4"/>
        <vers num="6.7.0-5"/>
        <vers num="6.7.0-6"/>
        <vers num="6.7.0-7"/>
        <vers num="6.7.0-8"/>
        <vers num="6.7.0-9"/>
        <vers num="6.7.1-0"/>
        <vers num="6.7.1-1"/>
        <vers num="6.7.1-10"/>
        <vers num="6.7.1-2"/>
        <vers num="6.7.1-3"/>
        <vers num="6.7.1-4"/>
        <vers num="6.7.1-5"/>
        <vers num="6.7.1-6"/>
        <vers num="6.7.1-7"/>
        <vers num="6.7.1-8"/>
        <vers num="6.7.1-9"/>
        <vers num="6.7.2-0"/>
        <vers num="6.7.2-1"/>
        <vers num="6.7.2-10"/>
        <vers num="6.7.2-2"/>
        <vers num="6.7.2-3"/>
        <vers num="6.7.2-4"/>
        <vers num="6.7.2-5"/>
        <vers num="6.7.2-6"/>
        <vers num="6.7.2-7"/>
        <vers num="6.7.2-8"/>
        <vers num="6.7.2-9"/>
        <vers num="6.7.3-0"/>
        <vers num="6.7.3-1"/>
        <vers num="6.7.3-10"/>
        <vers num="6.7.3-2"/>
        <vers num="6.7.3-3"/>
        <vers num="6.7.3-4"/>
        <vers num="6.7.3-5"/>
        <vers num="6.7.3-6"/>
        <vers num="6.7.3-7"/>
        <vers num="6.7.3-8"/>
        <vers num="6.7.3-9"/>
        <vers num="6.7.4-0"/>
        <vers num="6.7.4-1"/>
        <vers num="6.7.4-10"/>
        <vers num="6.7.4-2"/>
        <vers num="6.7.4-3"/>
        <vers num="6.7.4-4"/>
        <vers num="6.7.4-5"/>
        <vers num="6.7.4-6"/>
        <vers num="6.7.4-7"/>
        <vers num="6.7.4-8"/>
        <vers num="6.7.4-9"/>
        <vers num="6.7.5-0"/>
        <vers num="6.7.5-1"/>
        <vers num="6.7.5-2"/>
        <vers num="6.7.5-3"/>
        <vers num="6.7.5-4"/>
        <vers num="6.7.5-5"/>
        <vers num="6.7.5-6"/>
        <vers prev="1" num="6.7.5-7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0248" published="2012-06-05" name="CVE-2012-0248" modified="2012-11-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1027032" source="SECTRACK">1027032</ref>
      <ref url="http://www.securityfocus.com/bid/51957" source="BID">51957</ref>
      <ref url="http://www.osvdb.org/79003" source="OSVDB">79003</ref>
      <ref url="http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&amp;t=20286" source="CONFIRM" adv="1">http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&amp;t=20286</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-201203-09.xml" source="GENTOO">GLSA-201203-09</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2427" source="DEBIAN">DSA-2427</ref>
      <ref url="http://www.cert.fi/en/reports/2012/vulnerability595210.html" source="MISC">http://www.cert.fi/en/reports/2012/vulnerability595210.html</ref>
      <ref url="http://ubuntu.com/usn/usn-1435-1" source="UBUNTU">USN-1435-1</ref>
      <ref url="http://secunia.com/advisories/49068" source="SECUNIA" adv="1">49068</ref>
      <ref url="http://secunia.com/advisories/49063" source="SECUNIA" adv="1">49063</ref>
      <ref url="http://secunia.com/advisories/49043" source="SECUNIA" adv="1">49043</ref>
      <ref url="http://secunia.com/advisories/48259" source="SECUNIA" adv="1">48259</ref>
      <ref url="http://secunia.com/advisories/48247" source="SECUNIA" adv="1">48247</ref>
      <ref url="http://secunia.com/advisories/47926" source="SECUNIA" adv="1">47926</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0545.html" source="REDHAT">RHSA-2012:0545</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0544.html" source="REDHAT">RHSA-2012:0544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="4.2.7"/>
        <vers num="4.2.9"/>
        <vers num="5.2"/>
        <vers num="5.2.0"/>
        <vers num="5.2.4.3"/>
        <vers num="5.2.6"/>
        <vers num="5.3"/>
        <vers num="5.3.0"/>
        <vers num="5.3.1"/>
        <vers num="5.3.2"/>
        <vers num="5.3.3"/>
        <vers num="5.3.4"/>
        <vers num="5.3.5"/>
        <vers num="5.3.6"/>
        <vers num="5.3.7"/>
        <vers num="5.3.8"/>
        <vers num="5.3.8.2"/>
        <vers num="5.3.9"/>
        <vers num="5.4"/>
        <vers num="5.4.0.5"/>
        <vers num="5.4.1.2"/>
        <vers num="5.4.2.3"/>
        <vers num="5.4.3"/>
        <vers num="5.4.3.11"/>
        <vers num="5.4.4.5"/>
        <vers num="5.4.5.1"/>
        <vers num="5.4.6.3"/>
        <vers num="5.4.7"/>
        <vers num="5.4.7.4"/>
        <vers num="5.4.8"/>
        <vers num="5.4.8.3"/>
        <vers num="5.4.9.1"/>
        <vers num="5.5"/>
        <vers num="5.5.1.4"/>
        <vers num="5.5.2.5"/>
        <vers num="5.5.3.2"/>
        <vers num="5.5.3.2.1.2.0"/>
        <vers num="5.5.4"/>
        <vers num="5.5.4.4"/>
        <vers num="5.5.5.3"/>
        <vers num="5.5.6"/>
        <vers num="5.5.6.0_2003-04-09"/>
        <vers num="5.5.6.0_20030409"/>
        <vers num="5.5.7"/>
        <vers num="5.5.7.15"/>
        <vers num="5.5.7.31"/>
        <vers num="5.5.7.35"/>
        <vers num="5.5.7q16"/>
        <vers num="5.5.7q8"/>
        <vers num="6.0"/>
        <vers num="6.0.0.7"/>
        <vers num="6.0.1"/>
        <vers num="6.0.1.4"/>
        <vers num="6.0.2"/>
        <vers num="6.0.2.5"/>
        <vers num="6.0.2.7"/>
        <vers num="6.0.3"/>
        <vers num="6.0.3.5"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.4"/>
        <vers num="6.0.5"/>
        <vers num="6.0.5.3"/>
        <vers num="6.0.6"/>
        <vers num="6.0.6.1"/>
        <vers num="6.0.6.2"/>
        <vers num="6.0.7"/>
        <vers num="6.0.7.3"/>
        <vers num="6.0.8"/>
        <vers num="6.0.8.3"/>
        <vers num="6.1"/>
        <vers num="6.1.0.9"/>
        <vers num="6.1.1"/>
        <vers num="6.1.1.6"/>
        <vers num="6.1.2"/>
        <vers num="6.1.2.7"/>
        <vers num="6.1.3"/>
        <vers num="6.1.3.7"/>
        <vers num="6.1.4"/>
        <vers num="6.1.4.5"/>
        <vers num="6.1.5"/>
        <vers num="6.1.5.8"/>
        <vers num="6.1.6"/>
        <vers num="6.1.6.9"/>
        <vers num="6.1.7"/>
        <vers num="6.1.7.5"/>
        <vers num="6.1.8"/>
        <vers num="6.1.8.7"/>
        <vers num="6.1.9.4"/>
        <vers num="6.2"/>
        <vers num="6.2.0.3"/>
        <vers num="6.2.0.4"/>
        <vers num="6.2.0.7"/>
        <vers num="6.2.0.8"/>
        <vers num="6.2.1"/>
        <vers num="6.2.1.7"/>
        <vers num="6.2.2"/>
        <vers num="6.2.2.5"/>
        <vers num="6.2.3"/>
        <vers num="6.2.3.4"/>
        <vers num="6.2.3.6"/>
        <vers num="6.2.4"/>
        <vers num="6.2.4.3"/>
        <vers num="6.2.4.5"/>
        <vers num="6.2.5"/>
        <vers num="6.2.6"/>
        <vers num="6.2.7"/>
        <vers num="6.2.8"/>
        <vers num="6.2.8.0"/>
        <vers num="6.2.8.1"/>
        <vers num="6.2.8.2"/>
        <vers num="6.2.8.3"/>
        <vers num="6.2.9"/>
        <vers num="6.2.9.2"/>
        <vers num="6.3.0.0"/>
        <vers num="6.3.0.1"/>
        <vers num="6.3.0.2"/>
        <vers num="6.3.0.3"/>
        <vers num="6.3.0.4"/>
        <vers num="6.3.0.5"/>
        <vers num="6.3.0.7"/>
        <vers num="6.3.0.8"/>
        <vers num="6.3.1"/>
        <vers num="6.3.1-6"/>
        <vers num="6.3.1-7"/>
        <vers num="6.3.1.0"/>
        <vers num="6.3.1.1"/>
        <vers num="6.3.1.2."/>
        <vers num="6.3.1.3"/>
        <vers num="6.3.1.4"/>
        <vers num="6.3.1.5"/>
        <vers num="6.3.1.6"/>
        <vers num="6.3.1.7"/>
        <vers num="6.3.2"/>
        <vers num="6.3.2-1"/>
        <vers num="6.3.2-2"/>
        <vers num="6.3.2-3"/>
        <vers num="6.3.2-4"/>
        <vers num="6.3.2-5"/>
        <vers num="6.3.2-6"/>
        <vers num="6.3.2-7"/>
        <vers num="6.3.2-8"/>
        <vers num="6.3.2.0"/>
        <vers num="6.3.2.1"/>
        <vers num="6.3.2.2"/>
        <vers num="6.3.2.3"/>
        <vers num="6.3.2.4"/>
        <vers num="6.3.2.5"/>
        <vers num="6.3.2.6"/>
        <vers num="6.3.2.7"/>
        <vers num="6.3.2.8"/>
        <vers num="6.3.3"/>
        <vers num="6.3.3-1"/>
        <vers num="6.3.3-2"/>
        <vers num="6.3.3-3"/>
        <vers num="6.3.3-4"/>
        <vers num="6.3.3-5"/>
        <vers num="6.3.3-6"/>
        <vers num="6.3.3-7"/>
        <vers num="6.3.3-8"/>
        <vers num="6.3.3-9"/>
        <vers num="6.3.3.0"/>
        <vers num="6.3.3.1"/>
        <vers num="6.3.3.2"/>
        <vers num="6.3.3.3"/>
        <vers num="6.3.3.4"/>
        <vers num="6.3.3_3"/>
        <vers num="6.3.3_5"/>
        <vers num="6.3.3_6"/>
        <vers num="6.3.4"/>
        <vers num="6.3.4-1"/>
        <vers num="6.3.4-10"/>
        <vers num="6.3.4-2"/>
        <vers num="6.3.4-3"/>
        <vers num="6.3.4-4"/>
        <vers num="6.3.4-5"/>
        <vers num="6.3.4-6"/>
        <vers num="6.3.4-8"/>
        <vers num="6.3.4-9"/>
        <vers num="6.3.5"/>
        <vers num="6.3.5-10"/>
        <vers num="6.3.5-4"/>
        <vers num="6.3.5-5"/>
        <vers num="6.3.5-6"/>
        <vers num="6.3.5-7"/>
        <vers num="6.3.5-9"/>
        <vers num="6.3.6"/>
        <vers num="6.3.6-1"/>
        <vers num="6.3.6-10"/>
        <vers num="6.3.6-2"/>
        <vers num="6.3.6-3"/>
        <vers num="6.3.6-4"/>
        <vers num="6.3.6-5"/>
        <vers num="6.3.6-6"/>
        <vers num="6.3.6-7"/>
        <vers num="6.3.6-8"/>
        <vers num="6.3.6-9"/>
        <vers num="6.3.7"/>
        <vers num="6.3.7-1"/>
        <vers num="6.3.7-10"/>
        <vers num="6.3.7-2"/>
        <vers num="6.3.7-3"/>
        <vers num="6.3.7-4"/>
        <vers num="6.3.7-5"/>
        <vers num="6.3.7-7"/>
        <vers num="6.3.7-9"/>
        <vers num="6.3.8"/>
        <vers num="6.3.8-1"/>
        <vers num="6.3.8-10"/>
        <vers num="6.3.8-2"/>
        <vers num="6.3.8-3"/>
        <vers num="6.3.8-5"/>
        <vers num="6.3.8-6"/>
        <vers num="6.3.8-7"/>
        <vers num="6.3.8-9"/>
        <vers num="6.3.9"/>
        <vers num="6.3.9-1"/>
        <vers num="6.3.9-10"/>
        <vers num="6.3.9-2"/>
        <vers num="6.3.9-4"/>
        <vers num="6.3.9-5"/>
        <vers num="6.3.9-6"/>
        <vers num="6.3.9-7"/>
        <vers num="6.3.9-8"/>
        <vers num="6.3.9-9"/>
        <vers num="6.4.0"/>
        <vers num="6.4.0-1"/>
        <vers num="6.4.0-10"/>
        <vers num="6.4.0-11"/>
        <vers num="6.4.0-4"/>
        <vers num="6.4.0-5"/>
        <vers num="6.4.0-6"/>
        <vers num="6.4.0-7"/>
        <vers num="6.4.0-8"/>
        <vers num="6.4.1"/>
        <vers num="6.4.1-1"/>
        <vers num="6.4.1-2"/>
        <vers num="6.4.1-3"/>
        <vers num="6.4.1-4"/>
        <vers num="6.4.1-5"/>
        <vers num="6.4.1-6"/>
        <vers num="6.4.1-7"/>
        <vers num="6.4.1-8"/>
        <vers num="6.4.1-9"/>
        <vers num="6.4.2"/>
        <vers num="6.4.2-1"/>
        <vers num="6.4.2-10"/>
        <vers num="6.4.2-2"/>
        <vers num="6.4.2-4"/>
        <vers num="6.4.2-5"/>
        <vers num="6.4.2-6"/>
        <vers num="6.4.2-7"/>
        <vers num="6.4.2-8"/>
        <vers num="6.4.2-9"/>
        <vers num="6.4.3"/>
        <vers num="6.4.3-1"/>
        <vers num="6.4.3-10"/>
        <vers num="6.4.3-2"/>
        <vers num="6.4.3-3"/>
        <vers num="6.4.3-5"/>
        <vers num="6.4.3-6"/>
        <vers num="6.4.3-7"/>
        <vers num="6.4.3-8"/>
        <vers num="6.4.4"/>
        <vers num="6.4.4-1"/>
        <vers num="6.4.4-3"/>
        <vers num="6.4.4-5"/>
        <vers num="6.4.4-7"/>
        <vers num="6.4.4-8"/>
        <vers num="6.4.5"/>
        <vers num="6.4.5-1"/>
        <vers num="6.4.5-2"/>
        <vers num="6.4.5-3"/>
        <vers num="6.4.5-4"/>
        <vers num="6.4.5-6"/>
        <vers num="6.4.5-7"/>
        <vers num="6.4.5-9"/>
        <vers num="6.4.6"/>
        <vers num="6.4.6-1"/>
        <vers num="6.4.6-2"/>
        <vers num="6.4.6-3"/>
        <vers num="6.4.6-4"/>
        <vers num="6.4.6-5"/>
        <vers num="6.4.6-6"/>
        <vers num="6.4.6-8"/>
        <vers num="6.4.6-9"/>
        <vers num="6.4.7-1"/>
        <vers num="6.4.7-10"/>
        <vers num="6.4.7-2"/>
        <vers num="6.4.7-3"/>
        <vers num="6.4.7-4"/>
        <vers num="6.4.7-5"/>
        <vers num="6.4.7-6"/>
        <vers num="6.4.7-7"/>
        <vers num="6.4.7-8"/>
        <vers num="6.4.7-9"/>
        <vers num="6.4.8"/>
        <vers num="6.4.8-1"/>
        <vers num="6.4.8-10"/>
        <vers num="6.4.8-2"/>
        <vers num="6.4.8-3"/>
        <vers num="6.4.8-4"/>
        <vers num="6.4.8-5"/>
        <vers num="6.4.8-6"/>
        <vers num="6.4.8-7"/>
        <vers num="6.4.8-8"/>
        <vers num="6.4.8-9"/>
        <vers num="6.4.9"/>
        <vers num="6.4.9-10"/>
        <vers num="6.4.9-2"/>
        <vers num="6.4.9-3"/>
        <vers num="6.4.9-5"/>
        <vers num="6.4.9-7"/>
        <vers num="6.4.9-8"/>
        <vers num="6.4.9-9"/>
        <vers num="6.5.0"/>
        <vers num="6.5.0-1"/>
        <vers num="6.5.0-10"/>
        <vers num="6.5.0-2"/>
        <vers num="6.5.0-3"/>
        <vers num="6.5.0-4"/>
        <vers num="6.5.0-5"/>
        <vers num="6.5.0-6"/>
        <vers num="6.5.0-7"/>
        <vers num="6.5.0-8"/>
        <vers num="6.5.0-9"/>
        <vers num="6.5.1"/>
        <vers num="6.5.1-1"/>
        <vers num="6.5.1-10"/>
        <vers num="6.5.1-2"/>
        <vers num="6.5.1-3"/>
        <vers num="6.5.1-4"/>
        <vers num="6.5.1-5"/>
        <vers num="6.5.1-6"/>
        <vers num="6.5.1-7"/>
        <vers num="6.5.1-9"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2-1"/>
        <vers num="6.5.2-10"/>
        <vers num="6.5.2-2"/>
        <vers num="6.5.2-3"/>
        <vers num="6.5.2-4"/>
        <vers num="6.5.2-5"/>
        <vers num="6.5.2-6"/>
        <vers num="6.5.2-7"/>
        <vers num="6.5.2-8"/>
        <vers num="6.5.2-9"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3-1"/>
        <vers num="6.5.3-10"/>
        <vers num="6.5.3-3"/>
        <vers num="6.5.3-4"/>
        <vers num="6.5.3-5"/>
        <vers num="6.5.3-6"/>
        <vers num="6.5.3-7"/>
        <vers num="6.5.3-8"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4-1"/>
        <vers num="6.5.4-10"/>
        <vers num="6.5.4-2"/>
        <vers num="6.5.4-3"/>
        <vers num="6.5.4-4"/>
        <vers num="6.5.4-5"/>
        <vers num="6.5.4-6"/>
        <vers num="6.5.4-7"/>
        <vers num="6.5.4-8"/>
        <vers num="6.5.4-9"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5-1"/>
        <vers num="6.5.5-10"/>
        <vers num="6.5.5-2"/>
        <vers num="6.5.5-3"/>
        <vers num="6.5.5-4"/>
        <vers num="6.5.5-5"/>
        <vers num="6.5.5-6"/>
        <vers num="6.5.5-7"/>
        <vers num="6.5.5-8"/>
        <vers num="6.5.5-9"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6-10"/>
        <vers num="6.5.6-2"/>
        <vers num="6.5.6-3"/>
        <vers num="6.5.6-4"/>
        <vers num="6.5.6-5"/>
        <vers num="6.5.6-6"/>
        <vers num="6.5.6-7"/>
        <vers num="6.5.6-8"/>
        <vers num="6.5.6-9"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7-1"/>
        <vers num="6.5.7-2"/>
        <vers num="6.5.7-3"/>
        <vers num="6.5.7-4"/>
        <vers num="6.5.7-5"/>
        <vers num="6.5.7-6"/>
        <vers num="6.5.7-7"/>
        <vers num="6.5.7-8"/>
        <vers num="6.5.7-9"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8-1"/>
        <vers num="6.5.8-2"/>
        <vers num="6.5.8-3"/>
        <vers num="6.5.8-4"/>
        <vers num="6.5.8-5"/>
        <vers num="6.5.8-6"/>
        <vers num="6.5.8-7"/>
        <vers num="6.5.8-8"/>
        <vers num="6.5.8-9"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9-1"/>
        <vers num="6.5.9-10"/>
        <vers num="6.5.9-2"/>
        <vers num="6.5.9-3"/>
        <vers num="6.5.9-4"/>
        <vers num="6.5.9-5"/>
        <vers num="6.5.9-6"/>
        <vers num="6.5.9-7"/>
        <vers num="6.5.9-8"/>
        <vers num="6.6.0"/>
        <vers num="6.6.0-1"/>
        <vers num="6.6.0-10"/>
        <vers num="6.6.0-2"/>
        <vers num="6.6.0-4"/>
        <vers num="6.6.0-5"/>
        <vers num="6.6.0-6"/>
        <vers num="6.6.0-7"/>
        <vers num="6.6.0-8"/>
        <vers num="6.6.0-9"/>
        <vers num="6.6.1"/>
        <vers num="6.6.1-1"/>
        <vers num="6.6.1-10"/>
        <vers num="6.6.1-2"/>
        <vers num="6.6.1-3"/>
        <vers num="6.6.1-4"/>
        <vers num="6.6.1-5"/>
        <vers num="6.6.1-6"/>
        <vers num="6.6.1-7"/>
        <vers num="6.6.1-8"/>
        <vers num="6.6.1-9"/>
        <vers num="6.6.2"/>
        <vers num="6.6.2-1"/>
        <vers num="6.6.2-10"/>
        <vers num="6.6.2-2"/>
        <vers num="6.6.2-3"/>
        <vers num="6.6.2-4"/>
        <vers num="6.6.2-5"/>
        <vers num="6.6.2-6"/>
        <vers num="6.6.2-7"/>
        <vers num="6.6.2-8"/>
        <vers num="6.6.2-9"/>
        <vers num="6.6.3"/>
        <vers num="6.6.3-1"/>
        <vers num="6.6.3-10"/>
        <vers num="6.6.3-2"/>
        <vers num="6.6.3-3"/>
        <vers num="6.6.3-4"/>
        <vers num="6.6.3-5"/>
        <vers num="6.6.3-6"/>
        <vers num="6.6.3-7"/>
        <vers num="6.6.4"/>
        <vers num="6.6.4-1"/>
        <vers num="6.6.4-10"/>
        <vers num="6.6.4-2"/>
        <vers num="6.6.4-4"/>
        <vers num="6.6.4-5"/>
        <vers num="6.6.4-6"/>
        <vers num="6.6.4-7"/>
        <vers num="6.6.4-8"/>
        <vers num="6.6.4-9"/>
        <vers num="6.6.5"/>
        <vers num="6.6.5-1"/>
        <vers num="6.6.5-10"/>
        <vers num="6.6.5-2"/>
        <vers num="6.6.5-3"/>
        <vers num="6.6.5-4"/>
        <vers num="6.6.5-5"/>
        <vers num="6.6.5-6"/>
        <vers num="6.6.5-7"/>
        <vers num="6.6.5-8"/>
        <vers num="6.6.5-9"/>
        <vers num="6.6.6-0"/>
        <vers num="6.6.6-1"/>
        <vers num="6.6.6-10"/>
        <vers num="6.6.6-2"/>
        <vers num="6.6.6-3"/>
        <vers num="6.6.6-4"/>
        <vers num="6.6.6-5"/>
        <vers num="6.6.6-6"/>
        <vers num="6.6.6-7"/>
        <vers num="6.6.6-8"/>
        <vers num="6.6.6-9"/>
        <vers num="6.6.7-0"/>
        <vers num="6.6.7-1"/>
        <vers num="6.6.7-10"/>
        <vers num="6.6.7-2"/>
        <vers num="6.6.7-3"/>
        <vers num="6.6.7-4"/>
        <vers num="6.6.7-5"/>
        <vers num="6.6.7-6"/>
        <vers num="6.6.7-7"/>
        <vers num="6.6.7-8"/>
        <vers num="6.6.7-9"/>
        <vers num="6.6.8-0"/>
        <vers num="6.6.9-0"/>
        <vers num="6.6.9-1"/>
        <vers num="6.6.9-10"/>
        <vers num="6.6.9-2"/>
        <vers num="6.6.9-3"/>
        <vers num="6.6.9-4"/>
        <vers num="6.6.9-5"/>
        <vers num="6.6.9-6"/>
        <vers num="6.6.9-7"/>
        <vers num="6.6.9-8"/>
        <vers num="6.6.9-9"/>
        <vers num="6.7.0-0"/>
        <vers num="6.7.0-1"/>
        <vers num="6.7.0-10"/>
        <vers num="6.7.0-2"/>
        <vers num="6.7.0-3"/>
        <vers num="6.7.0-4"/>
        <vers num="6.7.0-5"/>
        <vers num="6.7.0-6"/>
        <vers num="6.7.0-7"/>
        <vers num="6.7.0-8"/>
        <vers num="6.7.0-9"/>
        <vers num="6.7.1-0"/>
        <vers num="6.7.1-1"/>
        <vers num="6.7.1-10"/>
        <vers num="6.7.1-2"/>
        <vers num="6.7.1-3"/>
        <vers num="6.7.1-4"/>
        <vers num="6.7.1-5"/>
        <vers num="6.7.1-6"/>
        <vers num="6.7.1-7"/>
        <vers num="6.7.1-8"/>
        <vers num="6.7.1-9"/>
        <vers num="6.7.2-0"/>
        <vers num="6.7.2-1"/>
        <vers num="6.7.2-10"/>
        <vers num="6.7.2-2"/>
        <vers num="6.7.2-3"/>
        <vers num="6.7.2-4"/>
        <vers num="6.7.2-5"/>
        <vers num="6.7.2-6"/>
        <vers num="6.7.2-7"/>
        <vers num="6.7.2-8"/>
        <vers num="6.7.2-9"/>
        <vers num="6.7.3-0"/>
        <vers num="6.7.3-1"/>
        <vers num="6.7.3-10"/>
        <vers num="6.7.3-2"/>
        <vers num="6.7.3-3"/>
        <vers num="6.7.3-4"/>
        <vers num="6.7.3-5"/>
        <vers num="6.7.3-6"/>
        <vers num="6.7.3-7"/>
        <vers num="6.7.3-8"/>
        <vers num="6.7.3-9"/>
        <vers num="6.7.4-0"/>
        <vers num="6.7.4-1"/>
        <vers num="6.7.4-10"/>
        <vers num="6.7.4-2"/>
        <vers num="6.7.4-3"/>
        <vers num="6.7.4-4"/>
        <vers num="6.7.4-5"/>
        <vers num="6.7.4-6"/>
        <vers num="6.7.4-7"/>
        <vers num="6.7.4-8"/>
        <vers num="6.7.4-9"/>
        <vers num="6.7.5-0"/>
        <vers num="6.7.5-1"/>
        <vers num="6.7.5-2"/>
        <vers num="6.7.5-3"/>
        <vers num="6.7.5-4"/>
        <vers num="6.7.5-5"/>
        <vers num="6.7.5-6"/>
        <vers prev="1" num="6.7.5-7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0249" published="2012-04-05" name="CVE-2012-0249" modified="2013-01-03" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a Link State Update (aka LS Update) packet that is smaller than the length specified in its header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/551715" source="CERT-VN" patch="1">VU#551715</ref>
      <ref url="https://bugzilla.quagga.net/show_bug.cgi?id=705" source="CONFIRM" patch="1">https://bugzilla.quagga.net/show_bug.cgi?id=705</ref>
      <ref url="http://secunia.com/advisories/48949" source="SECUNIA">48949</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1259.html" source="REDHAT">RHSA-2012:1259</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1258.html" source="REDHAT">RHSA-2012:1258</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078926.html" source="FEDORA">FEDORA-2012-5436</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078910.html" source="FEDORA">FEDORA-2012-5411</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078794.html" source="FEDORA">FEDORA-2012-5352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quagga" name="quagga">
        <vers num="0.95"/>
        <vers num="0.96"/>
        <vers num="0.96.1"/>
        <vers num="0.96.2"/>
        <vers num="0.96.3"/>
        <vers num="0.96.4"/>
        <vers num="0.96.5"/>
        <vers num="0.97.0"/>
        <vers num="0.97.1"/>
        <vers num="0.97.2"/>
        <vers num="0.97.3"/>
        <vers num="0.97.4"/>
        <vers num="0.97.5"/>
        <vers num="0.98.0"/>
        <vers num="0.98.1"/>
        <vers num="0.98.2"/>
        <vers num="0.98.3"/>
        <vers num="0.98.4"/>
        <vers num="0.98.5"/>
        <vers num="0.98.6"/>
        <vers num="0.99.1"/>
        <vers num="0.99.10"/>
        <vers num="0.99.11"/>
        <vers num="0.99.12"/>
        <vers num="0.99.13"/>
        <vers num="0.99.14"/>
        <vers num="0.99.15"/>
        <vers num="0.99.16"/>
        <vers num="0.99.17"/>
        <vers num="0.99.18"/>
        <vers num="0.99.19"/>
        <vers num="0.99.2"/>
        <vers prev="1" num="0.99.20"/>
        <vers num="0.99.3"/>
        <vers num="0.99.4"/>
        <vers num="0.99.5"/>
        <vers num="0.99.6"/>
        <vers num="0.99.7"/>
        <vers num="0.99.8"/>
        <vers num="0.99.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0250" published="2012-04-05" name="CVE-2012-0250" modified="2013-01-03" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA link-state advertisement for which the data-structure length is smaller than the value in the Length header field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/551715" source="CERT-VN">VU#551715</ref>
      <ref url="http://secunia.com/advisories/48949" source="SECUNIA">48949</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1259.html" source="REDHAT">RHSA-2012:1259</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1258.html" source="REDHAT">RHSA-2012:1258</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078926.html" source="FEDORA">FEDORA-2012-5436</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078910.html" source="FEDORA">FEDORA-2012-5411</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078794.html" source="FEDORA">FEDORA-2012-5352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quagga" name="quagga">
        <vers num="0.99.1"/>
        <vers num="0.99.10"/>
        <vers num="0.99.11"/>
        <vers num="0.99.12"/>
        <vers num="0.99.13"/>
        <vers num="0.99.14"/>
        <vers num="0.99.15"/>
        <vers num="0.99.16"/>
        <vers num="0.99.17"/>
        <vers num="0.99.18"/>
        <vers num="0.99.19"/>
        <vers num="0.99.2"/>
        <vers prev="1" num="0.99.20"/>
        <vers num="0.99.3"/>
        <vers num="0.99.4"/>
        <vers num="0.99.5"/>
        <vers num="0.99.6"/>
        <vers num="0.99.7"/>
        <vers num="0.99.8"/>
        <vers num="0.99.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0253" published="2012-04-18" name="CVE-2012-0253" modified="2013-02-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Demand Media Pluck SiteLife before 5.0.13 allow remote attackers to inject arbitrary web script or HTML via (1) the jsonRequest parameter to Direct/Process, the (2) r or (3) cb parameter to Direct/jsonp.htm, or (4) the cb parameter to sys/jsonp.app/.htm.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/MAPG-8Q6JEG" source="CONFIRM">http://www.kb.cert.org/vuls/id/MAPG-8Q6JEG</ref>
      <ref url="http://www.kb.cert.org/vuls/id/400619" source="CERT-VN">VU#400619</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74805" source="XF">plucksitelife-multiple-xss(74805)</ref>
      <ref url="http://www.securityfocus.com/bid/52968" source="BID">52968</ref>
      <ref url="http://secunia.com/advisories/48778" source="SECUNIA">48778</ref>
    </refs>
    <vuln_soft>
      <prod vendor="demandmedia" name="pluck_sitelife">
        <vers prev="1" num="5.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0254" published="2012-09-08" name="CVE-2012-0254" modified="2012-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the HMIWeb Browser HSCDSPRenderDLL ActiveX control in Honeywell Process Solutions (HPS) Experion R2xx, R30x, R31x, and R400.x; Honeywell Building Solutions (HBS) Enterprise Building Manager R400 and R410.1; and Honeywell Environmental Combustion and Controls (ECC) SymmetrE R410.1 allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-150-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-150-01.pdf</ref>
      <ref url="https://www.honeywellprocess.com/en-US/support/pages/all-notifications.aspx" source="MISC">https://www.honeywellprocess.com/en-US/support/pages/all-notifications.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="honeywellprocess" name="enterprise_building_manager">
        <vers num="r400"/>
        <vers num="r410.1"/>
      </prod>
      <prod vendor="honeywellprocess" name="experion">
        <vers num="r200"/>
        <vers num="r300"/>
        <vers num="r310"/>
        <vers num="r400.0"/>
      </prod>
      <prod vendor="honeywellprocess" name="symmetre">
        <vers num="r410.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0255" published="2012-04-05" name="CVE-2012-0255" modified="2013-01-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The BGP implementation in bgpd in Quagga before 0.99.20.1 does not properly use message buffers for OPEN messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a message associated with a malformed Four-octet AS Number Capability (aka AS4 capability).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/551715" source="CERT-VN">VU#551715</ref>
      <ref url="http://secunia.com/advisories/48949" source="SECUNIA">48949</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1259.html" source="REDHAT">RHSA-2012:1259</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078926.html" source="FEDORA">FEDORA-2012-5436</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078910.html" source="FEDORA">FEDORA-2012-5411</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078794.html" source="FEDORA">FEDORA-2012-5352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quagga" name="quagga">
        <vers num="0.95"/>
        <vers num="0.96"/>
        <vers num="0.96.1"/>
        <vers num="0.96.2"/>
        <vers num="0.96.3"/>
        <vers num="0.96.4"/>
        <vers num="0.96.5"/>
        <vers num="0.97.0"/>
        <vers num="0.97.1"/>
        <vers num="0.97.2"/>
        <vers num="0.97.3"/>
        <vers num="0.97.4"/>
        <vers num="0.97.5"/>
        <vers num="0.98.0"/>
        <vers num="0.98.1"/>
        <vers num="0.98.2"/>
        <vers num="0.98.3"/>
        <vers num="0.98.4"/>
        <vers num="0.98.5"/>
        <vers num="0.98.6"/>
        <vers num="0.99.1"/>
        <vers num="0.99.10"/>
        <vers num="0.99.11"/>
        <vers num="0.99.12"/>
        <vers num="0.99.13"/>
        <vers num="0.99.14"/>
        <vers num="0.99.15"/>
        <vers num="0.99.16"/>
        <vers num="0.99.17"/>
        <vers num="0.99.18"/>
        <vers num="0.99.19"/>
        <vers num="0.99.2"/>
        <vers prev="1" num="0.99.20"/>
        <vers num="0.99.3"/>
        <vers num="0.99.4"/>
        <vers num="0.99.5"/>
        <vers num="0.99.6"/>
        <vers num="0.99.7"/>
        <vers num="0.99.8"/>
        <vers num="0.99.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0256" published="2012-03-26" name="CVE-2012-0256" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long HTTP Host header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://trafficserver.apache.org/downloads" source="CONFIRM" patch="1">http://trafficserver.apache.org/downloads</ref>
      <ref url="https://www.cert.fi/en/reports/2012/vulnerability612884.html" source="MISC">https://www.cert.fi/en/reports/2012/vulnerability612884.html</ref>
      <ref url="http://www.securitytracker.com/id?1026847" source="SECTRACK">1026847</ref>
      <ref url="http://www.securityfocus.com/bid/52696" source="BID">52696</ref>
      <ref url="http://seclists.org/fulldisclosure/2012/Mar/260" source="FULLDISC">20120322 [ANNOUNCE] Apache Traffic Server releases for security incident CVE-2012-0256</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-03/0118.html" source="BUGTRAQ">20120322 [ANNOUNCE] Apache Traffic Server releases for security incident CVE-2012-0256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="traffic_server">
        <vers num="2.0.0" edition="alpha"/>
        <vers num="2.0.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0257" published="2012-04-02" name="CVE-2012-0257" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the Open member, leading to a function-pointer overwrite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-081-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-081-01.pdf</ref>
      <ref url="https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000071.pdf" source="MISC">https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000071.pdf</ref>
      <ref url="http://secunia.com/advisories/48675" source="SECUNIA">48675</ref>
      <ref url="http://osvdb.org/80891" source="OSVDB">80891</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invensys" name="archestra_application_object_toolkit">
        <vers prev="1" num="3.2"/>
      </prod>
      <prod vendor="invensys" name="foxboro_control_software">
        <vers prev="1" num="3.1"/>
      </prod>
      <prod vendor="invensys" name="infusion_control_edition">
        <vers prev="1" num="2.5"/>
      </prod>
      <prod vendor="invensys" name="infusion_foundation_edition">
        <vers prev="1" num="2.5"/>
      </prod>
      <prod vendor="invensys" name="infusion_scada">
        <vers prev="1" num="2.5"/>
      </prod>
      <prod vendor="invensys" name="intouch">
        <vers num="10.0"/>
        <vers num="10.5"/>
      </prod>
      <prod vendor="invensys" name="wonderware_application_server">
        <vers prev="1" num="2012"/>
      </prod>
      <prod vendor="invensys" name="wonderware_information_server">
        <vers num="3.1"/>
        <vers num="4.0" edition="sp1"/>
        <vers prev="1" num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0258" published="2012-04-02" name="CVE-2012-0258" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the AddFile member.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-081-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-081-01.pdf</ref>
      <ref url="https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000071.pdf" source="MISC">https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000071.pdf</ref>
      <ref url="http://secunia.com/advisories/48675" source="SECUNIA">48675</ref>
      <ref url="http://osvdb.org/80891" source="OSVDB">80891</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invensys" name="archestra_application_object_toolkit">
        <vers prev="1" num="3.2"/>
      </prod>
      <prod vendor="invensys" name="foxboro_control_software">
        <vers prev="1" num="3.1"/>
      </prod>
      <prod vendor="invensys" name="infusion_control_edition">
        <vers prev="1" num="2.5"/>
      </prod>
      <prod vendor="invensys" name="infusion_foundation_edition">
        <vers prev="1" num="2.5"/>
      </prod>
      <prod vendor="invensys" name="infusion_scada">
        <vers prev="1" num="2.5"/>
      </prod>
      <prod vendor="invensys" name="intouch">
        <vers num="10.0"/>
        <vers num="10.5"/>
      </prod>
      <prod vendor="invensys" name="wonderware_application_server">
        <vers prev="1" num="2012"/>
      </prod>
      <prod vendor="invensys" name="wonderware_information_server">
        <vers num="3.1"/>
        <vers num="4.0" edition="sp1"/>
        <vers prev="1" num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0259" published="2012-06-05" name="CVE-2012-0259" modified="2012-11-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0259" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0259</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74657" source="XF">imagemagick-jpegexif-dos(74657)</ref>
      <ref url="http://www.securitytracker.com/id?1027032" source="SECTRACK">1027032</ref>
      <ref url="http://www.securityfocus.com/bid/51957" source="BID">52898</ref>
      <ref url="http://www.osvdb.org/81021" source="OSVDB">81021</ref>
      <ref url="http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&amp;t=20629" source="CONFIRM" adv="1">http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&amp;t=20629</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2462" source="DEBIAN">DSA-2462</ref>
      <ref url="http://www.cert.fi/en/reports/2012/vulnerability635606.html" source="MISC">http://www.cert.fi/en/reports/2012/vulnerability635606.html</ref>
      <ref url="http://ubuntu.com/usn/usn-1435-1" source="UBUNTU">USN-1435-1</ref>
      <ref url="http://secunia.com/advisories/49317" source="SECUNIA" adv="1">49317</ref>
      <ref url="http://secunia.com/advisories/49063" source="SECUNIA" adv="1">49063</ref>
      <ref url="http://secunia.com/advisories/49043" source="SECUNIA" adv="1">49043</ref>
      <ref url="http://secunia.com/advisories/48974" source="SECUNIA" adv="1">48974</ref>
      <ref url="http://secunia.com/advisories/48679" source="SECUNIA" adv="1">48679</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0544.html" source="REDHAT">RHSA-2012:0544</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2012-06/msg00001.html" source="SUSE">openSUSE-SU-2012:0692</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="4.2.7"/>
        <vers num="4.2.9"/>
        <vers num="5.2"/>
        <vers num="5.2.0"/>
        <vers num="5.2.4.3"/>
        <vers num="5.2.6"/>
        <vers num="5.3"/>
        <vers num="5.3.0"/>
        <vers num="5.3.1"/>
        <vers num="5.3.2"/>
        <vers num="5.3.3"/>
        <vers num="5.3.4"/>
        <vers num="5.3.5"/>
        <vers num="5.3.6"/>
        <vers num="5.3.7"/>
        <vers num="5.3.8"/>
        <vers num="5.3.8.2"/>
        <vers num="5.3.9"/>
        <vers num="5.4"/>
        <vers num="5.4.0.5"/>
        <vers num="5.4.1.2"/>
        <vers num="5.4.2.3"/>
        <vers num="5.4.3"/>
        <vers num="5.4.3.11"/>
        <vers num="5.4.4.5"/>
        <vers num="5.4.5.1"/>
        <vers num="5.4.6.3"/>
        <vers num="5.4.7"/>
        <vers num="5.4.7.4"/>
        <vers num="5.4.8"/>
        <vers num="5.4.8.3"/>
        <vers num="5.4.9.1"/>
        <vers num="5.5"/>
        <vers num="5.5.1.4"/>
        <vers num="5.5.2.5"/>
        <vers num="5.5.3.2"/>
        <vers num="5.5.3.2.1.2.0"/>
        <vers num="5.5.4"/>
        <vers num="5.5.4.4"/>
        <vers num="5.5.5.3"/>
        <vers num="5.5.6"/>
        <vers num="5.5.6.0_2003-04-09"/>
        <vers num="5.5.6.0_20030409"/>
        <vers num="5.5.7"/>
        <vers num="5.5.7.15"/>
        <vers num="5.5.7.31"/>
        <vers num="5.5.7.35"/>
        <vers num="5.5.7q16"/>
        <vers num="5.5.7q8"/>
        <vers num="6.0"/>
        <vers num="6.0.0.7"/>
        <vers num="6.0.1"/>
        <vers num="6.0.1.4"/>
        <vers num="6.0.2"/>
        <vers num="6.0.2.5"/>
        <vers num="6.0.2.7"/>
        <vers num="6.0.3"/>
        <vers num="6.0.3.5"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.4"/>
        <vers num="6.0.5"/>
        <vers num="6.0.5.3"/>
        <vers num="6.0.6"/>
        <vers num="6.0.6.1"/>
        <vers num="6.0.6.2"/>
        <vers num="6.0.7"/>
        <vers num="6.0.7.3"/>
        <vers num="6.0.8"/>
        <vers num="6.0.8.3"/>
        <vers num="6.1"/>
        <vers num="6.1.0.9"/>
        <vers num="6.1.1"/>
        <vers num="6.1.1.6"/>
        <vers num="6.1.2"/>
        <vers num="6.1.2.7"/>
        <vers num="6.1.3"/>
        <vers num="6.1.3.7"/>
        <vers num="6.1.4"/>
        <vers num="6.1.4.5"/>
        <vers num="6.1.5"/>
        <vers num="6.1.5.8"/>
        <vers num="6.1.6"/>
        <vers num="6.1.6.9"/>
        <vers num="6.1.7"/>
        <vers num="6.1.7.5"/>
        <vers num="6.1.8"/>
        <vers num="6.1.8.7"/>
        <vers num="6.1.9.4"/>
        <vers num="6.2"/>
        <vers num="6.2.0.3"/>
        <vers num="6.2.0.4"/>
        <vers num="6.2.0.7"/>
        <vers num="6.2.0.8"/>
        <vers num="6.2.1"/>
        <vers num="6.2.1.7"/>
        <vers num="6.2.2"/>
        <vers num="6.2.2.5"/>
        <vers num="6.2.3"/>
        <vers num="6.2.3.4"/>
        <vers num="6.2.3.6"/>
        <vers num="6.2.4"/>
        <vers num="6.2.4.3"/>
        <vers num="6.2.4.5"/>
        <vers num="6.2.5"/>
        <vers num="6.2.6"/>
        <vers num="6.2.7"/>
        <vers num="6.2.8"/>
        <vers num="6.2.8.0"/>
        <vers num="6.2.8.1"/>
        <vers num="6.2.8.2"/>
        <vers num="6.2.8.3"/>
        <vers num="6.2.9"/>
        <vers num="6.2.9.2"/>
        <vers num="6.3.0.0"/>
        <vers num="6.3.0.1"/>
        <vers num="6.3.0.2"/>
        <vers num="6.3.0.3"/>
        <vers num="6.3.0.4"/>
        <vers num="6.3.0.5"/>
        <vers num="6.3.0.7"/>
        <vers num="6.3.0.8"/>
        <vers num="6.3.1"/>
        <vers num="6.3.1-6"/>
        <vers num="6.3.1-7"/>
        <vers num="6.3.1.0"/>
        <vers num="6.3.1.1"/>
        <vers num="6.3.1.2."/>
        <vers num="6.3.1.3"/>
        <vers num="6.3.1.4"/>
        <vers num="6.3.1.5"/>
        <vers num="6.3.1.6"/>
        <vers num="6.3.1.7"/>
        <vers num="6.3.2"/>
        <vers num="6.3.2-1"/>
        <vers num="6.3.2-2"/>
        <vers num="6.3.2-3"/>
        <vers num="6.3.2-4"/>
        <vers num="6.3.2-5"/>
        <vers num="6.3.2-6"/>
        <vers num="6.3.2-7"/>
        <vers num="6.3.2-8"/>
        <vers num="6.3.2.0"/>
        <vers num="6.3.2.1"/>
        <vers num="6.3.2.2"/>
        <vers num="6.3.2.3"/>
        <vers num="6.3.2.4"/>
        <vers num="6.3.2.5"/>
        <vers num="6.3.2.6"/>
        <vers num="6.3.2.7"/>
        <vers num="6.3.2.8"/>
        <vers num="6.3.3"/>
        <vers num="6.3.3-1"/>
        <vers num="6.3.3-2"/>
        <vers num="6.3.3-3"/>
        <vers num="6.3.3-4"/>
        <vers num="6.3.3-5"/>
        <vers num="6.3.3-6"/>
        <vers num="6.3.3-7"/>
        <vers num="6.3.3-8"/>
        <vers num="6.3.3-9"/>
        <vers num="6.3.3.0"/>
        <vers num="6.3.3.1"/>
        <vers num="6.3.3.2"/>
        <vers num="6.3.3.3"/>
        <vers num="6.3.3.4"/>
        <vers num="6.3.3_3"/>
        <vers num="6.3.3_5"/>
        <vers num="6.3.3_6"/>
        <vers num="6.3.4"/>
        <vers num="6.3.4-1"/>
        <vers num="6.3.4-10"/>
        <vers num="6.3.4-2"/>
        <vers num="6.3.4-3"/>
        <vers num="6.3.4-4"/>
        <vers num="6.3.4-5"/>
        <vers num="6.3.4-6"/>
        <vers num="6.3.4-8"/>
        <vers num="6.3.4-9"/>
        <vers num="6.3.5"/>
        <vers num="6.3.5-10"/>
        <vers num="6.3.5-4"/>
        <vers num="6.3.5-5"/>
        <vers num="6.3.5-6"/>
        <vers num="6.3.5-7"/>
        <vers num="6.3.5-9"/>
        <vers num="6.3.6"/>
        <vers num="6.3.6-1"/>
        <vers num="6.3.6-10"/>
        <vers num="6.3.6-2"/>
        <vers num="6.3.6-3"/>
        <vers num="6.3.6-4"/>
        <vers num="6.3.6-5"/>
        <vers num="6.3.6-6"/>
        <vers num="6.3.6-7"/>
        <vers num="6.3.6-8"/>
        <vers num="6.3.6-9"/>
        <vers num="6.3.7"/>
        <vers num="6.3.7-1"/>
        <vers num="6.3.7-10"/>
        <vers num="6.3.7-2"/>
        <vers num="6.3.7-3"/>
        <vers num="6.3.7-4"/>
        <vers num="6.3.7-5"/>
        <vers num="6.3.7-7"/>
        <vers num="6.3.7-9"/>
        <vers num="6.3.8"/>
        <vers num="6.3.8-1"/>
        <vers num="6.3.8-10"/>
        <vers num="6.3.8-2"/>
        <vers num="6.3.8-3"/>
        <vers num="6.3.8-5"/>
        <vers num="6.3.8-6"/>
        <vers num="6.3.8-7"/>
        <vers num="6.3.8-9"/>
        <vers num="6.3.9"/>
        <vers num="6.3.9-1"/>
        <vers num="6.3.9-10"/>
        <vers num="6.3.9-2"/>
        <vers num="6.3.9-4"/>
        <vers num="6.3.9-5"/>
        <vers num="6.3.9-6"/>
        <vers num="6.3.9-7"/>
        <vers num="6.3.9-8"/>
        <vers num="6.3.9-9"/>
        <vers num="6.4.0"/>
        <vers num="6.4.0-1"/>
        <vers num="6.4.0-10"/>
        <vers num="6.4.0-11"/>
        <vers num="6.4.0-4"/>
        <vers num="6.4.0-5"/>
        <vers num="6.4.0-6"/>
        <vers num="6.4.0-7"/>
        <vers num="6.4.0-8"/>
        <vers num="6.4.1"/>
        <vers num="6.4.1-1"/>
        <vers num="6.4.1-2"/>
        <vers num="6.4.1-3"/>
        <vers num="6.4.1-4"/>
        <vers num="6.4.1-5"/>
        <vers num="6.4.1-6"/>
        <vers num="6.4.1-7"/>
        <vers num="6.4.1-8"/>
        <vers num="6.4.1-9"/>
        <vers num="6.4.2"/>
        <vers num="6.4.2-1"/>
        <vers num="6.4.2-10"/>
        <vers num="6.4.2-2"/>
        <vers num="6.4.2-4"/>
        <vers num="6.4.2-5"/>
        <vers num="6.4.2-6"/>
        <vers num="6.4.2-7"/>
        <vers num="6.4.2-8"/>
        <vers num="6.4.2-9"/>
        <vers num="6.4.3"/>
        <vers num="6.4.3-1"/>
        <vers num="6.4.3-10"/>
        <vers num="6.4.3-2"/>
        <vers num="6.4.3-3"/>
        <vers num="6.4.3-5"/>
        <vers num="6.4.3-6"/>
        <vers num="6.4.3-7"/>
        <vers num="6.4.3-8"/>
        <vers num="6.4.4"/>
        <vers num="6.4.4-1"/>
        <vers num="6.4.4-3"/>
        <vers num="6.4.4-5"/>
        <vers num="6.4.4-7"/>
        <vers num="6.4.4-8"/>
        <vers num="6.4.5"/>
        <vers num="6.4.5-1"/>
        <vers num="6.4.5-2"/>
        <vers num="6.4.5-3"/>
        <vers num="6.4.5-4"/>
        <vers num="6.4.5-6"/>
        <vers num="6.4.5-7"/>
        <vers num="6.4.5-9"/>
        <vers num="6.4.6"/>
        <vers num="6.4.6-1"/>
        <vers num="6.4.6-2"/>
        <vers num="6.4.6-3"/>
        <vers num="6.4.6-4"/>
        <vers num="6.4.6-5"/>
        <vers num="6.4.6-6"/>
        <vers num="6.4.6-8"/>
        <vers num="6.4.6-9"/>
        <vers num="6.4.7-1"/>
        <vers num="6.4.7-10"/>
        <vers num="6.4.7-2"/>
        <vers num="6.4.7-3"/>
        <vers num="6.4.7-4"/>
        <vers num="6.4.7-5"/>
        <vers num="6.4.7-6"/>
        <vers num="6.4.7-7"/>
        <vers num="6.4.7-8"/>
        <vers num="6.4.7-9"/>
        <vers num="6.4.8"/>
        <vers num="6.4.8-1"/>
        <vers num="6.4.8-10"/>
        <vers num="6.4.8-2"/>
        <vers num="6.4.8-3"/>
        <vers num="6.4.8-4"/>
        <vers num="6.4.8-5"/>
        <vers num="6.4.8-6"/>
        <vers num="6.4.8-7"/>
        <vers num="6.4.8-8"/>
        <vers num="6.4.8-9"/>
        <vers num="6.4.9"/>
        <vers num="6.4.9-10"/>
        <vers num="6.4.9-2"/>
        <vers num="6.4.9-3"/>
        <vers num="6.4.9-5"/>
        <vers num="6.4.9-7"/>
        <vers num="6.4.9-8"/>
        <vers num="6.4.9-9"/>
        <vers num="6.5.0"/>
        <vers num="6.5.0-1"/>
        <vers num="6.5.0-10"/>
        <vers num="6.5.0-2"/>
        <vers num="6.5.0-3"/>
        <vers num="6.5.0-4"/>
        <vers num="6.5.0-5"/>
        <vers num="6.5.0-6"/>
        <vers num="6.5.0-7"/>
        <vers num="6.5.0-8"/>
        <vers num="6.5.0-9"/>
        <vers num="6.5.1"/>
        <vers num="6.5.1-1"/>
        <vers num="6.5.1-10"/>
        <vers num="6.5.1-2"/>
        <vers num="6.5.1-3"/>
        <vers num="6.5.1-4"/>
        <vers num="6.5.1-5"/>
        <vers num="6.5.1-6"/>
        <vers num="6.5.1-7"/>
        <vers num="6.5.1-9"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2-1"/>
        <vers num="6.5.2-10"/>
        <vers num="6.5.2-2"/>
        <vers num="6.5.2-3"/>
        <vers num="6.5.2-4"/>
        <vers num="6.5.2-5"/>
        <vers num="6.5.2-6"/>
        <vers num="6.5.2-7"/>
        <vers num="6.5.2-8"/>
        <vers num="6.5.2-9"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3-1"/>
        <vers num="6.5.3-10"/>
        <vers num="6.5.3-3"/>
        <vers num="6.5.3-4"/>
        <vers num="6.5.3-5"/>
        <vers num="6.5.3-6"/>
        <vers num="6.5.3-7"/>
        <vers num="6.5.3-8"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4-1"/>
        <vers num="6.5.4-10"/>
        <vers num="6.5.4-2"/>
        <vers num="6.5.4-3"/>
        <vers num="6.5.4-4"/>
        <vers num="6.5.4-5"/>
        <vers num="6.5.4-6"/>
        <vers num="6.5.4-7"/>
        <vers num="6.5.4-8"/>
        <vers num="6.5.4-9"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5-1"/>
        <vers num="6.5.5-10"/>
        <vers num="6.5.5-2"/>
        <vers num="6.5.5-3"/>
        <vers num="6.5.5-4"/>
        <vers num="6.5.5-5"/>
        <vers num="6.5.5-6"/>
        <vers num="6.5.5-7"/>
        <vers num="6.5.5-8"/>
        <vers num="6.5.5-9"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6-10"/>
        <vers num="6.5.6-2"/>
        <vers num="6.5.6-3"/>
        <vers num="6.5.6-4"/>
        <vers num="6.5.6-5"/>
        <vers num="6.5.6-6"/>
        <vers num="6.5.6-7"/>
        <vers num="6.5.6-8"/>
        <vers num="6.5.6-9"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7-1"/>
        <vers num="6.5.7-2"/>
        <vers num="6.5.7-3"/>
        <vers num="6.5.7-4"/>
        <vers num="6.5.7-5"/>
        <vers num="6.5.7-6"/>
        <vers num="6.5.7-7"/>
        <vers num="6.5.7-8"/>
        <vers num="6.5.7-9"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8-1"/>
        <vers num="6.5.8-2"/>
        <vers num="6.5.8-3"/>
        <vers num="6.5.8-4"/>
        <vers num="6.5.8-5"/>
        <vers num="6.5.8-6"/>
        <vers num="6.5.8-7"/>
        <vers num="6.5.8-8"/>
        <vers num="6.5.8-9"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9-1"/>
        <vers num="6.5.9-10"/>
        <vers num="6.5.9-2"/>
        <vers num="6.5.9-3"/>
        <vers num="6.5.9-4"/>
        <vers num="6.5.9-5"/>
        <vers num="6.5.9-6"/>
        <vers num="6.5.9-7"/>
        <vers num="6.5.9-8"/>
        <vers num="6.6.0"/>
        <vers num="6.6.0-1"/>
        <vers num="6.6.0-10"/>
        <vers num="6.6.0-2"/>
        <vers num="6.6.0-4"/>
        <vers num="6.6.0-5"/>
        <vers num="6.6.0-6"/>
        <vers num="6.6.0-7"/>
        <vers num="6.6.0-8"/>
        <vers num="6.6.0-9"/>
        <vers num="6.6.1"/>
        <vers num="6.6.1-1"/>
        <vers num="6.6.1-10"/>
        <vers num="6.6.1-2"/>
        <vers num="6.6.1-3"/>
        <vers num="6.6.1-4"/>
        <vers num="6.6.1-5"/>
        <vers num="6.6.1-6"/>
        <vers num="6.6.1-7"/>
        <vers num="6.6.1-8"/>
        <vers num="6.6.1-9"/>
        <vers num="6.6.2"/>
        <vers num="6.6.2-1"/>
        <vers num="6.6.2-10"/>
        <vers num="6.6.2-2"/>
        <vers num="6.6.2-3"/>
        <vers num="6.6.2-4"/>
        <vers num="6.6.2-5"/>
        <vers num="6.6.2-6"/>
        <vers num="6.6.2-7"/>
        <vers num="6.6.2-8"/>
        <vers num="6.6.2-9"/>
        <vers num="6.6.3"/>
        <vers num="6.6.3-1"/>
        <vers num="6.6.3-10"/>
        <vers num="6.6.3-2"/>
        <vers num="6.6.3-3"/>
        <vers num="6.6.3-4"/>
        <vers num="6.6.3-5"/>
        <vers num="6.6.3-6"/>
        <vers num="6.6.3-7"/>
        <vers num="6.6.4"/>
        <vers num="6.6.4-1"/>
        <vers num="6.6.4-10"/>
        <vers num="6.6.4-2"/>
        <vers num="6.6.4-4"/>
        <vers num="6.6.4-5"/>
        <vers num="6.6.4-6"/>
        <vers num="6.6.4-7"/>
        <vers num="6.6.4-8"/>
        <vers num="6.6.4-9"/>
        <vers num="6.6.5"/>
        <vers num="6.6.5-1"/>
        <vers num="6.6.5-10"/>
        <vers num="6.6.5-2"/>
        <vers num="6.6.5-3"/>
        <vers num="6.6.5-4"/>
        <vers num="6.6.5-5"/>
        <vers num="6.6.5-6"/>
        <vers num="6.6.5-7"/>
        <vers num="6.6.5-8"/>
        <vers num="6.6.5-9"/>
        <vers num="6.6.6-0"/>
        <vers num="6.6.6-1"/>
        <vers num="6.6.6-10"/>
        <vers num="6.6.6-2"/>
        <vers num="6.6.6-3"/>
        <vers num="6.6.6-4"/>
        <vers num="6.6.6-5"/>
        <vers num="6.6.6-6"/>
        <vers num="6.6.6-7"/>
        <vers num="6.6.6-8"/>
        <vers num="6.6.6-9"/>
        <vers num="6.6.7-0"/>
        <vers num="6.6.7-1"/>
        <vers num="6.6.7-10"/>
        <vers num="6.6.7-2"/>
        <vers num="6.6.7-3"/>
        <vers num="6.6.7-4"/>
        <vers num="6.6.7-5"/>
        <vers num="6.6.7-6"/>
        <vers num="6.6.7-7"/>
        <vers num="6.6.7-8"/>
        <vers num="6.6.7-9"/>
        <vers num="6.6.8-0"/>
        <vers num="6.6.9-0"/>
        <vers num="6.6.9-1"/>
        <vers num="6.6.9-10"/>
        <vers num="6.6.9-2"/>
        <vers num="6.6.9-3"/>
        <vers num="6.6.9-4"/>
        <vers num="6.6.9-5"/>
        <vers num="6.6.9-6"/>
        <vers num="6.6.9-7"/>
        <vers num="6.6.9-8"/>
        <vers num="6.6.9-9"/>
        <vers num="6.7.0-0"/>
        <vers num="6.7.0-1"/>
        <vers num="6.7.0-10"/>
        <vers num="6.7.0-2"/>
        <vers num="6.7.0-3"/>
        <vers num="6.7.0-4"/>
        <vers num="6.7.0-5"/>
        <vers num="6.7.0-6"/>
        <vers num="6.7.0-7"/>
        <vers num="6.7.0-8"/>
        <vers num="6.7.0-9"/>
        <vers num="6.7.1-0"/>
        <vers num="6.7.1-1"/>
        <vers num="6.7.1-10"/>
        <vers num="6.7.1-2"/>
        <vers num="6.7.1-3"/>
        <vers num="6.7.1-4"/>
        <vers num="6.7.1-5"/>
        <vers num="6.7.1-6"/>
        <vers num="6.7.1-7"/>
        <vers num="6.7.1-8"/>
        <vers num="6.7.1-9"/>
        <vers num="6.7.2-0"/>
        <vers num="6.7.2-1"/>
        <vers num="6.7.2-10"/>
        <vers num="6.7.2-2"/>
        <vers num="6.7.2-3"/>
        <vers num="6.7.2-4"/>
        <vers num="6.7.2-5"/>
        <vers num="6.7.2-6"/>
        <vers num="6.7.2-7"/>
        <vers num="6.7.2-8"/>
        <vers num="6.7.2-9"/>
        <vers num="6.7.3-0"/>
        <vers num="6.7.3-1"/>
        <vers num="6.7.3-10"/>
        <vers num="6.7.3-2"/>
        <vers num="6.7.3-3"/>
        <vers num="6.7.3-4"/>
        <vers num="6.7.3-5"/>
        <vers num="6.7.3-6"/>
        <vers num="6.7.3-7"/>
        <vers num="6.7.3-8"/>
        <vers num="6.7.3-9"/>
        <vers num="6.7.4-0"/>
        <vers num="6.7.4-1"/>
        <vers num="6.7.4-10"/>
        <vers num="6.7.4-2"/>
        <vers num="6.7.4-3"/>
        <vers num="6.7.4-4"/>
        <vers num="6.7.4-5"/>
        <vers num="6.7.4-6"/>
        <vers num="6.7.4-7"/>
        <vers num="6.7.4-8"/>
        <vers num="6.7.4-9"/>
        <vers num="6.7.5-0"/>
        <vers num="6.7.5-1"/>
        <vers num="6.7.5-10"/>
        <vers num="6.7.5-2"/>
        <vers num="6.7.5-3"/>
        <vers num="6.7.5-4"/>
        <vers num="6.7.5-5"/>
        <vers num="6.7.5-6"/>
        <vers num="6.7.5-7"/>
        <vers num="6.7.5-8"/>
        <vers num="6.7.5-9"/>
        <vers num="6.7.6-0"/>
        <vers num="6.7.6-1"/>
        <vers prev="1" num="6.7.6-2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0260" published="2012-06-05" name="CVE-2012-0260" modified="2012-11-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/52898" source="BID" patch="1">52898</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/74658" source="XF">imagemagick-jpegwarninghandler-dos(74658)</ref>
      <ref url="http://www.securitytracker.com/id?1027032" source="SECTRACK">1027032</ref>
      <ref url="http://www.osvdb.org/81022" source="OSVDB">81022</ref>
      <ref url="http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&amp;t=20629" source="CONFIRM" adv="1">http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&amp;t=20629</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2462" source="DEBIAN">DSA-2462</ref>
      <ref url="http://www.cert.fi/en/reports/2012/vulnerability635606.html" source="MISC">http://www.cert.fi/en/reports/2012/vulnerability635606.html</ref>
      <ref url="http://secunia.com/advisories/49317" source="SECUNIA" adv="1">49317</ref>
      <ref url="http://secunia.com/advisories/49068" source="SECUNIA" adv="1">49068</ref>
      <ref url="http://secunia.com/advisories/49063" source="SECUNIA" adv="1">49063</ref>
      <ref url="http://secunia.com/advisories/48974" source="SECUNIA" adv="1">48974</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0545.html" source="REDHAT">RHSA-2012:0545</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0544.html" source="REDHAT">RHSA-2012:0544</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2012-06/msg00001.html" source="SUSE">openSUSE-SU-2012:0692</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="4.2.7"/>
        <vers num="4.2.9"/>
        <vers num="5.2"/>
        <vers num="5.2.0"/>
        <vers num="5.2.4.3"/>
        <vers num="5.2.6"/>
        <vers num="5.3"/>
        <vers num="5.3.0"/>
        <vers num="5.3.1"/>
        <vers num="5.3.2"/>
        <vers num="5.3.3"/>
        <vers num="5.3.4"/>
        <vers num="5.3.5"/>
        <vers num="5.3.6"/>
        <vers num="5.3.7"/>
        <vers num="5.3.8"/>
        <vers num="5.3.8.2"/>
        <vers num="5.3.9"/>
        <vers num="5.4"/>
        <vers num="5.4.0.5"/>
        <vers num="5.4.1.2"/>
        <vers num="5.4.2.3"/>
        <vers num="5.4.3"/>
        <vers num="5.4.3.11"/>
        <vers num="5.4.4.5"/>
        <vers num="5.4.5.1"/>
        <vers num="5.4.6.3"/>
        <vers num="5.4.7"/>
        <vers num="5.4.7.4"/>
        <vers num="5.4.8"/>
        <vers num="5.4.8.3"/>
        <vers num="5.4.9.1"/>
        <vers num="5.5"/>
        <vers num="5.5.1.4"/>
        <vers num="5.5.2.5"/>
        <vers num="5.5.3.2"/>
        <vers num="5.5.3.2.1.2.0"/>
        <vers num="5.5.4"/>
        <vers num="5.5.4.4"/>
        <vers num="5.5.5.3"/>
        <vers num="5.5.6"/>
        <vers num="5.5.6.0_2003-04-09"/>
        <vers num="5.5.6.0_20030409"/>
        <vers num="5.5.7"/>
        <vers num="5.5.7.15"/>
        <vers num="5.5.7.31"/>
        <vers num="5.5.7.35"/>
        <vers num="5.5.7q16"/>
        <vers num="5.5.7q8"/>
        <vers num="6.0"/>
        <vers num="6.0.0.7"/>
        <vers num="6.0.1"/>
        <vers num="6.0.1.4"/>
        <vers num="6.0.2"/>
        <vers num="6.0.2.5"/>
        <vers num="6.0.2.7"/>
        <vers num="6.0.3"/>
        <vers num="6.0.3.5"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.4"/>
        <vers num="6.0.5"/>
        <vers num="6.0.5.3"/>
        <vers num="6.0.6"/>
        <vers num="6.0.6.1"/>
        <vers num="6.0.6.2"/>
        <vers num="6.0.7"/>
        <vers num="6.0.7.3"/>
        <vers num="6.0.8"/>
        <vers num="6.0.8.3"/>
        <vers num="6.1"/>
        <vers num="6.1.0.9"/>
        <vers num="6.1.1"/>
        <vers num="6.1.1.6"/>
        <vers num="6.1.2"/>
        <vers num="6.1.2.7"/>
        <vers num="6.1.3"/>
        <vers num="6.1.3.7"/>
        <vers num="6.1.4"/>
        <vers num="6.1.4.5"/>
        <vers num="6.1.5"/>
        <vers num="6.1.5.8"/>
        <vers num="6.1.6"/>
        <vers num="6.1.6.9"/>
        <vers num="6.1.7"/>
        <vers num="6.1.7.5"/>
        <vers num="6.1.8"/>
        <vers num="6.1.8.7"/>
        <vers num="6.1.9.4"/>
        <vers num="6.2"/>
        <vers num="6.2.0.3"/>
        <vers num="6.2.0.4"/>
        <vers num="6.2.0.7"/>
        <vers num="6.2.0.8"/>
        <vers num="6.2.1"/>
        <vers num="6.2.1.7"/>
        <vers num="6.2.2"/>
        <vers num="6.2.2.5"/>
        <vers num="6.2.3"/>
        <vers num="6.2.3.4"/>
        <vers num="6.2.3.6"/>
        <vers num="6.2.4"/>
        <vers num="6.2.4.3"/>
        <vers num="6.2.4.5"/>
        <vers num="6.2.5"/>
        <vers num="6.2.6"/>
        <vers num="6.2.7"/>
        <vers num="6.2.8"/>
        <vers num="6.2.8.0"/>
        <vers num="6.2.8.1"/>
        <vers num="6.2.8.2"/>
        <vers num="6.2.8.3"/>
        <vers num="6.2.9"/>
        <vers num="6.2.9.2"/>
        <vers num="6.3.0.0"/>
        <vers num="6.3.0.1"/>
        <vers num="6.3.0.2"/>
        <vers num="6.3.0.3"/>
        <vers num="6.3.0.4"/>
        <vers num="6.3.0.5"/>
        <vers num="6.3.0.7"/>
        <vers num="6.3.0.8"/>
        <vers num="6.3.1"/>
        <vers num="6.3.1-6"/>
        <vers num="6.3.1-7"/>
        <vers num="6.3.1.0"/>
        <vers num="6.3.1.1"/>
        <vers num="6.3.1.2."/>
        <vers num="6.3.1.3"/>
        <vers num="6.3.1.4"/>
        <vers num="6.3.1.5"/>
        <vers num="6.3.1.6"/>
        <vers num="6.3.1.7"/>
        <vers num="6.3.2"/>
        <vers num="6.3.2-1"/>
        <vers num="6.3.2-2"/>
        <vers num="6.3.2-3"/>
        <vers num="6.3.2-4"/>
        <vers num="6.3.2-5"/>
        <vers num="6.3.2-6"/>
        <vers num="6.3.2-7"/>
        <vers num="6.3.2-8"/>
        <vers num="6.3.2.0"/>
        <vers num="6.3.2.1"/>
        <vers num="6.3.2.2"/>
        <vers num="6.3.2.3"/>
        <vers num="6.3.2.4"/>
        <vers num="6.3.2.5"/>
        <vers num="6.3.2.6"/>
        <vers num="6.3.2.7"/>
        <vers num="6.3.2.8"/>
        <vers num="6.3.3"/>
        <vers num="6.3.3-1"/>
        <vers num="6.3.3-2"/>
        <vers num="6.3.3-3"/>
        <vers num="6.3.3-4"/>
        <vers num="6.3.3-5"/>
        <vers num="6.3.3-6"/>
        <vers num="6.3.3-7"/>
        <vers num="6.3.3-8"/>
        <vers num="6.3.3-9"/>
        <vers num="6.3.3.0"/>
        <vers num="6.3.3.1"/>
        <vers num="6.3.3.2"/>
        <vers num="6.3.3.3"/>
        <vers num="6.3.3.4"/>
        <vers num="6.3.3_3"/>
        <vers num="6.3.3_5"/>
        <vers num="6.3.3_6"/>
        <vers num="6.3.4"/>
        <vers num="6.3.4-1"/>
        <vers num="6.3.4-10"/>
        <vers num="6.3.4-2"/>
        <vers num="6.3.4-3"/>
        <vers num="6.3.4-4"/>
        <vers num="6.3.4-5"/>
        <vers num="6.3.4-6"/>
        <vers num="6.3.4-8"/>
        <vers num="6.3.4-9"/>
        <vers num="6.3.5"/>
        <vers num="6.3.5-10"/>
        <vers num="6.3.5-4"/>
        <vers num="6.3.5-5"/>
        <vers num="6.3.5-6"/>
        <vers num="6.3.5-7"/>
        <vers num="6.3.5-9"/>
        <vers num="6.3.6"/>
        <vers num="6.3.6-1"/>
        <vers num="6.3.6-10"/>
        <vers num="6.3.6-2"/>
        <vers num="6.3.6-3"/>
        <vers num="6.3.6-4"/>
        <vers num="6.3.6-5"/>
        <vers num="6.3.6-6"/>
        <vers num="6.3.6-7"/>
        <vers num="6.3.6-8"/>
        <vers num="6.3.6-9"/>
        <vers num="6.3.7"/>
        <vers num="6.3.7-1"/>
        <vers num="6.3.7-10"/>
        <vers num="6.3.7-2"/>
        <vers num="6.3.7-3"/>
        <vers num="6.3.7-4"/>
        <vers num="6.3.7-5"/>
        <vers num="6.3.7-7"/>
        <vers num="6.3.7-9"/>
        <vers num="6.3.8"/>
        <vers num="6.3.8-1"/>
        <vers num="6.3.8-10"/>
        <vers num="6.3.8-2"/>
        <vers num="6.3.8-3"/>
        <vers num="6.3.8-5"/>
        <vers num="6.3.8-6"/>
        <vers num="6.3.8-7"/>
        <vers num="6.3.8-9"/>
        <vers num="6.3.9"/>
        <vers num="6.3.9-1"/>
        <vers num="6.3.9-10"/>
        <vers num="6.3.9-2"/>
        <vers num="6.3.9-4"/>
        <vers num="6.3.9-5"/>
        <vers num="6.3.9-6"/>
        <vers num="6.3.9-7"/>
        <vers num="6.3.9-8"/>
        <vers num="6.3.9-9"/>
        <vers num="6.4.0"/>
        <vers num="6.4.0-1"/>
        <vers num="6.4.0-10"/>
        <vers num="6.4.0-11"/>
        <vers num="6.4.0-4"/>
        <vers num="6.4.0-5"/>
        <vers num="6.4.0-6"/>
        <vers num="6.4.0-7"/>
        <vers num="6.4.0-8"/>
        <vers num="6.4.1"/>
        <vers num="6.4.1-1"/>
        <vers num="6.4.1-2"/>
        <vers num="6.4.1-3"/>
        <vers num="6.4.1-4"/>
        <vers num="6.4.1-5"/>
        <vers num="6.4.1-6"/>
        <vers num="6.4.1-7"/>
        <vers num="6.4.1-8"/>
        <vers num="6.4.1-9"/>
        <vers num="6.4.2"/>
        <vers num="6.4.2-1"/>
        <vers num="6.4.2-10"/>
        <vers num="6.4.2-2"/>
        <vers num="6.4.2-4"/>
        <vers num="6.4.2-5"/>
        <vers num="6.4.2-6"/>
        <vers num="6.4.2-7"/>
        <vers num="6.4.2-8"/>
        <vers num="6.4.2-9"/>
        <vers num="6.4.3"/>
        <vers num="6.4.3-1"/>
        <vers num="6.4.3-10"/>
        <vers num="6.4.3-2"/>
        <vers num="6.4.3-3"/>
        <vers num="6.4.3-5"/>
        <vers num="6.4.3-6"/>
        <vers num="6.4.3-7"/>
        <vers num="6.4.3-8"/>
        <vers num="6.4.4"/>
        <vers num="6.4.4-1"/>
        <vers num="6.4.4-3"/>
        <vers num="6.4.4-5"/>
        <vers num="6.4.4-7"/>
        <vers num="6.4.4-8"/>
        <vers num="6.4.5"/>
        <vers num="6.4.5-1"/>
        <vers num="6.4.5-2"/>
        <vers num="6.4.5-3"/>
        <vers num="6.4.5-4"/>
        <vers num="6.4.5-6"/>
        <vers num="6.4.5-7"/>
        <vers num="6.4.5-9"/>
        <vers num="6.4.6"/>
        <vers num="6.4.6-1"/>
        <vers num="6.4.6-2"/>
        <vers num="6.4.6-3"/>
        <vers num="6.4.6-4"/>
        <vers num="6.4.6-5"/>
        <vers num="6.4.6-6"/>
        <vers num="6.4.6-8"/>
        <vers num="6.4.6-9"/>
        <vers num="6.4.7-1"/>
        <vers num="6.4.7-10"/>
        <vers num="6.4.7-2"/>
        <vers num="6.4.7-3"/>
        <vers num="6.4.7-4"/>
        <vers num="6.4.7-5"/>
        <vers num="6.4.7-6"/>
        <vers num="6.4.7-7"/>
        <vers num="6.4.7-8"/>
        <vers num="6.4.7-9"/>
        <vers num="6.4.8"/>
        <vers num="6.4.8-1"/>
        <vers num="6.4.8-10"/>
        <vers num="6.4.8-2"/>
        <vers num="6.4.8-3"/>
        <vers num="6.4.8-4"/>
        <vers num="6.4.8-5"/>
        <vers num="6.4.8-6"/>
        <vers num="6.4.8-7"/>
        <vers num="6.4.8-8"/>
        <vers num="6.4.8-9"/>
        <vers num="6.4.9"/>
        <vers num="6.4.9-10"/>
        <vers num="6.4.9-2"/>
        <vers num="6.4.9-3"/>
        <vers num="6.4.9-5"/>
        <vers num="6.4.9-7"/>
        <vers num="6.4.9-8"/>
        <vers num="6.4.9-9"/>
        <vers num="6.5.0"/>
        <vers num="6.5.0-1"/>
        <vers num="6.5.0-10"/>
        <vers num="6.5.0-2"/>
        <vers num="6.5.0-3"/>
        <vers num="6.5.0-4"/>
        <vers num="6.5.0-5"/>
        <vers num="6.5.0-6"/>
        <vers num="6.5.0-7"/>
        <vers num="6.5.0-8"/>
        <vers num="6.5.0-9"/>
        <vers num="6.5.1"/>
        <vers num="6.5.1-1"/>
        <vers num="6.5.1-10"/>
        <vers num="6.5.1-2"/>
        <vers num="6.5.1-3"/>
        <vers num="6.5.1-4"/>
        <vers num="6.5.1-5"/>
        <vers num="6.5.1-6"/>
        <vers num="6.5.1-7"/>
        <vers num="6.5.1-9"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2-1"/>
        <vers num="6.5.2-10"/>
        <vers num="6.5.2-2"/>
        <vers num="6.5.2-3"/>
        <vers num="6.5.2-4"/>
        <vers num="6.5.2-5"/>
        <vers num="6.5.2-6"/>
        <vers num="6.5.2-7"/>
        <vers num="6.5.2-8"/>
        <vers num="6.5.2-9"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3-1"/>
        <vers num="6.5.3-10"/>
        <vers num="6.5.3-3"/>
        <vers num="6.5.3-4"/>
        <vers num="6.5.3-5"/>
        <vers num="6.5.3-6"/>
        <vers num="6.5.3-7"/>
        <vers num="6.5.3-8"/>
        <vers num="6.5.4"/>
        <vers num="6.5.4-1"/>
        <vers num="6.5.4-10"/>
        <vers num="6.5.4-2"/>
        <vers num="6.5.4-3"/>
        <vers num="6.5.4-4"/>
        <vers num="6.5.4-5"/>
        <vers num="6.5.4-6"/>
        <vers num="6.5.4-7"/>
        <vers num="6.5.4-8"/>
        <vers num="6.5.4-9"/>
        <vers num="6.5.5"/>
        <vers num="6.5.5-1"/>
        <vers num="6.5.5-10"/>
        <vers num="6.5.5-2"/>
        <vers num="6.5.5-3"/>
        <vers num="6.5.5-4"/>
        <vers num="6.5.5-5"/>
        <vers num="6.5.5-6"/>
        <vers num="6.5.5-7"/>
        <vers num="6.5.5-8"/>
        <vers num="6.5.5-9"/>
        <vers num="6.5.6"/>
        <vers num="6.5.6-10"/>
        <vers num="6.5.6-2"/>
        <vers num="6.5.6-3"/>
        <vers num="6.5.6-4"/>
        <vers num="6.5.6-5"/>
        <vers num="6.5.6-6"/>
        <vers num="6.5.6-7"/>
        <vers num="6.5.6-8"/>
        <vers num="6.5.6-9"/>
        <vers num="6.5.7"/>
        <vers num="6.5.7-1"/>
        <vers num="6.5.7-2"/>
        <vers num="6.5.7-3"/>
        <vers num="6.5.7-4"/>
        <vers num="6.5.7-5"/>
        <vers num="6.5.7-6"/>
        <vers num="6.5.7-7"/>
        <vers num="6.5.7-8"/>
        <vers num="6.5.7-9"/>
        <vers num="6.5.8"/>
        <vers num="6.5.8-1"/>
        <vers num="6.5.8-2"/>
        <vers num="6.5.8-3"/>
        <vers num="6.5.8-4"/>
        <vers num="6.5.8-5"/>
        <vers num="6.5.8-6"/>
        <vers num="6.5.8-7"/>
        <vers num="6.5.8-8"/>
        <vers num="6.5.8-9"/>
        <vers num="6.5.9"/>
        <vers num="6.5.9-1"/>
        <vers num="6.5.9-10"/>
        <vers num="6.5.9-2"/>
        <vers num="6.5.9-3"/>
        <vers num="6.5.9-4"/>
        <vers num="6.5.9-5"/>
        <vers num="6.5.9-6"/>
        <vers num="6.5.9-7"/>
        <vers num="6.5.9-8"/>
        <vers num="6.6.0"/>
        <vers num="6.6.0-1"/>
        <vers num="6.6.0-10"/>
        <vers num="6.6.0-2"/>
        <vers num="6.6.0-4"/>
        <vers num="6.6.0-5"/>
        <vers num="6.6.0-6"/>
        <vers num="6.6.0-7"/>
        <vers num="6.6.0-8"/>
        <vers num="6.6.0-9"/>
        <vers num="6.6.1"/>
        <vers num="6.6.1-1"/>
        <vers num="6.6.1-10"/>
        <vers num="6.6.1-2"/>
        <vers num="6.6.1-3"/>
        <vers num="6.6.1-4"/>
        <vers num="6.6.1-5"/>
        <vers num="6.6.1-6"/>
        <vers num="6.6.1-7"/>
        <vers num="6.6.1-8"/>
        <vers num="6.6.1-9"/>
        <vers num="6.6.2"/>
        <vers num="6.6.2-1"/>
        <vers num="6.6.2-10"/>
        <vers num="6.6.2-2"/>
        <vers num="6.6.2-3"/>
        <vers num="6.6.2-4"/>
        <vers num="6.6.2-5"/>
        <vers num="6.6.2-6"/>
        <vers num="6.6.2-7"/>
        <vers num="6.6.2-8"/>
        <vers num="6.6.2-9"/>
        <vers num="6.6.3"/>
        <vers num="6.6.3-1"/>
        <vers num="6.6.3-10"/>
        <vers num="6.6.3-2"/>
        <vers num="6.6.3-3"/>
        <vers num="6.6.3-4"/>
        <vers num="6.6.3-5"/>
        <vers num="6.6.3-6"/>
        <vers num="6.6.3-7"/>
        <vers num="6.6.4"/>
        <vers num="6.6.4-1"/>
        <vers num="6.6.4-10"/>
        <vers num="6.6.4-2"/>
        <vers num="6.6.4-4"/>
        <vers num="6.6.4-5"/>
        <vers num="6.6.4-6"/>
        <vers num="6.6.4-7"/>
        <vers num="6.6.4-8"/>
        <vers num="6.6.4-9"/>
        <vers num="6.6.5"/>
        <vers num="6.6.5-1"/>
        <vers num="6.6.5-10"/>
        <vers num="6.6.5-2"/>
        <vers num="6.6.5-3"/>
        <vers num="6.6.5-4"/>
        <vers num="6.6.5-5"/>
        <vers num="6.6.5-6"/>
        <vers num="6.6.5-7"/>
        <vers num="6.6.5-8"/>
        <vers num="6.6.5-9"/>
        <vers num="6.6.6-0"/>
        <vers num="6.6.6-1"/>
        <vers num="6.6.6-10"/>
        <vers num="6.6.6-2"/>
        <vers num="6.6.6-3"/>
        <vers num="6.6.6-4"/>
        <vers num="6.6.6-5"/>
        <vers num="6.6.6-6"/>
        <vers num="6.6.6-7"/>
        <vers num="6.6.6-8"/>
        <vers num="6.6.6-9"/>
        <vers num="6.6.7-0"/>
        <vers num="6.6.7-1"/>
        <vers num="6.6.7-10"/>
        <vers num="6.6.7-2"/>
        <vers num="6.6.7-3"/>
        <vers num="6.6.7-4"/>
        <vers num="6.6.7-5"/>
        <vers num="6.6.7-6"/>
        <vers num="6.6.7-7"/>
        <vers num="6.6.7-8"/>
        <vers num="6.6.7-9"/>
        <vers num="6.6.8-0"/>
        <vers num="6.6.9-0"/>
        <vers num="6.6.9-1"/>
        <vers num="6.6.9-10"/>
        <vers num="6.6.9-2"/>
        <vers num="6.6.9-3"/>
        <vers num="6.6.9-4"/>
        <vers num="6.6.9-5"/>
        <vers num="6.6.9-6"/>
        <vers num="6.6.9-7"/>
        <vers num="6.6.9-8"/>
        <vers num="6.6.9-9"/>
        <vers num="6.7.0-0"/>
        <vers num="6.7.0-1"/>
        <vers num="6.7.0-10"/>
        <vers num="6.7.0-2"/>
        <vers num="6.7.0-3"/>
        <vers num="6.7.0-4"/>
        <vers num="6.7.0-5"/>
        <vers num="6.7.0-6"/>
        <vers num="6.7.0-7"/>
        <vers num="6.7.0-8"/>
        <vers num="6.7.0-9"/>
        <vers num="6.7.1-0"/>
        <vers num="6.7.1-1"/>
        <vers num="6.7.1-10"/>
        <vers num="6.7.1-2"/>
        <vers num="6.7.1-3"/>
        <vers num="6.7.1-4"/>
        <vers num="6.7.1-5"/>
        <vers num="6.7.1-6"/>
        <vers num="6.7.1-7"/>
        <vers num="6.7.1-8"/>
        <vers num="6.7.1-9"/>
        <vers num="6.7.2-0"/>
        <vers num="6.7.2-1"/>
        <vers num="6.7.2-10"/>
        <vers num="6.7.2-2"/>
        <vers num="6.7.2-3"/>
        <vers num="6.7.2-4"/>
        <vers num="6.7.2-5"/>
        <vers num="6.7.2-6"/>
        <vers num="6.7.2-7"/>
        <vers num="6.7.2-8"/>
        <vers num="6.7.2-9"/>
        <vers num="6.7.3-0"/>
        <vers num="6.7.3-1"/>
        <vers num="6.7.3-10"/>
        <vers num="6.7.3-2"/>
        <vers num="6.7.3-3"/>
        <vers num="6.7.3-4"/>
        <vers num="6.7.3-5"/>
        <vers num="6.7.3-6"/>
        <vers num="6.7.3-7"/>
        <vers num="6.7.3-8"/>
        <vers num="6.7.3-9"/>
        <vers num="6.7.4-0"/>
        <vers num="6.7.4-1"/>
        <vers num="6.7.4-10"/>
        <vers num="6.7.4-2"/>
        <vers num="6.7.4-3"/>
        <vers num="6.7.4-4"/>
        <vers num="6.7.4-5"/>
        <vers num="6.7.4-6"/>
        <vers num="6.7.4-7"/>
        <vers num="6.7.4-8"/>
        <vers num="6.7.4-9"/>
        <vers num="6.7.5-0"/>
        <vers num="6.7.5-1"/>
        <vers num="6.7.5-10"/>
        <vers num="6.7.5-2"/>
        <vers num="6.7.5-3"/>
        <vers num="6.7.5-4"/>
        <vers num="6.7.5-5"/>
        <vers num="6.7.5-6"/>
        <vers num="6.7.5-7"/>
        <vers num="6.7.5-8"/>
        <vers num="6.7.5-9"/>
        <vers num="6.7.6-0"/>
        <vers num="6.7.6-1"/>
        <vers prev="1" num="6.7.6-2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0265" published="2012-05-16" name="CVE-2012-0265" modified="2013-01-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted pathname for a file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1027065" source="SECTRACK">1027065</ref>
      <ref url="http://www.securityfocus.com/bid/53578" source="BID">53578</ref>
      <ref url="http://support.apple.com/kb/HT5261" source="CONFIRM" adv="1">http://support.apple.com/kb/HT5261</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2012/May/msg00005.html" source="APPLE" adv="1">APPLE-SA-2012-05-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.2.0"/>
        <vers num="6.3.0"/>
        <vers num="6.4.0"/>
        <vers num="6.5"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers num="7.5.5"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.6.5"/>
        <vers num="7.6.6"/>
        <vers num="7.6.7"/>
        <vers num="7.6.8"/>
        <vers num="7.6.9"/>
        <vers num="7.60.92.0"/>
        <vers num="7.62.14.0"/>
        <vers num="7.64.17.73"/>
        <vers num="7.65.17.80"/>
        <vers num="7.66.71.0"/>
        <vers num="7.67.75.0"/>
        <vers num="7.68.75.0"/>
        <vers num="7.69.80.9"/>
        <vers num="7.7.0"/>
        <vers prev="1" num="7.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0266" published="2012-01-14" name="CVE-2012-0266" modified="2013-04-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitrary code via (1) a long bstrUrl parameter to the StartModule method, (2) a long bstrParams parameter to the Check method, a long bstrUrl parameter to the (3) Download or (4) DownloadModule method during construction of a .ntr pathname, or a long bstrUrl parameter to the (5) Download or (6) DownloadModule method during construction of a URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72293" source="XF">ntr-download-bo(72293)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/72292" source="XF">ntr-check-bo(72292)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/72291" source="XF">ntr-startmodule-bo(72291)</ref>
      <ref url="http://www.exploit-db.com/exploits/21841" source="EXPLOIT-DB">21841</ref>
      <ref url="http://secunia.com/secunia_research/2012-1/" source="MISC" adv="1">http://secunia.com/secunia_research/2012-1/</ref>
      <ref url="http://secunia.com/advisories/45166" source="SECUNIA">45166</ref>
      <ref url="http://osvdb.org/78252" source="OSVDB">78252</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-01/0074.html" source="BUGTRAQ">20120111 Secunia Research: NTR ActiveX Control Four Buffer Overflow Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ntrglobal" name="ntr_activex_control">
        <vers prev="1" num="1.1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0267" published="2012-01-14" name="CVE-2012-0267" modified="2013-04-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter that triggers use of an arbitrary memory address as a function pointer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72295" source="XF">ntr-stopmodule-code-exec(72295)</ref>
      <ref url="http://www.exploit-db.com/exploits/21839" source="EXPLOIT-DB">21839</ref>
      <ref url="http://secunia.com/secunia_research/2012-2/" source="MISC" adv="1">http://secunia.com/secunia_research/2012-2/</ref>
      <ref url="http://secunia.com/advisories/45166" source="SECUNIA">45166</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ntrglobal" name="ntr_activex_control">
        <vers prev="1" num="1.1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0268" published="2012-01-19" name="CVE-2012-0268" modified="2012-01-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitrary code via a crafted JPG image that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/47041" source="SECUNIA" adv="1">47041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers num="0.99.17-1"/>
        <vers num="1.0"/>
        <vers num="1.0.4"/>
        <vers num="1.0.6"/>
        <vers num="10.0.0.1102"/>
        <vers num="10.0.0.1241"/>
        <vers num="10.0.0.1258"/>
        <vers num="10.0.0.1264"/>
        <vers num="10.0.0.1267"/>
        <vers num="10.0.0.1270"/>
        <vers num="10.0.0.331" edition="pre-alpha"/>
        <vers num="10.0.0.525" edition="beta"/>
        <vers num="10.0.0.542" edition="beta"/>
        <vers num="11.0.0.1751"/>
        <vers num="11.0.0.2009"/>
        <vers num="11.0.0.2014"/>
        <vers prev="1" num="11.5.0.152"/>
        <vers num="2.0.1.4"/>
        <vers num="3.0"/>
        <vers num="3.0.1" edition="beta-35554"/>
        <vers num="3.5"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
        <vers num="5.0.1046"/>
        <vers num="5.0.1065"/>
        <vers num="5.0.1232"/>
        <vers num="5.5"/>
        <vers num="5.5.1249"/>
        <vers num="5.6"/>
        <vers num="5.6.0.1347"/>
        <vers num="5.6.0.1351"/>
        <vers num="5.6.0.1355"/>
        <vers num="5.6.0.1356"/>
        <vers num="5.6.0.1358"/>
        <vers num="6.0"/>
        <vers num="6.0.0.1643"/>
        <vers num="6.0.0.1750"/>
        <vers num="6.0.0.1921"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.0.0.426"/>
        <vers num="7.0.0.437"/>
        <vers num="7.0.438"/>
        <vers num="7.5"/>
        <vers num="7.5.0.814"/>
        <vers num="8.0"/>
        <vers num="8.0.0.505"/>
        <vers num="8.0.0.508"/>
        <vers num="8.0.0.701"/>
        <vers num="8.0.0.716"/>
        <vers num="8.0.0.863"/>
        <vers num="8.0.1"/>
        <vers num="8.0_2005.1.1.4"/>
        <vers num="8.1"/>
        <vers num="8.1.0.195"/>
        <vers num="8.1.0.209"/>
        <vers num="8.1.0.239"/>
        <vers num="8.1.0.244"/>
        <vers num="8.1.0.249"/>
        <vers num="8.1.0.401"/>
        <vers num="8.1.0.402"/>
        <vers num="8.1.0.413"/>
        <vers num="8.1.0.416"/>
        <vers num="8.1.0.419"/>
        <vers num="8.1.0.421"/>
        <vers num="9.0.0.1389" edition="beta"/>
        <vers num="9.0.0.1912"/>
        <vers num="9.0.0.2018"/>
        <vers num="9.0.0.2034"/>
        <vers num="9.0.0.2112"/>
        <vers num="9.0.0.2123"/>
        <vers num="9.0.0.2128"/>
        <vers num="9.0.0.2133"/>
        <vers num="9.0.0.2136"/>
        <vers num="9.0.0.2152"/>
        <vers num="9.0.0.2160"/>
        <vers num="9.0.0.2161"/>
        <vers num="9.0.0.2162"/>
        <vers num="9.0.0.797" edition="beta"/>
        <vers num="9.0.0.907" edition="beta"/>
        <vers num="9.0.0.922" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0269" published="2012-04-27" name="CVE-2012-0269" modified="2012-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, oreplug, Shuriken Pro4, Shuriken 2007 through 2010, Shuriken Pro4 Corporate Edition, Shuriken CE/2007 through CE/2009 Corporate Edition, Shuriken 2010 Corporate Edition, Rekishimail Sengokubusho no missho, and Bakumatsushishi no missho allows remote attackers to execute arbitrary code via a crafted image file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.justsystems.com/jp/info/js12001.html" source="CONFIRM" adv="1">http://www.justsystems.com/jp/info/js12001.html</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000035" source="JVNDB">JVNDB-2012-000035</ref>
      <ref url="http://jvn.jp/en/jp/JVN09619876/index.html" source="JVN">JVN#09619876</ref>
    </refs>
    <vuln_soft>
      <prod vendor="justsystems" name="ichitaro">
        <vers num="2006" edition="-"/>
        <vers num="2006" edition="-:government"/>
        <vers num="2007" edition="-"/>
        <vers num="2007" edition="-:government"/>
        <vers num="2008" edition="-"/>
        <vers num="2008" edition="-:government"/>
        <vers num="2009" edition="-"/>
        <vers num="2009" edition="-:government"/>
        <vers num="2010" edition="-"/>
        <vers num="2010" edition="-:government"/>
        <vers num="2011" edition="-"/>
        <vers num="2011" edition="-:sou"/>
      </prod>
      <prod vendor="justsystems" name="ichitaro_portable_with_oreplug">
        <vers num="-"/>
      </prod>
      <prod vendor="justsystems" name="ichitaro_viewer">
        <vers num="-"/>
      </prod>
      <prod vendor="justsystems" name="just_frontier">
        <vers num="-"/>
      </prod>
      <prod vendor="justsystems" name="just_jump">
        <vers num="4"/>
      </prod>
      <prod vendor="justsystems" name="just_school">
        <vers num="-"/>
        <vers num="2009"/>
        <vers num="2010"/>
      </prod>
      <prod vendor="justsystems" name="oreplug">
        <vers num="-"/>
      </prod>
      <prod vendor="justsystems" name="rekishimail_bakumatsushishi_no_missho">
        <vers num="-"/>
      </prod>
      <prod vendor="justsystems" name="rekishimail_sengokubusho_no_missho">
        <vers num="-"/>
      </prod>
      <prod vendor="justsystems" name="shuriken">
        <vers num="2007" edition="-"/>
        <vers num="2007" edition="-:corporate"/>
        <vers num="2008" edition="-"/>
        <vers num="2008" edition="-:corporate"/>
        <vers num="2009" edition="-"/>
        <vers num="2009" edition="-:corporate"/>
        <vers num="2010" edition="-"/>
        <vers num="2010" edition="-:corporate"/>
      </prod>
      <prod vendor="justsystems" name="shuriken_pro">
        <vers num="4" edition="-"/>
        <vers num="4" edition="-:corporate"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0271" published="2012-09-19" name="CVE-2012-0271" modified="2013-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow, as demonstrated by a request with -1 in the Content-Length HTTP header.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.novell.com/support/kb/doc.php?id=7010769

"Previous versions of GroupWise are likely also vulnerable but are no longer supported."</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=746199" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=746199</ref>
      <ref url="http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=61&amp;Itemid=61" source="MISC">http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=61&amp;Itemid=61</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7010769" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7010769</ref>
      <ref url="http://osvdb.org/85426" source="OSVDB">85426</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="2012"/>
        <vers num="5.2"/>
        <vers num="5.5"/>
        <vers num="5.57e"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition="sp1"/>
        <vers num="6.5" edition="sp1"/>
        <vers num="6.5" edition="sp2"/>
        <vers num="6.5" edition="sp3"/>
        <vers num="6.5" edition="sp4"/>
        <vers num="6.5" edition="sp5"/>
        <vers num="6.5" edition="sp6"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="7.0"/>
        <vers num="7.0.3" edition="hp4"/>
        <vers num="7.0.3" edition="hp5"/>
        <vers num="7.0.4" edition="ftf"/>
        <vers num="7.01" edition="ir1"/>
        <vers num="7.02" edition="hp1"/>
        <vers num="7.02" edition="hp1a"/>
        <vers num="7.02" edition="hp2"/>
        <vers num="7.02" edition="hp2r1"/>
        <vers num="7.03" edition="hp"/>
        <vers num="7.03" edition="hp2"/>
        <vers num="7.03" edition="hp3"/>
        <vers num="7.03" edition="hp3+ftf"/>
        <vers num="8.0"/>
        <vers num="8.01" edition="hp"/>
        <vers num="8.02" edition="hp1"/>
        <vers num="8.02" edition="hp2"/>
        <vers num="8.02" edition="hp3"/>
        <vers num="8.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0272" published="2012-09-19" name="CVE-2012-0272" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to inject arbitrary web script or HTML via the merge parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=740563" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=740563</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=702785" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=702785</ref>
      <ref url="http://www.securitytracker.com/id?1027615" source="SECTRACK">1027615</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7010368" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7010368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="8.0"/>
        <vers num="8.00" edition="hp1"/>
        <vers num="8.00" edition="hp2"/>
        <vers num="8.00" edition="hp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0275" published="2012-09-04" name="CVE-2012-0275" modified="2013-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Photoshop.exe in Adobe Photoshop CS5 12.x before 12.0.5, CS5.1 12.1.x before 12.1.1, and CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafted TIFF image with SGI24LogLum compression.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/78185" source="XF">adobe-photoshop-unspec-bo(78185)</ref>
      <ref url="http://www.securitytracker.com/id?1027477" source="SECTRACK">1027477</ref>
      <ref url="http://www.securityfocus.com/bid/55372" source="BID">55372</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb12-20.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/bulletins/apsb12-20.html</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb12-11.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/bulletins/apsb12-11.html</ref>
      <ref url="http://secunia.com/secunia_research/2012-29/" source="MISC" adv="1">http://secunia.com/secunia_research/2012-29/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="photoshop_cs5.5">
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
        <vers num="12.0.4"/>
        <vers num="12.1"/>
      </prod>
      <prod vendor="adobe" name="photoshop_cs6">
        <vers num="13.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0276" published="2012-07-17" name="CVE-2012-0276" modified="2012-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a (1) SGI32LogLum compressed TIFF image or (2) SGI32LogLum compressed TIFF image with the PhotometricInterpretation encoding set to LogL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=49" source="MISC">http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=49</ref>
      <ref url="http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=48" source="MISC">http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=48</ref>
      <ref url="http://www.exploit-db.com/exploits/19338" source="EXPLOIT-DB">19338</ref>
      <ref url="http://www.exploit-db.com/exploits/19337" source="EXPLOIT-DB">19337</ref>
      <ref url="http://secunia.com/advisories/48666" source="SECUNIA" adv="1">48666</ref>
      <ref url="http://newsgroup.xnview.com/viewtopic.php?f=35&amp;t=25858" source="CONFIRM">http://newsgroup.xnview.com/viewtopic.php?f=35&amp;t=25858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xnview" name="xnview">
        <vers prev="1" num="1.98.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0277" published="2012-07-17" name="CVE-2012-0277" modified="2012-08-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PCT image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=50" source="MISC">http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=50</ref>
      <ref url="http://www.exploit-db.com/exploits/19336" source="EXPLOIT-DB">19336</ref>
      <ref url="http://secunia.com/advisories/48666" source="SECUNIA" adv="1">48666</ref>
      <ref url="http://newsgroup.xnview.com/viewtopic.php?f=35&amp;t=25858" source="CONFIRM">http://newsgroup.xnview.com/viewtopic.php?f=35&amp;t=25858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xnview" name="xnview">
        <vers prev="1" num="1.98.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0278" published="2012-04-18" name="CVE-2012-0278" modified="2013-02-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/53009" source="BID">53009</ref>
      <ref url="http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=41&amp;Itemid=41" source="MISC">http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=41&amp;Itemid=41</ref>
      <ref url="http://secunia.com/advisories/48772" source="SECUNIA" adv="1">48772</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irfanview" name="flashpix_plugin">
        <vers num="4.32"/>
        <vers prev="1" num="4.33"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0279" published="2012-05-01" name="CVE-2012-0279" modified="2013-02-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Quest Toad for Data Analysts 3.0.1 uses weak permissions (Everyone: Full Control) for the %COMMONPROGRAMFILES%\Quest Shared directory, which allows local users to gain privileges via a Trojan horse file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/75192" source="XF">quest-toad-insecure-permissions(75192)</ref>
      <ref url="http://www.securityfocus.com/bid/53276" source="BID">53276</ref>
      <ref url="http://secunia.com/secunia_research/2012-13/" source="MISC" adv="1">http://secunia.com/secunia_research/2012-13/</ref>
      <ref url="http://secunia.com/advisories/48663" source="SECUNIA">48663</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quest" name="toad_for_data_analysts">
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0282" published="2012-07-17" name="CVE-2012-0282" modified="2012-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ImageLeftPosition value in an ImageDescriptor structure in a GIF image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=51" source="MISC">http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=51</ref>
      <ref url="http://www.osvdb.org/83086" source="OSVDB">83086</ref>
      <ref url="http://www.exploit-db.com/exploits/19335" source="EXPLOIT-DB">19335</ref>
      <ref url="http://secunia.com/advisories/48666" source="SECUNIA" adv="1">48666</ref>
      <ref url="http://newsgroup.xnview.com/viewtopic.php?f=35&amp;t=25858" source="CONFIRM">http://newsgroup.xnview.com/viewtopic.php?f=35&amp;t=25858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xnview" name="xnview">
        <vers prev="1" num="1.98.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0283" published="2012-07-13" name="CVE-2012-0283" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/54439" source="BID">54439</ref>
      <ref url="http://secunia.com/secunia_research/2012-24/" source="MISC" adv="1">http://secunia.com/secunia_research/2012-24/</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-October/090938.html" source="FEDORA">FEDORA-2012-16605</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-October/090899.html" source="FEDORA">FEDORA-2012-16614</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2012-October/090755.html" source="FEDORA">FEDORA-2012-16550</ref>
      <ref url="http://bugs.dokuwiki.org/index.php?do=details&amp;task_id=2561" source="CONFIRM" adv="1">http://bugs.dokuwiki.org/index.php?do=details&amp;task_id=2561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andreas_gohr" name="dokuwiki">
        <vers num="2005-07-01"/>
        <vers num="2005-09-19"/>
        <vers num="2005-09-22"/>
        <vers num="2006-03-05"/>
        <vers num="2006-03-09"/>
        <vers num="2006-11-06"/>
        <vers num="2007-06-26"/>
        <vers num="2007-07-13"/>
        <vers num="2008-05-05"/>
        <vers num="2009-02-14b"/>
        <vers num="2009-12-25c"/>
        <vers num="2010-11-07a"/>
        <vers num="2011-05-25"/>
        <vers num="2011-05-25a"/>
        <vers num="2011-05-25c"/>
        <vers num="2012-01-25"/>
        <vers prev="1" num="2012-01-25a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0284" published="2012-07-19" name="CVE-2012-0284" modified="2012-07-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireless-G PTZ Internet video camera allows remote attackers to execute arbitrary code via a long URL in the first argument (aka the sURL argument).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2012-25/" source="MISC" adv="1">http://secunia.com/secunia_research/2012-25/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="linksys_playerpt_activex_control">
        <vers num="1.0.0.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0285" published="2012-01-24" name="CVE-2012-0285" modified="2012-01-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork before 6.0.8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.stone-ware.com/swql.jsp?kb=d1960" source="CONFIRM" adv="1">http://www.stone-ware.com/swql.jsp?kb=d1960</ref>
      <ref url="http://www.stone-ware.com/support/techdocs/kb/d1960/sb_6_0_8.pdf" source="CONFIRM" adv="1">http://www.stone-ware.com/support/techdocs/kb/d1960/sb_6_0_8.pdf</ref>
      <ref url="http://infosec42.blogspot.com/2012/01/cve-2012-0285-and-cve-2012-0286.html" source="MISC">http://infosec42.blogspot.com/2012/01/cve-2012-0285-and-cve-2012-0286.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stone-ware" name="webnetwork">
        <vers num="6.0.5.0"/>
        <vers prev="1" num="6.0.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0286" published="2012-01-24" name="CVE-2012-0286" modified="2012-01-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack the authentication of unspecified victims for requests that modify user accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.stone-ware.com/swql.jsp?kb=d1960" source="CONFIRM" adv="1">http://www.stone-ware.com/swql.jsp?kb=d1960</ref>
      <ref url="http://www.stone-ware.com/support/techdocs/kb/d1960/sb_6_0_8.pdf" source="CONFIRM" adv="1">http://www.stone-ware.com/support/techdocs/kb/d1960/sb_6_0_8.pdf</ref>
      <ref url="http://infosec42.blogspot.com/2012/01/cve-2012-0285-and-cve-2012-0286.html" source="MISC">http://infosec42.blogspot.com/2012/01/cve-2012-0285-and-cve-2012-0286.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stone-ware" name="webnetwork">
        <vers num="6.0.5.0"/>
        <vers prev="1" num="6.0.7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0287" published="2012-01-05" name="CVE-2012-0287" modified="2012-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://wordpress.org/news/2012/01/wordpress-3-3-1/" source="CONFIRM" patch="1" adv="1">https://wordpress.org/news/2012/01/wordpress-3-3-1/</ref>
      <ref url="http://www.securitytracker.com/id?1026542" source="SECTRACK">1026542</ref>
      <ref url="http://www.securityfocus.com/bid/51237" source="BID">51237</ref>
      <ref url="http://oldmanlab.blogspot.com/2012/01/wordpress-33-xss-vulnerability.html" source="MISC">http://oldmanlab.blogspot.com/2012/01/wordpress-33-xss-vulnerability.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0289" published="2012-05-23" name="CVE-2012-0289" modified="2012-10-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.710x allows local users to gain privileges, and modify data or cause a denial of service, via a crafted script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120522_01" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120522_01</ref>
      <ref url="http://www.securitytracker.com/id?1027093" source="SECTRACK">1027093</ref>
      <ref url="http://www.securityfocus.com/bid/51795" source="BID">51795</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="endpoint_protection">
        <vers num="11.0.6000"/>
        <vers num="11.0.6100"/>
        <vers num="11.0.6200"/>
        <vers num="11.0.6200.754"/>
        <vers num="11.0.6300"/>
        <vers num="11.0.7000"/>
        <vers num="11.0.7100"/>
      </prod>
      <prod vendor="symantec" name="network_access_control">
        <vers num="11.0.6000"/>
        <vers num="11.0.6100"/>
        <vers num="11.0.6200"/>
        <vers num="11.0.6300"/>
        <vers num="11.0.7000"/>
        <vers num="11.0.7100"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0290" published="2012-02-06" name="CVE-2012-0290" modified="2012-02-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) do not properly handle the client state after abnormal termination of a remote session, which allows remote attackers to obtain access to the client by leveraging an "open client session."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72996" source="XF">pcanywhere-unauth-access(72996)</ref>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120124_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120124_00</ref>
      <ref url="http://www.securityfocus.com/bid/51862" source="BID">51862</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="altiris_client_management_suite_pcanywhere_solution">
        <vers num="12.5" edition="sp1"/>
        <vers num="12.5" edition="sp2"/>
        <vers num="12.6" edition="sp1"/>
        <vers num="12.6" edition="sp2"/>
      </prod>
      <prod vendor="symantec" name="altiris_deployment_solution_remote_pcanywhere_solution">
        <vers num="12.5" edition="sp1"/>
        <vers num="12.5" edition="sp2"/>
        <vers num="12.6" edition="sp1"/>
        <vers num="12.6" edition="sp2"/>
      </prod>
      <prod vendor="symantec" name="pcanywhere">
        <vers num="10.5"/>
        <vers num="11.5"/>
        <vers num="11.5.1"/>
        <vers num="12.1"/>
        <vers num="12.5" edition="sp1"/>
        <vers num="12.5" edition="sp2"/>
        <vers num="12.5" edition="sp3"/>
        <vers num="12.5.265"/>
        <vers prev="1" num="12.5.3"/>
        <vers num="12.5.539"/>
        <vers num="12.6.65"/>
        <vers num="12.6.7580"/>
        <vers num="5.0"/>
        <vers num="8.0"/>
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0291" published="2012-02-22" name="CVE-2012-0291" modified="2012-02-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allow remote attackers to cause a denial of service (application crash or hang) via (1) malformed data from a client, (2) malformed data from a server, or (3) an invalid response.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120124_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120124_00</ref>
      <ref url="http://www.securityfocus.com/bid/51965" source="BID">51965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="altiris_client_management_suite_pcanywhere_solution">
        <vers num="7.0"/>
      </prod>
      <prod vendor="symantec" name="altiris_deployment_solution_remote_pcanywhere_solution">
        <vers num="7.1"/>
      </prod>
      <prod vendor="symantec" name="altiris_it_management_suite_pcanywhere_solution">
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
      <prod vendor="symantec" name="pcanywhere">
        <vers num="10.0"/>
        <vers num="10.5"/>
        <vers num="11.0"/>
        <vers num="11.0.1"/>
        <vers num="11.5"/>
        <vers num="11.5.1"/>
        <vers num="12.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
        <vers num="12.1"/>
        <vers prev="1" num="12.5" edition="sp1"/>
        <vers prev="1" num="12.5" edition="sp2"/>
        <vers prev="1" num="12.5" edition="sp3"/>
        <vers num="12.5.265"/>
        <vers num="12.5.3"/>
        <vers num="12.5.539"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0292" published="2012-03-07" name="CVE-2012-0292" modified="2012-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allows remote attackers to cause a denial of service (daemon crash) via a crafted TCP session on port 5631.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120301_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120301_00</ref>
      <ref url="http://www.securityfocus.com/bid/52094" source="BID">52094</ref>
      <ref url="http://www.exploit-db.com/exploits/18493/" source="EXPLOIT-DB">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="altiris_client_management_suite_pcanywhere_solution">
        <vers num="7.0"/>
      </prod>
      <prod vendor="symantec" name="altiris_climentent_manage_suite_pcanywhere_solution">
        <vers num="7.1"/>
      </prod>
      <prod vendor="symantec" name="altiris_deployment_solution_remote_pcanywhere_solution">
        <vers num="7.1"/>
      </prod>
      <prod vendor="symantec" name="altiris_it_management_suite_pcanywhere_solution">
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
      <prod vendor="symantec" name="pcanywhere">
        <vers num="10.0"/>
        <vers num="10.5"/>
        <vers num="11.0"/>
        <vers num="11.0.1"/>
        <vers num="11.5"/>
        <vers num="11.5.1"/>
        <vers num="12.0"/>
        <vers num="12.0.1"/>
        <vers num="12.0.2"/>
        <vers num="12.0.3"/>
        <vers num="12.1"/>
        <vers prev="1" num="12.5" edition="sp1"/>
        <vers prev="1" num="12.5" edition="sp2"/>
        <vers prev="1" num="12.5" edition="sp3"/>
        <vers num="12.5.265"/>
        <vers num="12.5.3"/>
        <vers num="12.5.539"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0293" published="2012-03-17" name="CVE-2012-0293" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Symantec Altiris WISE Package Studio before 8.0MR1 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120314_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120314_00</ref>
      <ref url="http://www.securityfocus.com/bid/52392" source="BID">52392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="altiris_wise_package_studio">
        <vers num="7" edition="sp2"/>
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp1:mr1"/>
        <vers num="7.0" edition="sp3"/>
        <vers prev="1" num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0294" published="2012-05-23" name="CVE-2012-0294" modified="2012-10-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to delete files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120522_01" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120522_01</ref>
      <ref url="http://www.securitytracker.com/id?1027093" source="SECTRACK">1027093</ref>
      <ref url="http://www.securityfocus.com/bid/53182" source="BID">53182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="endpoint_protection">
        <vers num="12.1"/>
        <vers num="12.1.1000"/>
        <vers num="12.1.671"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0295" published="2012-05-23" name="CVE-2012-0295" modified="2013-01-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120522_01" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120522_01</ref>
      <ref url="http://www.securitytracker.com/id?1027093" source="SECTRACK">1027093</ref>
      <ref url="http://www.securityfocus.com/bid/53184" source="BID">53184</ref>
      <ref url="http://www.securityfocus.com/bid/53183" source="BID">53183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="endpoint_protection">
        <vers num="12.1"/>
        <vers num="12.1.1000"/>
        <vers num="12.1.671"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0296" published="2012-05-21" name="CVE-2012-0296" modified="2012-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120517_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120517_00</ref>
      <ref url="http://www.securityfocus.com/bid/53396" source="BID">53396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="web_gateway">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0297" published="2012-05-21" name="CVE-2012-0297" modified="2012-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120517_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120517_00</ref>
      <ref url="http://www.securityfocus.com/bid/53444" source="BID">53444</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="web_gateway">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0298" published="2012-05-21" name="CVE-2012-0298" modified="2012-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120517_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120517_00</ref>
      <ref url="http://www.securityfocus.com/bid/53442" source="BID">53442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="web_gateway">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0299" published="2012-05-21" name="CVE-2012-0299" modified="2012-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a designated pathname, and possibly execute this code, via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120517_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120517_00</ref>
      <ref url="http://www.securityfocus.com/bid/53443" source="BID">53443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="web_gateway">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0300" published="2012-07-05" name="CVE-2012-0300" modified="2012-07-17" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Brightmail Control Center in Symantec Message Filter 6.3 does not properly restrict establishment of sessions to the listening port, which allows remote attackers to obtain potentially sensitive version information via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120626_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120626_00</ref>
      <ref url="http://www.securityfocus.com/bid/54136" source="BID">54136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="message_filter">
        <vers prev="1" num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0301" published="2012-07-05" name="CVE-2012-0301" modified="2012-07-06" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="5.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="5.5" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">Session fixation vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to hijack web sessions via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120626_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120626_00</ref>
      <ref url="http://www.securityfocus.com/bid/54135" source="BID">54135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="message_filter">
        <vers prev="1" num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0302" published="2012-07-05" name="CVE-2012-0302" modified="2012-07-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120626_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120626_00</ref>
      <ref url="http://www.securityfocus.com/bid/54134" source="BID">54134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="message_filter">
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0303" published="2012-07-05" name="CVE-2012-0303" modified="2012-07-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in Brightmail Control Center in Symantec Message Filter 6.3 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) execute application commands or (2) create admin accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120626_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120626_00</ref>
      <ref url="http://www.securityfocus.com/bid/54133" source="BID">54133</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="message_filter">
        <vers prev="1" num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0304" published="2012-06-22" name="CVE-2012-0304" modified="2013-04-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local users to gain privileges via a Trojan horse file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120615_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120615_00</ref>
      <ref url="http://www.securitytracker.com/id?1027182" source="SECTRACK">1027182</ref>
      <ref url="http://www.securityfocus.com/bid/53903" source="BID">53903</ref>
      <ref url="http://www.nessus.org/plugins/index.php?view=single&amp;id=59193" source="MISC">http://www.nessus.org/plugins/index.php?view=single&amp;id=59193</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="liveupdate_administrator">
        <vers num="1.5.3.21"/>
        <vers num="1.5.4"/>
        <vers num="1.5.7.19"/>
        <vers num="2.1.0"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.2.9"/>
        <vers prev="1" num="2.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0305" published="2012-07-23" name="CVE-2012-0305" modified="2013-02-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Symantec System Recovery 2011 before SP2 and Backup Exec System Recovery 2010 before SP5 allows local users to gain privileges via a Trojan horse DLL in the current working directory.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html 'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120720_01" source="CONFIRM">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120720_01</ref>
      <ref url="http://www.securityfocus.com/bid/54594" source="BID">54594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="backupexec_system_recovery">
        <vers num="2010"/>
        <vers num="2011"/>
      </prod>
      <prod vendor="symantec" name="system_recovery">
        <vers num="2011"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0306" published="2012-10-18" name="CVE-2012-0306" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Symantec Ghost Solution Suite 2.x through 2.5.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted backup file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20121010_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20121010_00</ref>
      <ref url="http://www.securitytracker.com/id?1027648" source="SECTRACK">1027648</ref>
      <ref url="http://www.securityfocus.com/bid/55748" source="BID">55748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="ghost_solutions_suite">
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0307" published="2012-08-29" name="CVE-2012-0307" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Symantec Messaging Gateway (SMG) before 10.0 allow remote attackers to inject arbitrary web script or HTML via (1) web content or (2) e-mail content.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/78031" source="XF">symantec-gateway-unspec-xss(78031)</ref>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120827_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120827_00</ref>
      <ref url="http://www.securityfocus.com/bid/55138" source="BID">55138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="messaging_gateway">
        <vers num="9.5"/>
        <vers num="9.5.1"/>
        <vers num="9.5.2"/>
        <vers num="9.5.3"/>
        <vers prev="1" num="9.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0308" published="2012-08-29" name="CVE-2012-0308" modified="2012-12-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers to hijack the authentication of administrators.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120827_00" source="CONFIRM" adv="1">http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2012&amp;suid=20120827_00</ref>
      <ref url="http://www.securityfocus.com/bid/55137" source="BID">55137</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="messaging_gateway">
        <vers num="10.0"/>
        <vers num="9.5"/>
        <vers num="9.5.1"/>
        <vers num="9.5.2"/>
        <vers num="9.5.3"/>
        <vers prev="1" num="9.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0309" published="2012-01-12" name="CVE-2012-0309" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Cogent DataHub 7.1.2 and earlier, Cascade DataHub 6.4.20 and earlier, and OPC DataHub 6.4.20 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72305" source="XF">cogentdatahub-unspecified-xss(72305)</ref>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-016-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-016-01.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/51375" source="BID">51375</ref>
      <ref url="http://www.cogentdatahub.com/ReleaseNotes.html" source="CONFIRM">http://www.cogentdatahub.com/ReleaseNotes.html</ref>
      <ref url="http://secunia.com/advisories/47525" source="SECUNIA">47525</ref>
      <ref url="http://secunia.com/advisories/47496" source="SECUNIA">47496</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000001" source="JVNDB">JVNDB-2012-000001</ref>
      <ref url="http://jvn.jp/en/jp/JVN12983784/index.html" source="JVN">JVN#12983784</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cogentdatahub" name="cascade_datahub">
        <vers prev="1" num="6.4.20"/>
      </prod>
      <prod vendor="cogentdatahub" name="cogent_datahub">
        <vers num="7.0"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.1.63"/>
        <vers prev="1" num="7.1.2"/>
      </prod>
      <prod vendor="cogentdatahub" name="opc_datahub">
        <vers prev="1" num="6.4.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0310" published="2012-01-12" name="CVE-2012-0310" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">CRLF injection vulnerability in Cogent DataHub 7.1.2 and earlier, Cascade DataHub 6.4.20 and earlier, and OPC DataHub 6.4.20 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72306" source="XF">cogentdatahub-unspecified-header-injection(72306)</ref>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-016-01.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-016-01.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/51375" source="BID">51375</ref>
      <ref url="http://www.cogentdatahub.com/ReleaseNotes.html" source="CONFIRM">http://www.cogentdatahub.com/ReleaseNotes.html</ref>
      <ref url="http://secunia.com/advisories/47525" source="SECUNIA">47525</ref>
      <ref url="http://secunia.com/advisories/47496" source="SECUNIA">47496</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000002" source="JVNDB">JVNDB-2012-000002</ref>
      <ref url="http://jvn.jp/en/jp/JVN63249231/index.html" source="JVN">JVN#63249231</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cogentdatahub" name="cascade_datahub">
        <vers prev="1" num="6.4.20"/>
      </prod>
      <prod vendor="cogentdatahub" name="cogent_datahub">
        <vers num="7.0"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.1.63"/>
        <vers prev="1" num="7.1.2"/>
      </prod>
      <prod vendor="cogentdatahub" name="opc_datahub">
        <vers prev="1" num="6.4.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0311" published="2012-01-26" name="CVE-2012-0311" modified="2012-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://sourceforge.jp/forum/forum.php?forum_id=28119" source="CONFIRM">http://sourceforge.jp/forum/forum.php?forum_id=28119</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000004" source="JVNDB">JVNDB-2012-000004</ref>
      <ref url="http://jvn.jp/en/jp/JVN36559450/index.html" source="JVN">JVN#36559450</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oscommerce" name="oscommerce">
        <vers num="2.2ms1j-r1"/>
        <vers num="2.2ms1j-r2"/>
        <vers num="2.2ms1j-r3"/>
        <vers num="2.2ms1j-r4"/>
        <vers num="2.2ms1j-r5"/>
        <vers num="2.2ms1j-r6a"/>
        <vers num="2.2ms1j-r7"/>
        <vers num="2.2ms1j-r8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0312" published="2012-01-26" name="CVE-2012-0312" modified="2012-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in osCommerce 2.2MS1J before R9, and osCommerce Online Merchant before 2.3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://sourceforge.jp/forum/forum.php?forum_id=28119" source="CONFIRM">http://sourceforge.jp/forum/forum.php?forum_id=28119</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000005" source="JVNDB">JVNDB-2012-000005</ref>
      <ref url="http://jvn.jp/en/jp/JVN64386898/index.html" source="JVN">JVN#64386898</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oscommerce" name="online_merchant">
        <vers num="2.2"/>
        <vers prev="1" num="2.3.0"/>
      </prod>
      <prod vendor="oscommerce" name="oscommerce">
        <vers num="2.2ms1j-r1"/>
        <vers num="2.2ms1j-r2"/>
        <vers num="2.2ms1j-r3"/>
        <vers num="2.2ms1j-r4"/>
        <vers num="2.2ms1j-r5"/>
        <vers num="2.2ms1j-r6a"/>
        <vers num="2.2ms1j-r7"/>
        <vers num="2.2ms1j-r8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0313" published="2012-01-23" name="CVE-2012-0313" modified="2012-01-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in glucose 2 before stage 6.2 allows remote attackers to inject arbitrary web script or HTML via an RSS feed.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000008" source="JVNDB">JVNDB-2012-000008</ref>
      <ref url="http://jvn.jp/en/jp/JVN65869891/index.html" source="JVN">JVN#65869891</ref>
      <ref url="http://glucose.jp/release/19" source="MISC" adv="1">http://glucose.jp/release/19</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glucose" name="glucose_2">
        <vers num="beta_stage_5"/>
        <vers num="beta_stage_5.1"/>
        <vers num="stage6"/>
        <vers prev="1" num="stage6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0314" published="2012-02-02" name="CVE-2012-0314" modified="2012-02-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities on the eAccess Pocket WiFi (aka GP02) router before 2.00 with firmware 11.203.11.05.168 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/51782" source="BID">51782</ref>
      <ref url="http://secunia.com/advisories/47795" source="SECUNIA">47795</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000010" source="JVNDB">JVNDB-2012-000010</ref>
      <ref url="http://jvn.jp/en/jp/JVN33021167/index.html" source="JVN">JVN#33021167</ref>
      <ref url="http://emobile.jp/topics/info20120201_01.html" source="CONFIRM">http://emobile.jp/topics/info20120201_01.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emobile" name="pocket_wifi_firmware">
        <vers prev="1" num="11.203.11.05.168"/>
      </prod>
      <prod vendor="emobile" name="pocket_wifi">
        <vers prev="1" num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0315" published="2012-02-22" nvd_name="CWE-426: Untrusted Search Path" name="CVE-2012-0315" modified="2012-02-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.altools.jp/download.aspx" source="MISC" patch="1">http://www.altools.jp/download.aspx</ref>
      <ref url="http://www.altools.jp/ETC/NEWS.aspx?mid=231&amp;vidx=118" source="MISC" adv="1">http://www.altools.jp/ETC/NEWS.aspx?mid=231&amp;vidx=118</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000011" source="JVNDB">JVNDB-2012-000011</ref>
      <ref url="http://jvn.jp/en/jp/JVN85695061/index.html" source="JVN">JVN#85695061</ref>
      <ref url="http://jvn.jp/en/jp/JVN85695061/995223/index.html" source="MISC">http://jvn.jp/en/jp/JVN85695061/995223/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="estsoft" name="alftp">
        <vers num="4.1" edition="beta2"/>
        <vers num="4.1" edition="beta2:"/>
        <vers num="4.1" edition="beta2::english"/>
        <vers num="5.0"/>
        <vers prev="1" num="5.1" edition="beta2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0316" published="2012-03-01" name="CVE-2012-0316" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Cookpad 1.5.16 and earlier and Cookpad Noseru 1.1.1 and earlier applications for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/52189" source="BID">52189</ref>
      <ref url="http://osvdb.org/79643" source="OSVDB">79643</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000014" source="JVNDB">JVNDB-2012-000014</ref>
      <ref url="http://jvn.jp/en/jp/JVN25731073/index.html" source="JVN">JVN#25731073</ref>
      <ref url="http://cookpad.typepad.jp/help/2012/02/23oshirase.html" source="CONFIRM" adv="1">http://cookpad.typepad.jp/help/2012/02/23oshirase.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cookpad" name="android_activities">
        <vers prev="1" num="1.5.16"/>
      </prod>
      <prod vendor="cookpad" name="android_mykitchen">
        <vers prev="1" num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0317" published="2012-03-02" name="CVE-2012-0317" modified="2012-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to hijack the authentication of arbitrary users for requests that modify data via the (1) commenting feature or (2) community script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.movabletype.org/documentation/appendices/release-notes/513.html" source="CONFIRM" patch="1" adv="1">http://www.movabletype.org/documentation/appendices/release-notes/513.html</ref>
      <ref url="http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html" source="CONFIRM" patch="1" adv="1">http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html</ref>
      <ref url="http://www.securitytracker.com/id?1026738" source="SECTRACK">1026738</ref>
      <ref url="http://www.securityfocus.com/bid/52138" source="BID">52138</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000015" source="JVNDB">JVNDB-2012-000015</ref>
      <ref url="http://jvn.jp/en/jp/JVN70683217/index.html" source="JVN">JVN#70683217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sixapart" name="movable_type">
        <vers num="4.0" edition="beta"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="rc1"/>
        <vers num="4.0" edition="rc2"/>
        <vers num="4.0" edition="rc3"/>
        <vers num="4.1" edition="beta"/>
        <vers num="4.1" edition="beta2"/>
        <vers num="4.1" edition="rc1"/>
        <vers num="4.12"/>
        <vers num="4.15" edition="beta1"/>
        <vers num="4.15" edition="beta3"/>
        <vers num="4.15" edition="beta4"/>
        <vers num="4.2" edition="rc2"/>
        <vers num="4.2" edition="rc4"/>
        <vers num="4.2" edition="rc5"/>
        <vers num="4.22"/>
        <vers num="4.23"/>
        <vers num="4.24"/>
        <vers num="4.25"/>
        <vers num="4.26"/>
        <vers num="4.261"/>
        <vers num="4.27"/>
        <vers num="4.28" edition=""/>
        <vers num="4.28" edition=":open_source"/>
        <vers num="4.28" edition=":enterprise"/>
        <vers num="4.29" edition=""/>
        <vers num="4.29" edition=":open_source"/>
        <vers num="4.29" edition=":enterprise"/>
        <vers num="4.291" edition=""/>
        <vers num="4.291" edition=":open_source"/>
        <vers num="4.291" edition=":enterprise"/>
        <vers prev="1" num="4.292" edition=""/>
        <vers prev="1" num="4.292" edition=":enterprise"/>
        <vers prev="1" num="4.292" edition=":open_source"/>
        <vers num="4.35"/>
        <vers num="4.36" edition=""/>
        <vers num="4.36" edition=":open_source"/>
        <vers num="4.361" edition=""/>
        <vers num="4.361" edition=":open_source"/>
        <vers prev="1" num="4.37" edition=""/>
        <vers prev="1" num="4.37" edition=":open_source"/>
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":open_source"/>
        <vers num="5.0" edition="beta1"/>
        <vers num="5.0" edition="beta2"/>
        <vers num="5.0" edition="beta3"/>
        <vers num="5.0" edition="beta4"/>
        <vers num="5.0" edition="rc1"/>
        <vers num="5.0" edition="rc2"/>
        <vers num="5.0" edition="rc3"/>
        <vers num="5.01" edition=""/>
        <vers num="5.01" edition=":open_source"/>
        <vers num="5.02" edition=""/>
        <vers num="5.02" edition=":open_source"/>
        <vers num="5.02" edition=":advanced"/>
        <vers num="5.03"/>
        <vers num="5.031"/>
        <vers num="5.04" edition=""/>
        <vers num="5.04" edition=":advanced"/>
        <vers num="5.04" edition=":open_source"/>
        <vers num="5.05" edition=""/>
        <vers num="5.05" edition=":advanced"/>
        <vers num="5.05" edition=":open_source"/>
        <vers num="5.051" edition=""/>
        <vers num="5.051" edition=":advanced"/>
        <vers num="5.051" edition=":open_source"/>
        <vers num="5.06" edition=""/>
        <vers num="5.06" edition=":open_source"/>
        <vers num="5.06" edition=":advanced"/>
        <vers num="5.07"/>
        <vers num="5.1" edition=""/>
        <vers num="5.1" edition=":advanced"/>
        <vers num="5.1" edition=":open_source"/>
        <vers num="5.1" edition="beta"/>
        <vers num="5.1" edition="rc1"/>
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":advanced"/>
        <vers num="5.11" edition=":open_source"/>
        <vers num="5.12" edition=""/>
        <vers num="5.12" edition=":open_source"/>
        <vers num="5.12" edition=":advanced"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0318" published="2012-03-02" name="CVE-2012-0318" modified="2012-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to inject arbitrary web script or HTML via vectors involving templates, a different issue than CVE-2012-1262.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.movabletype.org/documentation/appendices/release-notes/513.html" source="CONFIRM" patch="1" adv="1">http://www.movabletype.org/documentation/appendices/release-notes/513.html</ref>
      <ref url="http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html" source="CONFIRM" patch="1" adv="1">http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html</ref>
      <ref url="http://www.securitytracker.com/id?1026738" source="SECTRACK">1026738</ref>
      <ref url="http://www.securityfocus.com/bid/52138" source="BID">52138</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000016" source="JVNDB">JVNDB-2012-000016</ref>
      <ref url="http://jvn.jp/en/jp/JVN49836527/index.html" source="JVN">JVN#49836527</ref>
    </refs>
    <vuln_soft>
      <prod vendor="movabletype" name="movable_type_advanced">
        <vers num="4.0" edition="beta"/>
        <vers num="4.01" edition="beta"/>
        <vers num="4.1" edition="beta"/>
        <vers num="4.2" edition="beta"/>
        <vers num="4.23"/>
        <vers num="4.25"/>
        <vers num="4.26"/>
        <vers num="4.261"/>
        <vers num="4.3"/>
        <vers num="4.31"/>
        <vers num="4.32"/>
        <vers num="4.33"/>
        <vers num="4.34"/>
        <vers num="4.35"/>
        <vers num="4.36"/>
        <vers num="4.361"/>
        <vers prev="1" num="4.37"/>
        <vers num="5.02"/>
        <vers num="5.03"/>
        <vers num="5.031"/>
        <vers num="5.04"/>
        <vers num="5.05"/>
        <vers num="5.051"/>
        <vers num="5.06"/>
        <vers num="5.1"/>
        <vers num="5.11"/>
        <vers num="5.12"/>
      </prod>
      <prod vendor="movabletype" name="movable_type_enterprise">
        <vers num="4.0" edition="beta"/>
        <vers num="4.01" edition="beta"/>
        <vers num="4.1" edition="beta"/>
        <vers num="4.2" edition="beta"/>
        <vers num="4.23"/>
        <vers num="4.25"/>
        <vers num="4.26"/>
        <vers num="4.261"/>
        <vers num="4.3"/>
        <vers num="4.31"/>
        <vers num="4.32"/>
        <vers num="4.33"/>
        <vers num="4.34"/>
        <vers num="4.35"/>
        <vers num="4.36"/>
        <vers num="4.361"/>
        <vers prev="1" num="4.37"/>
        <vers num="5.02"/>
        <vers num="5.03"/>
        <vers num="5.031"/>
        <vers num="5.04"/>
        <vers num="5.05"/>
        <vers num="5.051"/>
        <vers num="5.06"/>
        <vers num="5.1"/>
        <vers num="5.11"/>
        <vers num="5.12"/>
      </prod>
      <prod vendor="movabletype" name="movable_type_open_source">
        <vers num="4.0" edition="beta"/>
        <vers num="4.01" edition="beta"/>
        <vers num="4.1" edition="beta"/>
        <vers num="4.2" edition="beta"/>
        <vers num="4.23"/>
        <vers num="4.25"/>
        <vers num="4.26"/>
        <vers num="4.261"/>
        <vers num="4.3"/>
        <vers num="4.31"/>
        <vers num="4.32"/>
        <vers num="4.33"/>
        <vers num="4.34"/>
        <vers num="4.35"/>
        <vers num="4.36"/>
        <vers num="4.361"/>
        <vers prev="1" num="4.37"/>
        <vers num="5.02"/>
        <vers num="5.03"/>
        <vers num="5.031"/>
        <vers num="5.04"/>
        <vers num="5.05"/>
        <vers num="5.051"/>
        <vers num="5.06"/>
        <vers num="5.1"/>
        <vers num="5.11"/>
        <vers num="5.12"/>
      </prod>
      <prod vendor="movabletype" name="movable_type_pro">
        <vers num="4.0" edition="beta"/>
        <vers num="4.01" edition="beta"/>
        <vers num="4.1" edition="beta"/>
        <vers num="4.2" edition="beta"/>
        <vers num="4.23"/>
        <vers num="4.25"/>
        <vers num="4.26"/>
        <vers num="4.261"/>
        <vers num="4.3"/>
        <vers num="4.31"/>
        <vers num="4.32"/>
        <vers num="4.33"/>
        <vers num="4.34"/>
        <vers num="4.35"/>
        <vers num="4.36"/>
        <vers num="4.361"/>
        <vers prev="1" num="4.37"/>
        <vers num="5.02"/>
        <vers num="5.03"/>
        <vers num="5.031"/>
        <vers num="5.04"/>
        <vers num="5.05"/>
        <vers num="5.051"/>
        <vers num="5.06"/>
        <vers num="5.1"/>
        <vers num="5.11"/>
        <vers num="5.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0319" published="2012-03-02" name="CVE-2012-0319" modified="2012-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The file-management system in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote authenticated users to execute arbitrary commands by leveraging the file-upload feature, related to an "OS Command Injection" issue.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.movabletype.org/documentation/appendices/release-notes/513.html" source="CONFIRM" patch="1" adv="1">http://www.movabletype.org/documentation/appendices/release-notes/513.html</ref>
      <ref url="http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html" source="CONFIRM" patch="1" adv="1">http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html</ref>
      <ref url="http://www.securitytracker.com/id?1026738" source="SECTRACK">1026738</ref>
      <ref url="http://www.securityfocus.com/bid/52138" source="BID">52138</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000017" source="JVNDB">JVNDB-2012-000017</ref>
      <ref url="http://jvn.jp/en/jp/JVN92683325/index.html" source="JVN">JVN#92683325</ref>
    </refs>
    <vuln_soft>
      <prod vendor="movabletype" name="movable_type_advanced">
        <vers num="4.0" edition="beta"/>
        <vers num="4.01" edition="beta"/>
        <vers num="4.1" edition="beta"/>
        <vers num="4.2" edition="beta"/>
        <vers num="4.23"/>
        <vers num="4.25"/>
        <vers num="4.26"/>
        <vers num="4.261"/>
        <vers num="4.3"/>
        <vers num="4.31"/>
        <vers num="4.32"/>
        <vers num="4.33"/>
        <vers num="4.34"/>
        <vers num="4.35"/>
        <vers num="4.36"/>
        <vers num="4.361"/>
        <vers prev="1" num="4.37"/>
        <vers num="5.02"/>
        <vers num="5.03"/>
        <vers num="5.031"/>
        <vers num="5.04"/>
        <vers num="5.05"/>
        <vers num="5.051"/>
        <vers num="5.06"/>
        <vers num="5.1"/>
        <vers num="5.11"/>
        <vers num="5.12"/>
      </prod>
      <prod vendor="movabletype" name="movable_type_enterprise">
        <vers num="4.0" edition="beta"/>
        <vers num="4.01" edition="beta"/>
        <vers num="4.1" edition="beta"/>
        <vers num="4.2" edition="beta"/>
        <vers num="4.23"/>
        <vers num="4.25"/>
        <vers num="4.26"/>
        <vers num="4.261"/>
        <vers num="4.3"/>
        <vers num="4.31"/>
        <vers num="4.32"/>
        <vers num="4.33"/>
        <vers num="4.34"/>
        <vers num="4.35"/>
        <vers num="4.36"/>
        <vers num="4.361"/>
        <vers prev="1" num="4.37"/>
        <vers num="5.02"/>
        <vers num="5.03"/>
        <vers num="5.031"/>
        <vers num="5.04"/>
        <vers num="5.05"/>
        <vers num="5.051"/>
        <vers num="5.06"/>
        <vers num="5.1"/>
        <vers num="5.11"/>
        <vers num="5.12"/>
      </prod>
      <prod vendor="movabletype" name="movable_type_open_source">
        <vers num="4.0" edition="beta"/>
        <vers num="4.01" edition="beta"/>
        <vers num="4.1" edition="beta"/>
        <vers num="4.2" edition="beta"/>
        <vers num="4.23"/>
        <vers num="4.25"/>
        <vers num="4.26"/>
        <vers num="4.261"/>
        <vers num="4.3"/>
        <vers num="4.31"/>
        <vers num="4.32"/>
        <vers num="4.33"/>
        <vers num="4.34"/>
        <vers num="4.35"/>
        <vers num="4.36"/>
        <vers num="4.361"/>
        <vers prev="1" num="4.37"/>
        <vers num="5.02"/>
        <vers num="5.03"/>
        <vers num="5.031"/>
        <vers num="5.04"/>
        <vers num="5.05"/>
        <vers num="5.051"/>
        <vers num="5.06"/>
        <vers num="5.1"/>
        <vers num="5.11"/>
        <vers num="5.12"/>
      </prod>
      <prod vendor="movabletype" name="movable_type_pro">
        <vers num="4.0" edition="beta"/>
        <vers num="4.01" edition="beta"/>
        <vers num="4.1" edition="beta"/>
        <vers num="4.2" edition="beta"/>
        <vers num="4.23"/>
        <vers num="4.25"/>
        <vers num="4.26"/>
        <vers num="4.261"/>
        <vers num="4.3"/>
        <vers num="4.31"/>
        <vers num="4.32"/>
        <vers num="4.33"/>
        <vers num="4.34"/>
        <vers num="4.35"/>
        <vers num="4.36"/>
        <vers num="4.361"/>
        <vers prev="1" num="4.37"/>
        <vers num="5.02"/>
        <vers num="5.03"/>
        <vers num="5.031"/>
        <vers num="5.04"/>
        <vers num="5.05"/>
        <vers num="5.051"/>
        <vers num="5.06"/>
        <vers num="5.1"/>
        <vers num="5.11"/>
        <vers num="5.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0320" published="2012-03-02" name="CVE-2012-0320" modified="2012-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote attackers to take control of sessions via unspecified vectors related to the (1) commenting feature and (2) community script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.movabletype.org/documentation/appendices/release-notes/513.html" source="CONFIRM" patch="1" adv="1">http://www.movabletype.org/documentation/appendices/release-notes/513.html</ref>
      <ref url="http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html" source="CONFIRM" patch="1" adv="1">http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html</ref>
      <ref url="http://www.securitytracker.com/id?1026738" source="SECTRACK">1026738</ref>
      <ref url="http://www.securityfocus.com/bid/52138" source="BID">52138</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000018" source="JVNDB">JVNDB-2012-000018</ref>
      <ref url="http://jvn.jp/en/jp/JVN20083397/index.html" source="JVN">JVN#20083397</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sixapart" name="movable_type">
        <vers num="4.0" edition="beta"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="rc1"/>
        <vers num="4.0" edition="rc2"/>
        <vers num="4.0" edition="rc3"/>
        <vers num="4.1" edition="beta"/>
        <vers num="4.1" edition="beta2"/>
        <vers num="4.1" edition="rc1"/>
        <vers num="4.12"/>
        <vers num="4.15" edition="beta1"/>
        <vers num="4.15" edition="beta3"/>
        <vers num="4.15" edition="beta4"/>
        <vers num="4.2" edition="rc2"/>
        <vers num="4.2" edition="rc4"/>
        <vers num="4.2" edition="rc5"/>
        <vers num="4.22"/>
        <vers num="4.23"/>
        <vers num="4.24"/>
        <vers num="4.25"/>
        <vers num="4.26"/>
        <vers num="4.261"/>
        <vers num="4.27"/>
        <vers num="4.28" edition=""/>
        <vers num="4.28" edition=":open_source"/>
        <vers num="4.28" edition=":enterprise"/>
        <vers num="4.29" edition=""/>
        <vers num="4.29" edition=":open_source"/>
        <vers num="4.29" edition=":enterprise"/>
        <vers num="4.291" edition=""/>
        <vers num="4.291" edition=":open_source"/>
        <vers num="4.291" edition=":enterprise"/>
        <vers prev="1" num="4.292" edition=""/>
        <vers prev="1" num="4.292" edition=":enterprise"/>
        <vers prev="1" num="4.292" edition=":open_source"/>
        <vers num="4.35"/>
        <vers num="4.36" edition=""/>
        <vers num="4.36" edition=":open_source"/>
        <vers num="4.361" edition=""/>
        <vers num="4.361" edition=":open_source"/>
        <vers prev="1" num="4.37" edition=""/>
        <vers prev="1" num="4.37" edition=":open_source"/>
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":open_source"/>
        <vers num="5.0" edition="beta1"/>
        <vers num="5.0" edition="beta2"/>
        <vers num="5.0" edition="beta3"/>
        <vers num="5.0" edition="beta4"/>
        <vers num="5.0" edition="rc1"/>
        <vers num="5.0" edition="rc2"/>
        <vers num="5.0" edition="rc3"/>
        <vers num="5.01" edition=""/>
        <vers num="5.01" edition=":open_source"/>
        <vers num="5.02" edition=""/>
        <vers num="5.02" edition=":open_source"/>
        <vers num="5.02" edition=":advanced"/>
        <vers num="5.03"/>
        <vers num="5.031"/>
        <vers num="5.04" edition=""/>
        <vers num="5.04" edition=":advanced"/>
        <vers num="5.04" edition=":open_source"/>
        <vers num="5.05" edition=""/>
        <vers num="5.05" edition=":advanced"/>
        <vers num="5.05" edition=":open_source"/>
        <vers num="5.051" edition=""/>
        <vers num="5.051" edition=":advanced"/>
        <vers num="5.051" edition=":open_source"/>
        <vers num="5.06" edition=""/>
        <vers num="5.06" edition=":open_source"/>
        <vers num="5.06" edition=":advanced"/>
        <vers num="5.07"/>
        <vers num="5.1" edition=""/>
        <vers num="5.1" edition=":advanced"/>
        <vers num="5.1" edition=":open_source"/>
        <vers num="5.1" edition="beta"/>
        <vers num="5.1" edition="rc1"/>
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":advanced"/>
        <vers num="5.11" edition=":open_source"/>
        <vers num="5.12" edition=""/>
        <vers num="5.12" edition=":open_source"/>
        <vers num="5.12" edition=":advanced"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0321" published="2012-03-02" name="CVE-2012-0321" modified="2012-03-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the device driver in Kingsoft Internet Security 2011 allows local users to cause a denial of service via a crafted application.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kingsoft.jp/support/security/support_news/supportnews_20120229" source="CONFIRM" adv="1">http://www.kingsoft.jp/support/security/support_news/supportnews_20120229</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000019" source="JVNDB">JVNDB-2012-000019</ref>
      <ref url="http://jvn.jp/en/jp/JVN31517714/index.html" source="JVN">JVN#31517714</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kingsoft" name="internet_security">
        <vers num="2011"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0322" published="2012-03-05" name="CVE-2012-0322" modified="2012-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The EStrongs ES File Explorer application 1.6.0.2 through 1.6.1.1 for Android does not properly restrict access, which allows remote attackers to read arbitrary files via vectors involving an unspecified function.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000020" source="JVNDB">JVNDB-2012-000020</ref>
      <ref url="http://jvn.jp/en/jp/JVN08871006/index.html" source="JVN">JVN#08871006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="estrongs" name="es_file_explorer">
        <vers num="1.6.0.2"/>
        <vers num="1.6.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0323" published="2012-03-09" name="CVE-2012-0323" modified="2012-07-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Autocomplete plugin before 3.0 for SquirrelMail allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://squirrelmail.org/plugin_view.php?id=32" source="MISC" adv="1">http://squirrelmail.org/plugin_view.php?id=32</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000021" source="JVNDB">JVNDB-2012-000021</ref>
      <ref url="http://jvn.jp/en/jp/JVN56653852/index.html" source="JVN">JVN#56653852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_lesniewsk" name="autocomplete">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="2.0"/>
        <vers prev="1" num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0324" published="2012-03-09" name="CVE-2012-0324" modified="2012-03-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CloudBees Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0325.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2012-03-05.cb" source="CONFIRM" adv="1">http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2012-03-05.cb</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000022" source="JVNDB">JVNDB-2012-000022</ref>
      <ref url="http://jvn.jp/en/jp/JVN14791558/index.html" source="JVN">JVN#14791558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cloudbees" name="jenkins">
        <vers num="1.301"/>
        <vers num="1.302"/>
        <vers num="1.303"/>
        <vers num="1.304"/>
        <vers num="1.305"/>
        <vers num="1.306"/>
        <vers num="1.307"/>
        <vers num="1.308"/>
        <vers num="1.309"/>
        <vers num="1.310"/>
        <vers num="1.311"/>
        <vers num="1.312"/>
        <vers num="1.313"/>
        <vers num="1.314"/>
        <vers num="1.315"/>
        <vers num="1.316"/>
        <vers num="1.317"/>
        <vers num="1.318"/>
        <vers num="1.319"/>
        <vers num="1.320"/>
        <vers num="1.321"/>
        <vers num="1.322"/>
        <vers num="1.323"/>
        <vers num="1.324"/>
        <vers num="1.325"/>
        <vers num="1.326"/>
        <vers num="1.327"/>
        <vers num="1.328"/>
        <vers num="1.329"/>
        <vers num="1.330"/>
        <vers num="1.331"/>
        <vers num="1.332"/>
        <vers num="1.333"/>
        <vers num="1.334"/>
        <vers num="1.335"/>
        <vers num="1.336"/>
        <vers num="1.337"/>
        <vers num="1.338"/>
        <vers num="1.339"/>
        <vers num="1.340"/>
        <vers num="1.341"/>
        <vers num="1.342"/>
        <vers num="1.343"/>
        <vers num="1.344"/>
        <vers num="1.345"/>
        <vers num="1.346"/>
        <vers num="1.347"/>
        <vers num="1.348"/>
        <vers num="1.349"/>
        <vers num="1.350"/>
        <vers num="1.351"/>
        <vers num="1.352"/>
        <vers num="1.353"/>
        <vers num="1.354"/>
        <vers num="1.355"/>
        <vers num="1.356"/>
        <vers num="1.357"/>
        <vers num="1.358"/>
        <vers num="1.359"/>
        <vers num="1.360"/>
        <vers num="1.361"/>
        <vers num="1.362"/>
        <vers num="1.363"/>
        <vers num="1.364"/>
        <vers num="1.365"/>
        <vers num="1.366"/>
        <vers num="1.367"/>
        <vers num="1.368"/>
        <vers num="1.369"/>
        <vers num="1.370"/>
        <vers num="1.371"/>
        <vers num="1.372"/>
        <vers num="1.373"/>
        <vers num="1.374"/>
        <vers num="1.375"/>
        <vers num="1.376"/>
        <vers num="1.377"/>
        <vers num="1.378"/>
        <vers num="1.379"/>
        <vers num="1.380"/>
        <vers num="1.382"/>
        <vers num="1.383"/>
        <vers num="1.384"/>
        <vers num="1.386"/>
        <vers num="1.387"/>
        <vers num="1.388"/>
        <vers num="1.389"/>
        <vers num="1.390"/>
        <vers num="1.391"/>
        <vers num="1.392"/>
        <vers num="1.393"/>
        <vers num="1.394"/>
        <vers num="1.395"/>
        <vers num="1.396"/>
        <vers num="1.397"/>
        <vers num="1.398"/>
        <vers num="1.399"/>
        <vers num="1.400" edition=""/>
        <vers num="1.400" edition=":lts"/>
        <vers num="1.400" edition=":enterprise"/>
        <vers num="1.400.0.12" edition=""/>
        <vers num="1.400.0.12" edition=":enterprise"/>
        <vers num="1.400.0.12" edition=":lts"/>
        <vers num="1.401"/>
        <vers num="1.402"/>
        <vers num="1.403"/>
        <vers num="1.404"/>
        <vers num="1.405"/>
        <vers num="1.406"/>
        <vers num="1.407"/>
        <vers num="1.408"/>
        <vers num="1.409"/>
        <vers num="1.409.1" edition=""/>
        <vers num="1.409.1" edition=":lts"/>
        <vers num="1.409.2" edition=""/>
        <vers num="1.409.2" edition=":lts"/>
        <vers num="1.410"/>
        <vers num="1.411"/>
        <vers num="1.412"/>
        <vers num="1.413"/>
        <vers num="1.414"/>
        <vers num="1.415"/>
        <vers num="1.416"/>
        <vers num="1.417"/>
        <vers num="1.418"/>
        <vers num="1.419"/>
        <vers num="1.420"/>
        <vers num="1.421"/>
        <vers num="1.422"/>
        <vers num="1.423"/>
        <vers num="1.424" edition=""/>
        <vers num="1.424" edition=":enterprise"/>
        <vers num="1.424.5" edition=""/>
        <vers num="1.424.5" edition=":enterprise"/>
        <vers num="1.425"/>
        <vers num="1.426"/>
        <vers num="1.427"/>
        <vers num="1.428"/>
        <vers num="1.429"/>
        <vers num="1.430"/>
        <vers num="1.431"/>
        <vers num="1.432"/>
        <vers num="1.433"/>
        <vers num="1.434"/>
        <vers num="1.435"/>
        <vers num="1.436"/>
        <vers num="1.437"/>
        <vers prev="1" num="1.453"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0325" published="2012-03-09" name="CVE-2012-0325" modified="2012-03-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CloudBees Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0324.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2012-03-05.cb" source="CONFIRM" adv="1">http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2012-03-05.cb</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000023" source="JVNDB">JVNDB-2012-000023</ref>
      <ref url="http://jvn.jp/en/jp/JVN79950061/index.html" source="JVN">JVN#79950061</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cloudbees" name="jenkins">
        <vers num="1.301"/>
        <vers num="1.302"/>
        <vers num="1.303"/>
        <vers num="1.304"/>
        <vers num="1.305"/>
        <vers num="1.306"/>
        <vers num="1.307"/>
        <vers num="1.308"/>
        <vers num="1.309"/>
        <vers num="1.310"/>
        <vers num="1.311"/>
        <vers num="1.312"/>
        <vers num="1.313"/>
        <vers num="1.314"/>
        <vers num="1.315"/>
        <vers num="1.316"/>
        <vers num="1.317"/>
        <vers num="1.318"/>
        <vers num="1.319"/>
        <vers num="1.320"/>
        <vers num="1.321"/>
        <vers num="1.322"/>
        <vers num="1.323"/>
        <vers num="1.324"/>
        <vers num="1.325"/>
        <vers num="1.326"/>
        <vers num="1.327"/>
        <vers num="1.328"/>
        <vers num="1.329"/>
        <vers num="1.330"/>
        <vers num="1.331"/>
        <vers num="1.332"/>
        <vers num="1.333"/>
        <vers num="1.334"/>
        <vers num="1.335"/>
        <vers num="1.336"/>
        <vers num="1.337"/>
        <vers num="1.338"/>
        <vers num="1.339"/>
        <vers num="1.340"/>
        <vers num="1.341"/>
        <vers num="1.342"/>
        <vers num="1.343"/>
        <vers num="1.344"/>
        <vers num="1.345"/>
        <vers num="1.346"/>
        <vers num="1.347"/>
        <vers num="1.348"/>
        <vers num="1.349"/>
        <vers num="1.350"/>
        <vers num="1.351"/>
        <vers num="1.352"/>
        <vers num="1.353"/>
        <vers num="1.354"/>
        <vers num="1.355"/>
        <vers num="1.356"/>
        <vers num="1.357"/>
        <vers num="1.358"/>
        <vers num="1.359"/>
        <vers num="1.360"/>
        <vers num="1.361"/>
        <vers num="1.362"/>
        <vers num="1.363"/>
        <vers num="1.364"/>
        <vers num="1.365"/>
        <vers num="1.366"/>
        <vers num="1.367"/>
        <vers num="1.368"/>
        <vers num="1.369"/>
        <vers num="1.370"/>
        <vers num="1.371"/>
        <vers num="1.372"/>
        <vers num="1.373"/>
        <vers num="1.374"/>
        <vers num="1.375"/>
        <vers num="1.376"/>
        <vers num="1.377"/>
        <vers num="1.378"/>
        <vers num="1.379"/>
        <vers num="1.380"/>
        <vers num="1.382"/>
        <vers num="1.383"/>
        <vers num="1.384"/>
        <vers num="1.386"/>
        <vers num="1.387"/>
        <vers num="1.388"/>
        <vers num="1.389"/>
        <vers num="1.390"/>
        <vers num="1.391"/>
        <vers num="1.392"/>
        <vers num="1.393"/>
        <vers num="1.394"/>
        <vers num="1.395"/>
        <vers num="1.396"/>
        <vers num="1.397"/>
        <vers num="1.398"/>
        <vers num="1.399"/>
        <vers num="1.400" edition=""/>
        <vers num="1.400" edition=":lts"/>
        <vers num="1.400" edition=":enterprise"/>
        <vers num="1.400.0.12" edition=""/>
        <vers num="1.400.0.12" edition=":enterprise"/>
        <vers num="1.400.0.12" edition=":lts"/>
        <vers num="1.401"/>
        <vers num="1.402"/>
        <vers num="1.403"/>
        <vers num="1.404"/>
        <vers num="1.405"/>
        <vers num="1.406"/>
        <vers num="1.407"/>
        <vers num="1.408"/>
        <vers num="1.409"/>
        <vers num="1.409.1" edition=""/>
        <vers num="1.409.1" edition=":lts"/>
        <vers num="1.409.2" edition=""/>
        <vers num="1.409.2" edition=":lts"/>
        <vers num="1.410"/>
        <vers num="1.411"/>
        <vers num="1.412"/>
        <vers num="1.413"/>
        <vers num="1.414"/>
        <vers num="1.415"/>
        <vers num="1.416"/>
        <vers num="1.417"/>
        <vers num="1.418"/>
        <vers num="1.419"/>
        <vers num="1.420"/>
        <vers num="1.421"/>
        <vers num="1.422"/>
        <vers num="1.423"/>
        <vers num="1.424" edition=""/>
        <vers num="1.424" edition=":enterprise"/>
        <vers num="1.424.5" edition=""/>
        <vers num="1.424.5" edition=":enterprise"/>
        <vers num="1.425"/>
        <vers num="1.426"/>
        <vers num="1.427"/>
        <vers num="1.428"/>
        <vers num="1.429"/>
        <vers num="1.430"/>
        <vers num="1.431"/>
        <vers num="1.432"/>
        <vers num="1.433"/>
        <vers num="1.434"/>
        <vers num="1.435"/>
        <vers num="1.436"/>
        <vers num="1.437"/>
        <vers prev="1" num="1.453"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0326" published="2012-03-17" name="CVE-2012-0326" modified="2012-11-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The twicca application 0.7.0 through 0.9.30 for Android does not properly restrict the use of network privileges, which allows remote attackers to read media files on an SD card via a crafted application.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://play.google.com/store/apps/details?id=jp.r246.twicca" source="CONFIRM" patch="1" adv="1">https://play.google.com/store/apps/details?id=jp.r246.twicca</ref>
      <ref url="http://twicca.r246.jp/notice/" source="CONFIRM" patch="1">http://twicca.r246.jp/notice/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/73951" source="XF">twicca-android-sec-bypass(73951)</ref>
      <ref url="http://www.securityfocus.com/bid/52442" source="BID">52442</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000024" source="JVNDB">JVNDB-2012-000024</ref>
      <ref url="http://jvn.jp/en/jp/JVN31860555/index.html" source="JVN">JVN#31860555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tetsuya_aoyama" name="twicca">
        <vers num="0.7.0"/>
        <vers num="0.8.8"/>
        <vers num="0.9.13" edition="rc2"/>
        <vers num="0.9.13a" edition="rc2"/>
        <vers num="0.9.13b-rc2"/>
        <vers num="0.9.16"/>
        <vers num="0.9.17b"/>
        <vers num="0.9.20"/>
        <vers num="0.9.20a"/>
        <vers num="0.9.20b"/>
        <vers num="0.9.20c"/>
        <vers num="0.9.20e"/>
        <vers num="0.9.26"/>
        <vers num="0.9.26c"/>
        <vers num="0.9.26c2"/>
        <vers num="0.9.30"/>
        <vers num="0.9.31"/>
        <vers num="0.9.31a"/>
        <vers num="0.9.4g" edition="rc2"/>
        <vers num="0.9.4g2" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0327" published="2012-04-05" name="CVE-2012-0327" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Redmine before 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/52447" source="BID">52447</ref>
      <ref url="http://www.redmine.org/versions/42" source="MISC">http://www.redmine.org/versions/42</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000025" source="JVNDB">JVNDB-2012-000025</ref>
      <ref url="http://jvn.jp/en/jp/JVN93406632/index.html" source="JVN">JVN#93406632</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redmine" name="redmine">
        <vers num="0.1.0"/>
        <vers num="0.2.1"/>
        <vers num="0.2.2"/>
        <vers num="0.3.0"/>
        <vers num="0.4.0"/>
        <vers num="0.4.1"/>
        <vers num="0.4.2"/>
        <vers num="0.5.0"/>
        <vers num="0.5.1"/>
        <vers num="0.6.0"/>
        <vers num="0.6.1"/>
        <vers num="0.6.2"/>
        <vers num="0.6.3"/>
        <vers num="0.6.4"/>
        <vers num="0.7.0" edition="rc1"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.7.4"/>
        <vers num="0.8.0" edition="rc1"/>
        <vers num="0.8.1"/>
        <vers num="0.8.2"/>
        <vers num="0.8.3"/>
        <vers num="0.8.4"/>
        <vers num="0.8.5"/>
        <vers num="0.8.6"/>
        <vers num="0.8.7"/>
        <vers num="0.9.0"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.3.0"/>
        <vers prev="1" num="1.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0328" published="2012-03-19" name="CVE-2012-0328" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Janetter before 3.3.0.0 (aka 3.3.0) allows remote attackers to obtain session information for twitter.com web sites via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74132" source="XF">janetter-info-disclosure(74132)</ref>
      <ref url="http://www.securityfocus.com/bid/52555" source="BID">52555</ref>
      <ref url="http://secunia.com/advisories/48480" source="SECUNIA">48480</ref>
      <ref url="http://osvdb.org/80334" source="OSVDB">80334</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000026" source="JVNDB">JVNDB-2012-000026</ref>
      <ref url="http://jvn.jp/en/jp/JVN10745573/index.html" source="JVN">JVN#10745573</ref>
      <ref url="http://janetter.net/history.html" source="CONFIRM">http://janetter.net/history.html</ref>
      <ref url="http://blog.janetter.net/" source="CONFIRM">http://blog.janetter.net/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="janetter" name="janetter">
        <vers num="1.0.0.0"/>
        <vers num="1.1.0.0"/>
        <vers num="1.2.0.0"/>
        <vers num="1.2.1.0"/>
        <vers num="1.3.0.0"/>
        <vers num="1.4.0.0"/>
        <vers num="1.5.0.0"/>
        <vers num="1.6.0.0"/>
        <vers num="1.6.1.0"/>
        <vers num="1.6.2.0"/>
        <vers num="1.6.3.0"/>
        <vers num="1.7.0.0"/>
        <vers num="1.7.1.0"/>
        <vers num="1.7.2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.1.0"/>
        <vers num="2.0.2.0"/>
        <vers num="2.0.3.0"/>
        <vers num="2.1.0.0"/>
        <vers num="2.1.1.0"/>
        <vers num="2.1.1.1"/>
        <vers num="2.1.1.2"/>
        <vers num="2.2.0.0"/>
        <vers num="2.3.0.0"/>
        <vers num="2.4.0.0"/>
        <vers num="2.5.0.0"/>
        <vers num="2.5.1.0"/>
        <vers num="3.0.0.0"/>
        <vers num="3.1.0.0"/>
        <vers num="3.1.0.1"/>
        <vers num="3.1.1.0"/>
        <vers num="3.2.0.0"/>
        <vers num="3.2.1.0"/>
        <vers prev="1" num="3.2.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0329" published="2012-01-19" name="CVE-2012-0329" modified="2012-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Cisco Digital Media Manager 5.2.2 and earlier, and 5.2.3, allows remote authenticated users to execute arbitrary code via vectors involving a URL and an administrative resource, aka Bug ID CSCts63878.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1026541" source="SECTRACK">1026541</ref>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120118-dmm" source="CISCO" adv="1">20120118 Cisco Digital Media Manager Privilege Escalation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="digital_media_manager">
        <vers num="3.5"/>
        <vers num="3.5(1)"/>
        <vers num="4.0"/>
        <vers num="4.1(0)40"/>
        <vers num="5.0"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2.1"/>
        <vers num="5.2.1.1"/>
        <vers prev="1" num="5.2.2"/>
        <vers num="5.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0330" published="2012-02-29" name="CVE-2012-0330" modified="2012-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a malformed SIP message, aka Bug ID CSCtr20426.</descript>
      <descript source="nvd">Per: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-vcs

'Vulnerable Products
These vulnerabilities affect all three variants (Control, Expressway, and Starter Pack Express) of Cisco TelePresence Video Communication Server.'</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-vcs" source="CISCO" adv="1">20120229 Cisco TelePresence Video Communication Server Session Initiation Protocol Denial of Service Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_system_software">
        <vers num="x5.2"/>
        <vers num="x6.0"/>
        <vers num="x6.1"/>
        <vers prev="1" num="x7.0"/>
      </prod>
      <prod vendor="cisco" name="telepresence_video_communication_server">
        <vers num="" edition=":starter_pack_express"/>
        <vers num="" edition=":control"/>
        <vers num="" edition=":expressway"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0331" published="2012-02-29" name="CVE-2012-0331" modified="2012-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP packet, as demonstrated by a SIP INVITE message from a Tandberg device, aka Bug ID CSCtq73319.</descript>
      <descript source="nvd">Per: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-vcs

'Vulnerable Products
These vulnerabilities affect all three variants (Control, Expressway, and Starter Pack Express) of Cisco TelePresence Video Communication Server.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-vcs" source="CISCO" adv="1">20120229 Cisco TelePresence Video Communication Server Session Initiation Protocol Denial of Service Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_system_software">
        <vers num="x5.2"/>
        <vers num="x6.0"/>
        <vers num="x6.1"/>
        <vers prev="1" num="x7.0"/>
      </prod>
      <prod vendor="cisco" name="telepresence_video_communication_server">
        <vers num="" edition=":starter_pack_express"/>
        <vers num="" edition=":control"/>
        <vers num="" edition=":expressway"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0333" published="2012-05-02" name="CVE-2012-0333" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Small Business IP phones with SPA 500 series firmware 7.4.9 and earlier do not require authentication for Push XML requests, which allows remote attackers to make telephone calls via an XML document, aka Bug ID CSCts08768.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1027012" source="SECTRACK">1027012</ref>
      <ref url="http://www-europe.cisco.com/en/US/docs/voice_ip_comm/csbpipp/ip_phones/release/notes/spa525g_relnote_7_5_1.pdf" source="CONFIRM">http://www-europe.cisco.com/en/US/docs/voice_ip_comm/csbpipp/ip_phones/release/notes/spa525g_relnote_7_5_1.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="small_business_ip_phone_firmware">
        <vers num="7.1.7"/>
        <vers num="7.2.5"/>
        <vers num="7.3.5"/>
        <vers num="7.4.3"/>
        <vers num="7.4.4"/>
        <vers num="7.4.5"/>
        <vers num="7.4.6"/>
        <vers num="7.4.7"/>
        <vers num="7.4.8"/>
        <vers prev="1" num="7.4.9"/>
      </prod>
      <prod vendor="cisco" name="small_business_ip_phone">
        <vers num="spa525g"/>
        <vers num="spa525g2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0335" published="2012-05-02" name="CVE-2012-0335" modified="2012-11-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attempts to cut through a firewall, which allows remote attackers to obtain sensitive information via a connection attempt, aka Bug ID CSCtx42746.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1027008" source="SECTRACK">1027008</ref>
      <ref url="http://www.securityfocus.com/bid/53558" source="BID">53558</ref>
      <ref url="http://www.cisco.com/web/software/280775065/89203/ASA-843-Interim-Release-Notes.html" source="CONFIRM">http://www.cisco.com/web/software/280775065/89203/ASA-843-Interim-Release-Notes.html</ref>
      <ref url="http://secunia.com/advisories/49139" source="SECUNIA">49139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_software">
        <vers num="7.2"/>
        <vers num="7.2(1)"/>
        <vers num="7.2(1.22)"/>
        <vers num="7.2(2)"/>
        <vers num="7.2(2.10)"/>
        <vers num="7.2(2.14)"/>
        <vers num="7.2(2.15)"/>
        <vers num="7.2(2.16)"/>
        <vers num="7.2(2.17)"/>
        <vers num="7.2(2.18)"/>
        <vers num="7.2(2.19)"/>
        <vers num="7.2(2.48)"/>
        <vers num="7.2(2.5)"/>
        <vers num="7.2(2.7)"/>
        <vers num="7.2(2.8)"/>
        <vers num="7.2(3)"/>
        <vers num="7.2(4)"/>
        <vers num="7.2(5)"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.2.5"/>
        <vers num="8.2(1)"/>
        <vers num="8.2(2)"/>
        <vers num="8.2(3)"/>
        <vers num="8.2(3.9)"/>
        <vers num="8.2(4)"/>
        <vers num="8.2(4.1)"/>
        <vers num="8.2(4.4)"/>
        <vers num="8.2(5)"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2" edition="interim"/>
        <vers num="8.2.3"/>
        <vers num="8.3(1)"/>
        <vers num="8.3(2)"/>
        <vers num="8.3.1" edition="interim"/>
        <vers num="8.3.2"/>
        <vers num="8.4"/>
        <vers num="8.4(1)"/>
        <vers num="8.4(1.11)"/>
        <vers num="8.4(2)"/>
        <vers num="8.4(2.11)"/>
      </prod>
      <prod vendor="cisco" name="5500_series_adaptive_security_appliance">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0337" published="2012-05-02" name="CVE-2012-0337" modified="2012-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the web component in Cisco Unified MeetingPlace 7.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtx08939.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/docs/voice_ip_comm/meetingplace/7_1/english/release_notes/mp71rn.html" source="CONFIRM">http://www.cisco.com/en/US/docs/voice_ip_comm/meetingplace/7_1/english/release_notes/mp71rn.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_meetingplace">
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0338" published="2012-05-02" name="CVE-2012-0338" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish SSH connections from arbitrary source IP addresses via a standard SSH client, aka Bug ID CSCsv86113.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://supportforums.cisco.com/thread/2030226" source="CONFIRM">https://supportforums.cisco.com/thread/2030226</ref>
      <ref url="http://www.securitytracker.com/id?1027005" source="SECTRACK">1027005</ref>
      <ref url="http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/release/notes/caveats_SXH_rebuilds.html" source="CONFIRM">http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/release/notes/caveats_SXH_rebuilds.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2"/>
        <vers num="12.3"/>
        <vers num="12.4"/>
        <vers num="15.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0339" published="2012-05-02" name="CVE-2012-0339" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish TELNET connections from arbitrary source IP addresses via a standard TELNET client, aka Bug ID CSCsi77774.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1027005" source="SECTRACK">1027005</ref>
      <ref url="http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SXF/native/release/notes/caveats_SXF_rebuilds.html" source="CONFIRM">http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SXF/native/release/notes/caveats_SXF_rebuilds.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2"/>
        <vers num="12.3"/>
        <vers num="12.4"/>
        <vers num="15.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0340" published="2012-02-13" name="CVE-2012-0340" modified="2012-02-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the management interface on the Cisco IronPort Encryption Appliance with software before 6.5.3 allows remote attackers to inject arbitrary web script or HTML via the header parameter to the default URI under admin/, aka bug ID 72410.</descript>
      <descript source="nvd">Additional information can be found at: 
http://www.secureworks.com/research/advisories/SWRX-2012-001/ </descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.secureworks.com/research/advisories/SWRX-2012-001/" source="MISC">http://www.secureworks.com/research/advisories/SWRX-2012-001/</ref>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=25045" source="CONFIRM" adv="1">http://tools.cisco.com/security/center/viewAlert.x?alertId=25045</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_encryption_appliance">
        <vers num="4.2.1-22.2.i386"/>
        <vers num="4.2.1-22.i386"/>
        <vers num="5.2"/>
        <vers num="6.2"/>
        <vers num="6.2.4"/>
        <vers num="6.2.4.1"/>
        <vers num="6.2.5"/>
        <vers num="6.2.6"/>
        <vers num="6.2.7"/>
        <vers num="6.2.7.1"/>
        <vers num="6.2.7.2"/>
        <vers num="6.2.7.3"/>
        <vers num="6.2.7.4"/>
        <vers num="6.2.7.5"/>
        <vers num="6.2.7.6"/>
        <vers num="6.2.7.7"/>
        <vers num="6.2.9"/>
        <vers num="6.3"/>
        <vers num="6.3.0.1"/>
        <vers num="6.3.0.2"/>
        <vers num="6.3.0.3"/>
        <vers num="6.3.0.4"/>
        <vers num="6.5"/>
        <vers num="6.5.0.1"/>
        <vers num="6.5.0.3"/>
        <vers num="6.5.2"/>
        <vers num="6.5.2.1"/>
        <vers prev="1" num="6.5.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0352" published="2012-02-16" name="CVE-2012-0352" modified="2012-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco NX-OS 4.2.x before 4.2(1)SV1(5.1) on Nexus 1000v series switches; 4.x and 5.0.x before 5.0(2)N1(1) on Nexus 5000 series switches; and 4.2.x before 4.2.8, 5.0.x before 5.0.5, and 5.1.x before 5.1.1 on Nexus 7000 series switches allows remote attackers to cause a denial of service (netstack process crash and device reload) via a malformed IP packet, aka Bug IDs CSCti23447, CSCti49507, and CSCtj01991.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120215-nxos" source="CISCO" adv="1">20120215 Cisco NX-OS Malformed IP Packet Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="nexus_1000v">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="nexus_5000">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="nexus_5010">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="nexus_5020">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="nexus_5548p">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="nexus_5548up">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="nexus_5596up">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="nexus_7000">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="nexus_7000_10-slot">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="nexus_7000_18-slot">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="nexus_7000_9-slot">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="nx-os">
        <vers num="4.0(0)n1(1a)"/>
        <vers num="4.0(0)n1(2)"/>
        <vers num="4.0(0)n1(2a)"/>
        <vers num="4.0(1a)n1(1)"/>
        <vers num="4.0(1a)n1(1a)"/>
        <vers num="4.0(1a)n2(1)"/>
        <vers num="4.0(1a)n2(1a)"/>
        <vers num="4.0(4)sv1(1)"/>
        <vers num="4.0(4)sv1(2)"/>
        <vers num="4.0(4)sv1(3)"/>
        <vers num="4.0(4)sv1(3a)"/>
        <vers num="4.0(4)sv1(3b)"/>
        <vers num="4.0(4)sv1(3c)"/>
        <vers num="4.0(4)sv1(3d)"/>
        <vers num="4.1(3)n1(1)"/>
        <vers num="4.1(3)n1(1a)"/>
        <vers num="4.1(3)n2(1)"/>
        <vers num="4.1(3)n2(1a)"/>
        <vers num="4.1.(2)"/>
        <vers num="4.1.(3)"/>
        <vers num="4.1.(4)"/>
        <vers num="4.1.(5)"/>
        <vers num="4.2(1)"/>
        <vers num="4.2(1)n1(1)"/>
        <vers num="4.2(1)n2(1)"/>
        <vers num="4.2(1)n2(1a)"/>
        <vers num="4.2(1)sv1(4)"/>
        <vers num="4.2(1)sv1(4a)"/>
        <vers num="4.2(2)"/>
        <vers num="4.2(3)"/>
        <vers num="4.2(4)"/>
        <vers num="4.2(6)"/>
        <vers num="4.2.(2a)"/>
        <vers num="5.0(2)"/>
        <vers num="5.0(2)n2(1)"/>
        <vers num="5.0(2)n2(1a)"/>
        <vers num="5.0(2a)"/>
        <vers num="5.0(3)"/>
        <vers num="5.0(3)n1(1)"/>
        <vers num="5.0(3)n1(1a)"/>
        <vers num="5.0(3)n1(1b)"/>
        <vers num="5.0(3)n1(1c)"/>
        <vers num="5.0(3)n2(1)"/>
        <vers num="5.0(3)n2(2)"/>
        <vers num="5.0(3)n2(2a)"/>
        <vers num="5.0(3)n2(2b)"/>
        <vers num="5.1(1a)"/>
        <vers num="5.1(2)"/>
        <vers num="5.1(3)"/>
        <vers num="5.1(3)n1(1)"/>
        <vers num="5.1(3)n1(1a)"/>
        <vers num="5.1(4)"/>
        <vers num="5.1(5)"/>
        <vers num="5.1(6)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0353" published="2012-03-14" name="CVE-2012-0353" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The UDP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.5), 8.3 before 8.3(2.22), 8.4 before 8.4(2.1), and 8.5 before 8.5(1.2) does not properly handle flows, which allows remote attackers to cause a denial of service (device reload) via a crafted series of (1) IPv4 or (2) IPv6 UDP packets, aka Bug ID CSCtq10441.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74029" source="XF">cisco-udp-dos(74029)</ref>
      <ref url="http://www.securityfocus.com/bid/52484" source="BID">52484</ref>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120314-asa" source="CISCO" adv="1">20120314 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module</ref>
      <ref url="http://secunia.com/advisories/48423" source="SECUNIA">48423</ref>
      <ref url="http://osvdb.org/80043" source="OSVDB">80043</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_software">
        <vers num="8.0"/>
        <vers num="8.0(2)"/>
        <vers num="8.0(3)"/>
        <vers num="8.0(4)"/>
        <vers num="8.0(5)"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="8.0.5"/>
        <vers num="8.1"/>
        <vers num="8.2(1)"/>
        <vers num="8.2(2)"/>
        <vers num="8.2(3)"/>
        <vers num="8.2(3.9)"/>
        <vers num="8.2(4)"/>
        <vers num="8.2(4.1)"/>
        <vers num="8.2(4.4)"/>
        <vers num="8.2(5)"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2" edition="interim"/>
        <vers num="8.2.3"/>
        <vers num="8.3(1)"/>
        <vers num="8.3(2)"/>
        <vers num="8.3.1" edition="interim"/>
        <vers num="8.3.2"/>
        <vers num="8.4"/>
        <vers num="8.4(1)"/>
        <vers num="8.4(1.11)"/>
        <vers num="8.4(2)"/>
        <vers num="8.5"/>
      </prod>
      <prod vendor="cisco" name="5500_series_adaptive_security_appliance">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="catalyst_6500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="catalyst_6503-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6504-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6506-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6509-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6509-neb-a">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6509-v-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6513">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6513-e">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0354" published="2012-03-14" name="CVE-2012-0354" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The Threat Detection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.0 through 8.2 before 8.2(5.20), 8.3 before 8.3(2.29), 8.4 before 8.4(3), 8.5 before 8.5(1.6), and 8.6 before 8.6(1.1) allows remote attackers to cause a denial of service (device reload) via (1) IPv4 or (2) IPv6 packets that trigger a shun event, aka Bug ID CSCtw35765.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120314-asa" source="CISCO" adv="1">20120314 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module</ref>
      <ref url="http://secunia.com/advisories/48423" source="SECUNIA">48423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_software">
        <vers num="8.0"/>
        <vers num="8.0(2)"/>
        <vers num="8.0(3)"/>
        <vers num="8.0(4)"/>
        <vers num="8.0(5)"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="8.0.5"/>
        <vers num="8.1"/>
        <vers num="8.2(1)"/>
        <vers num="8.2(2)"/>
        <vers num="8.2(3)"/>
        <vers num="8.2(3.9)"/>
        <vers num="8.2(4)"/>
        <vers num="8.2(4.1)"/>
        <vers num="8.2(4.4)"/>
        <vers num="8.2(5)"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2" edition="interim"/>
        <vers num="8.2.3"/>
        <vers num="8.3(1)"/>
        <vers num="8.3(2)"/>
        <vers num="8.3.1" edition="interim"/>
        <vers num="8.3.2"/>
        <vers num="8.4"/>
        <vers num="8.4(1)"/>
        <vers num="8.4(1.11)"/>
        <vers num="8.4(2)"/>
        <vers num="8.4(2.11)"/>
        <vers num="8.5"/>
        <vers num="8.5(1)"/>
        <vers num="8.5(1.4)"/>
        <vers num="8.6"/>
      </prod>
      <prod vendor="cisco" name="5500_series_adaptive_security_appliance">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="catalyst_6500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="catalyst_6503-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6504-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6506-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6509-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6509-neb-a">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6509-v-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6513">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6513-e">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0355" published="2012-03-14" name="CVE-2012-0355" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.4 before 8.4(2.11) and 8.5 before 8.5(1.4) allow remote attackers to cause a denial of service (device reload) via (1) IPv4 or (2) IPv6 packets that trigger syslog message 305006, aka Bug ID CSCts39634.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120314-asa" source="CISCO" adv="1">20120314 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module</ref>
      <ref url="http://secunia.com/advisories/48423" source="SECUNIA">48423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_software">
        <vers num="8.4"/>
        <vers num="8.4(1)"/>
        <vers num="8.4(1.11)"/>
        <vers num="8.4(2)"/>
        <vers num="8.4(2.11)"/>
        <vers num="8.5"/>
        <vers num="8.5(1)"/>
        <vers num="8.5(1.4)"/>
      </prod>
      <prod vendor="cisco" name="5500_series_adaptive_security_appliance">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="catalyst_6500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="catalyst_6503-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6504-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6506-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6509-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6509-neb-a">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6509-v-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6513">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6513-e">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0356" published="2012-03-14" name="CVE-2012-0356" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 7.0 through 7.2 before 7.2(5.7), 8.0 before 8.0(5.27), 8.1 before 8.1(2.53), 8.2 before 8.2(5.8), 8.3 before 8.3(2.25), 8.4 before 8.4(2.5), and 8.5 before 8.5(1.2) and the Firewall Services Module (FWSM) 3.1 and 3.2 before 3.2(23) and 4.0 and 4.1 before 4.1(8) in Cisco Catalyst 6500 series devices, when multicast routing is enabled, allow remote attackers to cause a denial of service (device reload) via a crafted IPv4 PIM message, aka Bug IDs CSCtr47517 and CSCtu97367.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120314-fwsm" source="CISCO" adv="1">20120314 Cisco Firewall Services Module Crafted Protocol Independent Multicast Message Denial of Service Vulnerability</ref>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120314-asa" source="CISCO" adv="1">20120314 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module</ref>
      <ref url="http://secunia.com/advisories/48423" source="SECUNIA">48423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_software">
        <vers num="7.0"/>
        <vers num="7.0(0)"/>
        <vers num="7.0(1)"/>
        <vers num="7.0(2)"/>
        <vers num="7.0(4)"/>
        <vers num="7.0(5)"/>
        <vers num="7.0(5.2)"/>
        <vers num="7.0(6)"/>
        <vers num="7.0(6.7)"/>
        <vers num="7.0(7)"/>
        <vers num="7.0(8)"/>
        <vers num="7.0.1"/>
        <vers num="7.0.1.4"/>
        <vers num="7.0.2"/>
        <vers num="7.0.4"/>
        <vers num="7.0.4.3"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8" edition="interim"/>
        <vers num="7.1"/>
        <vers num="7.1(2)"/>
        <vers num="7.1(2.27)"/>
        <vers num="7.1(2.48)"/>
        <vers num="7.1(2.49)"/>
        <vers num="7.1(2.5)"/>
        <vers num="7.1(5)"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.2"/>
        <vers num="7.2(1)"/>
        <vers num="7.2(1.22)"/>
        <vers num="7.2(2)"/>
        <vers num="7.2(2.10)"/>
        <vers num="7.2(2.14)"/>
        <vers num="7.2(2.15)"/>
        <vers num="7.2(2.16)"/>
        <vers num="7.2(2.17)"/>
        <vers num="7.2(2.18)"/>
        <vers num="7.2(2.19)"/>
        <vers num="7.2(2.48)"/>
        <vers num="7.2(2.5)"/>
        <vers num="7.2(2.7)"/>
        <vers num="7.2(2.8)"/>
        <vers num="7.2(3)"/>
        <vers num="7.2(4)"/>
        <vers num="7.2(5)"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.2.5"/>
        <vers num="8.0"/>
        <vers num="8.0(2)"/>
        <vers num="8.0(3)"/>
        <vers num="8.0(4)"/>
        <vers num="8.0(5)"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="8.0.5"/>
        <vers num="8.1"/>
        <vers num="8.2(1)"/>
        <vers num="8.2(2)"/>
        <vers num="8.2(3)"/>
        <vers num="8.2(3.9)"/>
        <vers num="8.2(4)"/>
        <vers num="8.2(4.1)"/>
        <vers num="8.2(4.4)"/>
        <vers num="8.2(5)"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2" edition="interim"/>
        <vers num="8.2.3"/>
        <vers num="8.3(1)"/>
        <vers num="8.3(2)"/>
        <vers num="8.3.1" edition="interim"/>
        <vers num="8.3.2"/>
        <vers num="8.4"/>
        <vers num="8.4(1)"/>
        <vers num="8.4(1.11)"/>
        <vers num="8.4(2)"/>
        <vers num="8.4(2.11)"/>
        <vers num="8.5"/>
        <vers num="8.5(1)"/>
        <vers num="8.5(1.4)"/>
      </prod>
      <prod vendor="cisco" name="firewall_services_module_software">
        <vers num="3.1"/>
        <vers num="3.1(10)"/>
        <vers num="3.1(11)"/>
        <vers num="3.1(12)"/>
        <vers num="3.1(13)"/>
        <vers num="3.1(14)"/>
        <vers num="3.1(15)"/>
        <vers num="3.1(16)"/>
        <vers num="3.1(17)"/>
        <vers num="3.1(18)"/>
        <vers num="3.1(19)"/>
        <vers num="3.1(2)"/>
        <vers num="3.1(20)"/>
        <vers num="3.1(21)"/>
        <vers num="3.1(3)"/>
        <vers num="3.1(4)"/>
        <vers num="3.1(5)"/>
        <vers num="3.1(6)"/>
        <vers num="3.1(7)"/>
        <vers num="3.1(8)"/>
        <vers num="3.1(9)"/>
        <vers num="3.2"/>
        <vers num="3.2(1)"/>
        <vers num="3.2(10)"/>
        <vers num="3.2(11)"/>
        <vers num="3.2(12)"/>
        <vers num="3.2(13)"/>
        <vers num="3.2(14)"/>
        <vers num="3.2(15)"/>
        <vers num="3.2(16)"/>
        <vers num="3.2(17)"/>
        <vers num="3.2(18)"/>
        <vers num="3.2(19)"/>
        <vers num="3.2(2)"/>
        <vers num="3.2(20)"/>
        <vers num="3.2(21)"/>
        <vers num="3.2(22)"/>
        <vers num="3.2(3)"/>
        <vers num="3.2(4)"/>
        <vers num="3.2(5)"/>
        <vers num="3.2(6)"/>
        <vers num="3.2(7)"/>
        <vers num="3.2(8)"/>
        <vers num="3.2(9)"/>
        <vers num="4.0"/>
        <vers num="4.0(1)"/>
        <vers num="4.0(10)"/>
        <vers num="4.0(11)"/>
        <vers num="4.0(12)"/>
        <vers num="4.0(13)"/>
        <vers num="4.0(14)"/>
        <vers num="4.0(15)"/>
        <vers num="4.0(2)"/>
        <vers num="4.0(3)"/>
        <vers num="4.0(4)"/>
        <vers num="4.0(5)"/>
        <vers num="4.0(6)"/>
        <vers num="4.0(7)"/>
        <vers num="4.0(8)"/>
        <vers num="4.1"/>
        <vers num="4.1(1)"/>
        <vers num="4.1(2)"/>
        <vers num="4.1(3)"/>
        <vers num="4.1(4)"/>
        <vers num="4.1(5)"/>
        <vers num="4.1(6)"/>
        <vers num="4.1(7)"/>
      </prod>
      <prod vendor="cisco" name="5500_series_adaptive_security_appliance">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="catalyst_6500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="catalyst_6503-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6504-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6506-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6509-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6509-neb-a">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6509-v-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6513">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="catalyst_6513-e">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0358" published="2012-03-14" name="CVE-2012-0358" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Cisco Port Forwarder ActiveX control in cscopf.ocx, as distributed through the Clientless VPN feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 through 7.2 before 7.2(5.6), 8.0 before 8.0(5.26), 8.1 before 8.1(2.53), 8.2 before 8.2(5.18), 8.3 before 8.3(2.28), 8.2 before 8.4(2.16), and 8.6 before 8.6(1.1), allows remote attackers to execute arbitrary code via unspecified vectors, aka Bug ID CSCtr00165.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/339177" source="CERT-VN">VU#339177</ref>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120314-asaclient" source="CISCO" adv="1">20120314 Cisco ASA 5500 Series Adaptive Security Appliance Clientless VPN ActiveX Control Remote Code Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_software">
        <vers num="7.0"/>
        <vers num="7.0(0)"/>
        <vers num="7.0(1)"/>
        <vers num="7.0(2)"/>
        <vers num="7.0(4)"/>
        <vers num="7.0(5)"/>
        <vers num="7.0(5.2)"/>
        <vers num="7.0(6)"/>
        <vers num="7.0(6.7)"/>
        <vers num="7.0(7)"/>
        <vers num="7.0(8)"/>
        <vers num="7.0.1"/>
        <vers num="7.0.1.4"/>
        <vers num="7.0.2"/>
        <vers num="7.0.4"/>
        <vers num="7.0.4.3"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8" edition="interim"/>
        <vers num="7.1"/>
        <vers num="7.1(2)"/>
        <vers num="7.1(2.27)"/>
        <vers num="7.1(2.48)"/>
        <vers num="7.1(2.49)"/>
        <vers num="7.1(2.5)"/>
        <vers num="7.1(5)"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.2"/>
        <vers num="7.2(1)"/>
        <vers num="7.2(1.22)"/>
        <vers num="7.2(2)"/>
        <vers num="7.2(2.10)"/>
        <vers num="7.2(2.14)"/>
        <vers num="7.2(2.15)"/>
        <vers num="7.2(2.16)"/>
        <vers num="7.2(2.17)"/>
        <vers num="7.2(2.18)"/>
        <vers num="7.2(2.19)"/>
        <vers num="7.2(2.48)"/>
        <vers num="7.2(2.5)"/>
        <vers num="7.2(2.7)"/>
        <vers num="7.2(2.8)"/>
        <vers num="7.2(3)"/>
        <vers num="7.2(4)"/>
        <vers num="7.2(5)"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.2.5"/>
        <vers num="8.0"/>
        <vers num="8.0(2)"/>
        <vers num="8.0(3)"/>
        <vers num="8.0(4)"/>
        <vers num="8.0(5)"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="8.0.5"/>
        <vers num="8.1"/>
        <vers num="8.2(1)"/>
        <vers num="8.2(2)"/>
        <vers num="8.2(3)"/>
        <vers num="8.2(3.9)"/>
        <vers num="8.2(4)"/>
        <vers num="8.2(4.1)"/>
        <vers num="8.2(4.4)"/>
        <vers num="8.2(5)"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2" edition="interim"/>
        <vers num="8.2.3"/>
        <vers num="8.3(1)"/>
        <vers num="8.3(2)"/>
        <vers num="8.3.1" edition="interim"/>
        <vers num="8.3.2"/>
        <vers num="8.4"/>
        <vers num="8.4(1)"/>
        <vers num="8.4(1.11)"/>
        <vers num="8.4(2)"/>
        <vers num="8.4(2.11)"/>
        <vers num="8.5"/>
        <vers num="8.6"/>
        <vers num="8.6(1)"/>
      </prod>
      <prod vendor="cisco" name="5500_series_adaptive_security_appliance">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0359" published="2012-02-29" name="CVE-2012-0359" modified="2012-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Cisco Cius with software before 9.2(1) SR2 allows remote attackers to cause a denial of service (device crash or hang) via malformed network traffic, aka Bug ID CSCto71445.</descript>
      <descript source="nvd">Per: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-cius

'Vulnerable Products
The following products are affected by the vulnerability detailed in this advisory:

    * Cius Wifi devices running Cius Software Version 9.2(1) SR1 and prior'</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-cius" source="CISCO" adv="1">20120229 Cisco Cius Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cius_software">
        <vers num="9.2"/>
        <vers num="9.2(1)"/>
        <vers prev="1" num="9.2(1)sr1"/>
        <vers num="9.2(2)"/>
        <vers num="9.2(2)at"/>
      </prod>
      <prod vendor="cisco" name="cius">
        <vers num="-"/>
        <vers num="7-at-k9"/>
        <vers num="7-k9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0361" published="2012-05-02" name="CVE-2012-0361" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The sccp-protocol component in Cisco IP Communicator (CIPC) 7.0 through 8.6 does not limit the rate of SCCP messages to Cisco Unified Communications Manager (CUCM), which allows remote attackers to cause a denial of service via vectors that trigger (1) on hook and (2) off hook messages, as demonstrated by a Plantronics headset, aka Bug ID CSCti40315.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1027013" source="SECTRACK">1027013</ref>
      <ref url="http://www.cisco.com/en/US/docs/voice_ip_comm/cipc/8_5/english/release_notes/CIPC8x_RN.html" source="CONFIRM">http://www.cisco.com/en/US/docs/voice_ip_comm/cipc/8_5/english/release_notes/CIPC8x_RN.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ip_communicator">
        <vers num="7.0"/>
        <vers num="7.0(1)"/>
        <vers num="7.0(2)"/>
        <vers num="7.0(3)"/>
        <vers num="7.0(4)"/>
        <vers num="7.0(5)"/>
        <vers num="7.0(6)"/>
        <vers num="8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0362" published="2012-05-02" name="CVE-2012-0362" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The extended ACL functionality in Cisco IOS 12.2(58)SE2 and 15.0(1)SE discards all lines that end with a log or time keyword, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending network traffic, aka Bug ID CSCts01106.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1027005" source="SECTRACK">1027005</ref>
      <ref url="http://puck.nether.net/pipermail/cisco-nsp/2012-February/083517.html" source="MLIST">[cisco-nsp] 20120202 Ambiguous ACL </ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2(58)ses"/>
        <vers num="15.0(1)se"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0363" published="2012-02-24" name="CVE-2012-0363" modified="2012-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The web interface on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability," aka Bug ID CSCtt46871.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120223-srp500" source="CISCO" patch="1" adv="1">20120223 Cisco Small Business SRP 500 Series Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="small_business_srp520-u_series_firmware">
        <vers num="1.1.0"/>
      </prod>
      <prod vendor="cisco" name="small_business_srp520_series_firmware">
        <vers num="1.01.01"/>
        <vers num="1.01.09"/>
        <vers num="1.01.11"/>
        <vers num="1.01.19"/>
        <vers num="1.01.23"/>
        <vers prev="1" num="1.01.24"/>
      </prod>
      <prod vendor="cisco" name="small_business_srp540_series_firmware">
        <vers num="1.02.00.023"/>
        <vers prev="1" num="1.02.01"/>
      </prod>
      <prod vendor="cisco" name="small_business_srp521w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp521w-u">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp526w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp526w-u">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp527w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp527w-u">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp541w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp546w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp547w">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0364" published="2012-02-24" name="CVE-2012-0364" modified="2012-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allow remote attackers to replace the configuration file via an upload request to an unspecified URL, aka Bug ID CSCtw55495.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120223-srp500" source="CISCO" patch="1" adv="1">20120223 Cisco Small Business SRP 500 Series Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="small_business_srp520-u_series_firmware">
        <vers num="1.1.0"/>
      </prod>
      <prod vendor="cisco" name="small_business_srp520_series_firmware">
        <vers num="1.01.01"/>
        <vers num="1.01.09"/>
        <vers num="1.01.11"/>
        <vers num="1.01.19"/>
        <vers num="1.01.23"/>
        <vers prev="1" num="1.01.24"/>
      </prod>
      <prod vendor="cisco" name="small_business_srp540_series_firmware">
        <vers num="1.02.00.023"/>
        <vers prev="1" num="1.02.01"/>
      </prod>
      <prod vendor="cisco" name="small_business_srp521w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp521w-u">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp526w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp526w-u">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp527w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp527w-u">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp541w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp546w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp547w">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0365" published="2012-02-24" name="CVE-2012-0365" modified="2012-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Local TFTP file-upload application on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to upload software to arbitrary directories via unspecified vectors, aka Bug ID CSCtw56009.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120223-srp500" source="CISCO" adv="1">20120223 Cisco Small Business SRP 500 Series Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="small_business_srp520-u_series_firmware">
        <vers num="1.1.0"/>
      </prod>
      <prod vendor="cisco" name="small_business_srp520_series_firmware">
        <vers num="1.01.01"/>
        <vers num="1.01.09"/>
        <vers num="1.01.11"/>
        <vers num="1.01.19"/>
        <vers num="1.01.23"/>
        <vers prev="1" num="1.01.24"/>
      </prod>
      <prod vendor="cisco" name="small_business_srp540_series_firmware">
        <vers num="1.02.00.023"/>
        <vers prev="1" num="1.02.01"/>
      </prod>
      <prod vendor="cisco" name="small_business_srp521w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp521w-u">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp526w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp526w-u">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp527w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp527w-u">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp541w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp546w">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="small_business_srp547w">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0366" published="2012-02-29" name="CVE-2012-0366" modified="2012-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Cisco Unity Connection before 7.1.3b(Su2) allows remote authenticated users to change the administrative password by leveraging the Help Desk Administrator role, aka Bug ID CSCtd45141.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-cuc" source="CISCO" adv="1">20120229 Multiple Vulnerabilities in Cisco Unity Connection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unity_connection">
        <vers num="1.1"/>
        <vers num="1.1(1)"/>
        <vers num="1.1(1)_es1"/>
        <vers num="1.1(1)_es12"/>
        <vers num="1.1(1)_sr1"/>
        <vers num="1.2"/>
        <vers num="1.2(1)"/>
        <vers num="1.2(1)_es65"/>
        <vers num="1.2(1)sr2"/>
        <vers num="2.0"/>
        <vers num="2.0(1)"/>
        <vers num="2.1"/>
        <vers num="2.1(1)"/>
        <vers num="2.1(2)"/>
        <vers num="2.1(3)"/>
        <vers num="2.1(3b)su1"/>
        <vers num="2.1(4)"/>
        <vers num="2.1(4)su1"/>
        <vers num="2.1(4a)"/>
        <vers num="2.1(4a)su2"/>
        <vers num="2.1(5)"/>
        <vers num="2.1(5)su1"/>
        <vers num="2.1(5)su2"/>
        <vers num="2.1(5)su3"/>
        <vers num="6.1(3b)su1"/>
        <vers num="7.0"/>
        <vers num="7.0(2)"/>
        <vers num="7.0(2a)su2"/>
        <vers num="7.0(2a)su3"/>
        <vers num="7.1"/>
        <vers num="7.1(2)"/>
        <vers num="7.1(2a)"/>
        <vers num="7.1(2a)su1"/>
        <vers num="7.1(2b)"/>
        <vers num="7.1(2b)su1"/>
        <vers num="7.1(3)"/>
        <vers num="7.1(3a)"/>
        <vers num="7.1(3a)su1"/>
        <vers num="7.1(3a)su1a"/>
        <vers num="7.1(3b)"/>
        <vers prev="1" num="7.1(3b)su1"/>
        <vers num="7.1(5)"/>
        <vers num="7.1(5)su1a"/>
        <vers num="7.1(5a)"/>
        <vers num="7.1(5b)"/>
        <vers num="7.1(5b)su2"/>
        <vers num="7.1(5b)su3"/>
        <vers num="7.1(5b)su4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0367" published="2012-02-29" name="CVE-2012-0367" modified="2012-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8.6 before 8.6.2 allows remote attackers to cause a denial of service (services crash) via a series of crafted TCP segments, aka Bug ID CSCtq67899.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-cuc" source="CISCO" adv="1">20120229 Multiple Vulnerabilities in Cisco Unity Connection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unity_connection">
        <vers num="1.1"/>
        <vers num="1.1(1)"/>
        <vers num="1.1(1)_es1"/>
        <vers num="1.1(1)_es12"/>
        <vers num="1.1(1)_sr1"/>
        <vers num="1.2"/>
        <vers num="1.2(1)"/>
        <vers num="1.2(1)_es65"/>
        <vers num="1.2(1)sr2"/>
        <vers num="2.0"/>
        <vers num="2.0(1)"/>
        <vers num="2.1"/>
        <vers num="2.1(1)"/>
        <vers num="2.1(2)"/>
        <vers num="2.1(3)"/>
        <vers num="2.1(3b)su1"/>
        <vers num="2.1(4)"/>
        <vers num="2.1(4)su1"/>
        <vers num="2.1(4a)"/>
        <vers num="2.1(4a)su2"/>
        <vers num="2.1(5)"/>
        <vers num="2.1(5)su1"/>
        <vers num="2.1(5)su2"/>
        <vers num="2.1(5)su3"/>
        <vers num="6.1(3b)su1"/>
        <vers num="7.0"/>
        <vers num="7.0(2)"/>
        <vers num="7.0(2a)su2"/>
        <vers num="7.0(2a)su3"/>
        <vers num="7.1"/>
        <vers num="7.1(2)"/>
        <vers num="7.1(2a)"/>
        <vers num="7.1(2a)su1"/>
        <vers num="7.1(2b)"/>
        <vers num="7.1(2b)su1"/>
        <vers num="7.1(3)"/>
        <vers num="7.1(3a)"/>
        <vers num="7.1(3a)su1"/>
        <vers num="7.1(3a)su1a"/>
        <vers num="7.1(3b)"/>
        <vers num="7.1(3b)su1"/>
        <vers num="7.1(3b)su2"/>
        <vers num="7.1(5)"/>
        <vers num="7.1(5)su1a"/>
        <vers num="7.1(5a)"/>
        <vers num="7.1(5b)"/>
        <vers num="7.1(5b)su2"/>
        <vers num="7.1(5b)su3"/>
        <vers prev="1" num="7.1(5b)su4"/>
        <vers num="8.0"/>
        <vers num="8.0(2c)"/>
        <vers num="8.0(2c)su1"/>
        <vers num="8.0(3)"/>
        <vers num="8.0(3a)"/>
        <vers num="8.0(3a)su1"/>
        <vers num="8.0(3a)su2"/>
        <vers num="8.0(3a)su3"/>
        <vers num="8.5"/>
        <vers num="8.5(1)"/>
        <vers num="8.5(1)su1"/>
        <vers num="8.5(1)su2"/>
        <vers num="8.6"/>
        <vers num="8.6(1a)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0368" published="2012-02-29" name="CVE-2012-0368" modified="2012-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allows remote attackers to cause a denial of service (device crash) via a malformed URL in an HTTP request, aka Bug ID CSCts81997.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-wlc" source="CISCO" adv="1">20120229 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="2000_wireless_lan_controller">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="2100_wireless_lan_controller">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="2106_wireless_lan_controller">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="2112_wireless_lan_controller">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="2125_wireless_lan_controller">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="2500_wireless_lan_controller">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="2504_wireless_lan_controller">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="4100_wireless_lan_controller">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="4400_wireless_lan_controller">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="4402_wireless_lan_controller">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="4404_wireless_lan_controller">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="5508_wireless_controller">
        <vers num="-"/>
      </prod>
      <prod vendor="cisco" name="wireless_lan_controller_software">
        <vers num="4.0"/>
        <vers num="4.0.108"/>
        <vers num="4.0.155.0"/>
        <vers num="4.0.155.5"/>
        <vers num="4.0.179.11"/>
        <vers num="4.0.179.8"/>
        <vers num="4.0.196"/>
        <vers num="4.0.206.0"/>
        <vers num="4.0.217.0"/>
        <vers num="4.0.219.0"/>
        <vers num="4.1"/>
        <vers num="4.1.171.0"/>
        <vers num="4.1.181.0"/>
        <vers num="4.1.185.0"/>
        <vers num="4.1m"/>
        <vers num="4.2"/>
        <vers num="4.2.112.0"/>
        <vers num="4.2.117.0"/>
        <vers num="4.2.130.0"/>
        <vers num="4.2.173.0"/>
        <vers num="4.2.174.0"/>
        <vers num="4.2.176.0"/>
        <vers num="4.2.182.0"/>
        <vers num="4.2.61.0"/>
        <vers num="4.2.99.0"/>
        <vers num="4.2m"/>
        <vers num="5.0"/>
        <vers num="5.0.148.0"/>
        <vers num="5.0.148.2"/>
        <vers num="5.1"/>
        <vers num="5.1.151.0"/>
        <vers num="5.1.152.0"/>
        <vers num="5.1.160.0"/>
        <vers num="5.2"/>
        <vers num="5.2.157.0"/>
        <vers num="5.2.169.0"/>
        <vers num="6.0"/>
        <vers num="6.0.182.0"/>
        <vers num="6.0.188.0"/>
        <vers num="6.0.196.0"/>
        <vers num="6.0.199.0"/>
        <vers num="6.0.199.4"/>
        <vers num="7.0"/>
        <vers num="7.0.98.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0369" published="2012-02-29" name="CVE-2012-0369" modified="2012-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Wireless LAN Controller (WLC) devices with software 6.0 and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allow remote attackers to cause a denial of service (device reload) via a sequence of IPv6 packets, aka Bug ID CSCtt07949.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-wlc" source="CISCO" adv="1">20120229 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="2000_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2100_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2106_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2112_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2125_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2500_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2504_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="4100_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="4400_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="4402_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="4404_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="5508_wireless_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="wireless_lan_controller_software">
        <vers num="6.0"/>
        <vers num="6.0.182.0"/>
        <vers num="6.0.188.0"/>
        <vers num="6.0.196.0"/>
        <vers num="6.0.199.0"/>
        <vers num="6.0.199.4"/>
        <vers num="7.0"/>
        <vers num="7.0.98.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0370" published="2012-02-29" name="CVE-2012-0370" modified="2012-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0 and 7.1 before 7.1.91.0, when WebAuth is enabled, allow remote attackers to cause a denial of service (device reload) via a sequence of (1) HTTP or (2) HTTPS packets, aka Bug ID CSCtt47435.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-wlc" source="CISCO" adv="1">20120229 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="2000_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2100_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2106_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2112_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2125_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2500_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2504_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="4100_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="4400_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="4402_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="4404_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="5508_wireless_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="wireless_lan_controller_software">
        <vers num="4.0"/>
        <vers num="4.0.108"/>
        <vers num="4.0.155.0"/>
        <vers num="4.0.155.5"/>
        <vers num="4.0.179.11"/>
        <vers num="4.0.179.8"/>
        <vers num="4.0.196"/>
        <vers num="4.0.206.0"/>
        <vers num="4.0.217.0"/>
        <vers num="4.0.219.0"/>
        <vers num="4.1"/>
        <vers num="4.1.171.0"/>
        <vers num="4.1.181.0"/>
        <vers num="4.1.185.0"/>
        <vers num="4.1m"/>
        <vers num="4.2"/>
        <vers num="4.2.112.0"/>
        <vers num="4.2.117.0"/>
        <vers num="4.2.130.0"/>
        <vers num="4.2.173.0"/>
        <vers num="4.2.174.0"/>
        <vers num="4.2.176.0"/>
        <vers num="4.2.182.0"/>
        <vers num="4.2.61.0"/>
        <vers num="4.2.99.0"/>
        <vers num="4.2m"/>
        <vers num="5.0"/>
        <vers num="5.0.148.0"/>
        <vers num="5.0.148.2"/>
        <vers num="5.1"/>
        <vers num="5.1.151.0"/>
        <vers num="5.1.152.0"/>
        <vers num="5.1.160.0"/>
        <vers num="5.2"/>
        <vers num="5.2.157.0"/>
        <vers num="5.2.169.0"/>
        <vers num="6.0"/>
        <vers num="6.0.182.0"/>
        <vers num="6.0.188.0"/>
        <vers num="6.0.196.0"/>
        <vers num="6.0.199.0"/>
        <vers num="6.0.199.4"/>
        <vers num="7.0"/>
        <vers num="7.0.98.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0371" published="2012-02-29" name="CVE-2012-0371" modified="2012-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.4, when CPU-based ACLs are enabled, allow remote attackers to read or modify the configuration via unspecified vectors, aka Bug ID CSCtu56709.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-wlc" source="CISCO" adv="1">20120229 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="2000_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2100_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2106_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2112_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2125_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2500_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="2504_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="4100_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="4400_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="4402_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="4404_wireless_lan_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="5508_wireless_controller">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="wireless_lan_controller_software">
        <vers num="4.0"/>
        <vers num="4.0.108"/>
        <vers num="4.0.155.0"/>
        <vers num="4.0.155.5"/>
        <vers num="4.0.179.11"/>
        <vers num="4.0.179.8"/>
        <vers num="4.0.196"/>
        <vers num="4.0.206.0"/>
        <vers num="4.0.217.0"/>
        <vers num="4.0.219.0"/>
        <vers num="4.1"/>
        <vers num="4.1.171.0"/>
        <vers num="4.1.181.0"/>
        <vers num="4.1.185.0"/>
        <vers num="4.1m"/>
        <vers num="4.2"/>
        <vers num="4.2.112.0"/>
        <vers num="4.2.117.0"/>
        <vers num="4.2.130.0"/>
        <vers num="4.2.173.0"/>
        <vers num="4.2.174.0"/>
        <vers num="4.2.176.0"/>
        <vers num="4.2.182.0"/>
        <vers num="4.2.61.0"/>
        <vers num="4.2.99.0"/>
        <vers num="4.2m"/>
        <vers num="5.0"/>
        <vers num="5.0.148.0"/>
        <vers num="5.0.148.2"/>
        <vers num="5.1"/>
        <vers num="5.1.151.0"/>
        <vers num="5.1.152.0"/>
        <vers num="5.1.160.0"/>
        <vers num="5.2"/>
        <vers num="5.2.157.0"/>
        <vers num="5.2.169.0"/>
        <vers num="6.0"/>
        <vers num="6.0.182.0"/>
        <vers num="6.0.188.0"/>
        <vers num="6.0.196.0"/>
        <vers num="6.0.199.0"/>
        <vers num="6.0.199.4"/>
        <vers num="7.0"/>
        <vers num="7.0.98.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0376" published="2012-05-03" name="CVE-2012-0376" modified="2012-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The voice-sipstack component in Cisco Unified Communications Manager (CUCM) 8.5 allows remote attackers to cause a denial of service (core dump) via vectors involving SIP messages that arrive after an upgrade, aka Bug ID CSCtj87367.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/docs/voice_ip_comm/cucmbe/rel_notes/8_5_1/cucmbe-rel_notes-851.html" source="CONFIRM">http://www.cisco.com/en/US/docs/voice_ip_comm/cucmbe/rel_notes/8_5_1/cucmbe-rel_notes-851.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_communications_manager">
        <vers num="8.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0378" published="2012-05-03" name="CVE-2012-0378" modified="2012-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 allow remote attackers to cause a denial of service (connection limit exceeded) by triggering a large number of stale connections that result in an incorrect value for an MPF connection count, aka Bug ID CSCtv19854.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.cisco.com/web/software/280775065/89203/ASA-843-Interim-Release-Notes.html" source="CONFIRM">http://www.cisco.com/web/software/280775065/89203/ASA-843-Interim-Release-Notes.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_software">
        <vers num="8.0"/>
        <vers num="8.0(2)"/>
        <vers num="8.0(3)"/>
        <vers num="8.0(4)"/>
        <vers num="8.0(5)"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="8.0.5"/>
        <vers num="8.1"/>
        <vers num="8.2(1)"/>
        <vers num="8.2(2)"/>
        <vers num="8.2(3)"/>
        <vers num="8.2(3.9)"/>
        <vers num="8.2(4)"/>
        <vers num="8.2(4.1)"/>
        <vers num="8.2(4.4)"/>
        <vers num="8.2(5)"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2" edition="interim"/>
        <vers num="8.2.3"/>
        <vers num="8.3(1)"/>
        <vers num="8.3(2)"/>
        <vers num="8.3.1" edition="interim"/>
        <vers num="8.3.2"/>
        <vers num="8.4"/>
        <vers num="8.4(1)"/>
        <vers num="8.4(1.11)"/>
        <vers num="8.4(2)"/>
        <vers num="8.4(2.11)"/>
      </prod>
      <prod vendor="cisco" name="5500_series_adaptive_security_appliance">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0381" published="2012-03-29" name="CVE-2012-0381" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) by sending IKE UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCts38429.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74427" source="XF">ciscoios-ike-packet-dos(74427)</ref>
      <ref url="http://www.securitytracker.com/id?1026863" source="SECTRACK">1026863</ref>
      <ref url="http://www.securityfocus.com/bid/52757" source="BID">52757</ref>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-ike" source="CISCO" adv="1">20120328 Cisco IOS Internet Key Exchange Vulnerability</ref>
      <ref url="http://secunia.com/advisories/48607" source="SECUNIA">48607</ref>
      <ref url="http://secunia.com/advisories/48605" source="SECUNIA">48605</ref>
      <ref url="http://osvdb.org/80700" source="OSVDB">80700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2"/>
        <vers num="12.2(1)"/>
        <vers num="12.2(1)dx"/>
        <vers num="12.2(1)s"/>
        <vers num="12.2(1)t"/>
        <vers num="12.2(1)xa"/>
        <vers num="12.2(1)xd"/>
        <vers num="12.2(1)xd1"/>
        <vers num="12.2(1)xd3"/>
        <vers num="12.2(1)xd4"/>
        <vers num="12.2(1)xe"/>
        <vers num="12.2(1)xe2"/>
        <vers num="12.2(1)xe3"/>
        <vers num="12.2(1)xh"/>
        <vers num="12.2(1)xq"/>
        <vers num="12.2(1)xs"/>
        <vers num="12.2(1)xs1"/>
        <vers num="12.2(1.1)"/>
        <vers num="12.2(1.1)pi"/>
        <vers num="12.2(1.4)s"/>
        <vers num="12.2(10)da2"/>
        <vers num="12.2(10)da4"/>
        <vers num="12.2(10.5)s"/>
        <vers num="12.2(10g)"/>
        <vers num="12.2(11)bc3c"/>
        <vers num="12.2(11)ja"/>
        <vers num="12.2(11)ja1"/>
        <vers num="12.2(11)t"/>
        <vers num="12.2(11)t2"/>
        <vers num="12.2(11)t3"/>
        <vers num="12.2(11)t8"/>
        <vers num="12.2(11)t9"/>
        <vers num="12.2(11)yp1"/>
        <vers num="12.2(11)yu"/>
        <vers num="12.2(11)yv"/>
        <vers num="12.2(11)yx1"/>
        <vers num="12.2(11)yz2"/>
        <vers num="12.2(12)"/>
        <vers num="12.2(12)da3"/>
        <vers num="12.2(12)da8"/>
        <vers num="12.2(12)da9"/>
        <vers num="12.2(12.02)s"/>
        <vers num="12.2(12.02)t"/>
        <vers num="12.2(12.05)"/>
        <vers num="12.2(12.05)s"/>
        <vers num="12.2(12.05)t"/>
        <vers num="12.2(12b)"/>
        <vers num="12.2(12c)"/>
        <vers num="12.2(12g)"/>
        <vers num="12.2(12h)"/>
        <vers num="12.2(12i)"/>
        <vers num="12.2(12m)"/>
        <vers num="12.2(13)"/>
        <vers num="12.2(13)ja1"/>
        <vers num="12.2(13)mc1"/>
        <vers num="12.2(13)t"/>
        <vers num="12.2(13)t1"/>
        <vers num="12.2(13)t14"/>
        <vers num="12.2(13)t16"/>
        <vers num="12.2(13)t9"/>
        <vers num="12.2(13)zc"/>
        <vers num="12.2(13)zd"/>
        <vers num="12.2(13)zd3"/>
        <vers num="12.2(13)zd4"/>
        <vers num="12.2(13)ze"/>
        <vers num="12.2(13)zf"/>
        <vers num="12.2(13)zg"/>
        <vers num="12.2(13)zh"/>
        <vers num="12.2(13)zh3"/>
        <vers num="12.2(13)zh8"/>
        <vers num="12.2(13)zj"/>
        <vers num="12.2(13)zk"/>
        <vers num="12.2(13)zl"/>
        <vers num="12.2(13.03)b"/>
        <vers num="12.2(13a)"/>
        <vers num="12.2(13e)"/>
        <vers num="12.2(14)s"/>
        <vers num="12.2(14)s13"/>
        <vers num="12.2(14)s14"/>
        <vers num="12.2(14)s15"/>
        <vers num="12.2(14)su2"/>
        <vers num="12.2(14)sx1"/>
        <vers num="12.2(14)sy"/>
        <vers num="12.2(14)sy03"/>
        <vers num="12.2(14)sy1"/>
        <vers num="12.2(14)sz"/>
        <vers num="12.2(14)sz1"/>
        <vers num="12.2(14)sz2"/>
        <vers num="12.2(14)za"/>
        <vers num="12.2(14)za2"/>
        <vers num="12.2(14)za8"/>
        <vers num="12.2(14.5)"/>
        <vers num="12.2(14.5)t"/>
        <vers num="12.2(15)b"/>
        <vers num="12.2(15)bc"/>
        <vers num="12.2(15)bc1"/>
        <vers num="12.2(15)bc1f"/>
        <vers num="12.2(15)bc2f"/>
        <vers num="12.2(15)bc2h"/>
        <vers num="12.2(15)bc2i"/>
        <vers num="12.2(15)bx"/>
        <vers num="12.2(15)bz"/>
        <vers num="12.2(15)cx"/>
        <vers num="12.2(15)cz3"/>
        <vers num="12.2(15)jk2"/>
        <vers num="12.2(15)jk4"/>
        <vers num="12.2(15)jk5"/>
        <vers num="12.2(15)mc1"/>
        <vers num="12.2(15)mc2c"/>
        <vers num="12.2(15)mc2e"/>
        <vers num="12.2(15)sl1"/>
        <vers num="12.2(15)t"/>
        <vers num="12.2(15)t15"/>
        <vers num="12.2(15)t16"/>
        <vers num="12.2(15)t17"/>
        <vers num="12.2(15)t5"/>
        <vers num="12.2(15)t7"/>
        <vers num="12.2(15)t8"/>
        <vers num="12.2(15)t9"/>
        <vers num="12.2(15)xr"/>
        <vers num="12.2(15)xr2"/>
        <vers num="12.2(15)ys"/>
        <vers num="12.2(15)ys_1.2(1)"/>
        <vers num="12.2(15)zj"/>
        <vers num="12.2(15)zj1"/>
        <vers num="12.2(15)zj2"/>
        <vers num="12.2(15)zj3"/>
        <vers num="12.2(15)zk"/>
        <vers num="12.2(15)zl"/>
        <vers num="12.2(15)zl1"/>
        <vers num="12.2(15)zn"/>
        <vers num="12.2(15)zo"/>
        <vers num="12.2(15.1)s"/>
        <vers num="12.2(16)b"/>
        <vers num="12.2(16)b1"/>
        <vers num="12.2(16)bx"/>
        <vers num="12.2(16.1)b"/>
        <vers num="12.2(16.5)s"/>
        <vers num="12.2(16f)"/>
        <vers num="12.2(17)"/>
        <vers num="12.2(17)a"/>
        <vers num="12.2(17)zd3"/>
        <vers num="12.2(17a)"/>
        <vers num="12.2(17a)sxa"/>
        <vers num="12.2(17b)sxa"/>
        <vers num="12.2(17d)"/>
        <vers num="12.2(17d)sx"/>
        <vers num="12.2(17d)sxb"/>
        <vers num="12.2(17d)sxb10"/>
        <vers num="12.2(17d)sxb7"/>
        <vers num="12.2(17d)sxb8"/>
        <vers num="12.2(17f)"/>
        <vers num="12.2(18)ew"/>
        <vers num="12.2(18)ew2"/>
        <vers num="12.2(18)ew3"/>
        <vers num="12.2(18)ew5"/>
        <vers num="12.2(18)ewa"/>
        <vers num="12.2(18)s"/>
        <vers num="12.2(18)s10"/>
        <vers num="12.2(18)s6"/>
        <vers num="12.2(18)s8"/>
        <vers num="12.2(18)s9"/>
        <vers num="12.2(18)se"/>
        <vers num="12.2(18)so4"/>
        <vers num="12.2(18)sv"/>
        <vers num="12.2(18)sv3"/>
        <vers num="12.2(18)sw"/>
        <vers num="12.2(18)sxd1"/>
        <vers num="12.2(18)sxd4"/>
        <vers num="12.2(18)sxd5"/>
        <vers num="12.2(18)sxd6"/>
        <vers num="12.2(18)sxd7"/>
        <vers num="12.2(18)sxe"/>
        <vers num="12.2(18)sxe1"/>
        <vers num="12.2(18)sxe3"/>
        <vers num="12.2(18)sxf"/>
        <vers num="12.2(18.2)"/>
        <vers num="12.2(19)"/>
        <vers num="12.2(19)b"/>
        <vers num="12.2(1b)"/>
        <vers num="12.2(1b)da1"/>
        <vers num="12.2(1d)"/>
        <vers num="12.2(2)b"/>
        <vers num="12.2(2)bx"/>
        <vers num="12.2(2)by"/>
        <vers num="12.2(2)by2"/>
        <vers num="12.2(2)dd3"/>
        <vers num="12.2(2)t"/>
        <vers num="12.2(2)t1"/>
        <vers num="12.2(2)t4"/>
        <vers num="12.2(2)xa"/>
        <vers num="12.2(2)xa1"/>
        <vers num="12.2(2)xa5"/>
        <vers num="12.2(2)xb"/>
        <vers num="12.2(2)xb11"/>
        <vers num="12.2(2)xb14"/>
        <vers num="12.2(2)xb15"/>
        <vers num="12.2(2)xb3"/>
        <vers num="12.2(2)xb4"/>
        <vers num="12.2(2)xc1"/>
        <vers num="12.2(2)xf"/>
        <vers num="12.2(2)xg"/>
        <vers num="12.2(2)xh"/>
        <vers num="12.2(2)xh2"/>
        <vers num="12.2(2)xh3"/>
        <vers num="12.2(2)xi"/>
        <vers num="12.2(2)xi1"/>
        <vers num="12.2(2)xi2"/>
        <vers num="12.2(2)xj"/>
        <vers num="12.2(2)xj1"/>
        <vers num="12.2(2)xk"/>
        <vers num="12.2(2)xk2"/>
        <vers num="12.2(2)xn"/>
        <vers num="12.2(2)xr"/>
        <vers num="12.2(2)xt"/>
        <vers num="12.2(2)xt3"/>
        <vers num="12.2(2)xu"/>
        <vers num="12.2(2)xu2"/>
        <vers num="12.2(2)yc"/>
        <vers num="12.2(2.2)t"/>
        <vers num="12.2(20)eu"/>
        <vers num="12.2(20)eu1"/>
        <vers num="12.2(20)eu2"/>
        <vers num="12.2(20)ew"/>
        <vers num="12.2(20)ew2"/>
        <vers num="12.2(20)ew3"/>
        <vers num="12.2(20)ewa"/>
        <vers num="12.2(20)ewa2"/>
        <vers num="12.2(20)ewa3"/>
        <vers num="12.2(20)s"/>
        <vers num="12.2(20)s1"/>
        <vers num="12.2(20)s2"/>
        <vers num="12.2(20)s4"/>
        <vers num="12.2(20)s7"/>
        <vers num="12.2(20)s8"/>
        <vers num="12.2(20)s9"/>
        <vers num="12.2(20)se3"/>
        <vers num="12.2(21)"/>
        <vers num="12.2(21a)"/>
        <vers num="12.2(21b)"/>
        <vers num="12.2(22)ea6"/>
        <vers num="12.2(22)s"/>
        <vers num="12.2(22)s2"/>
        <vers num="12.2(22)sv1"/>
        <vers num="12.2(23)"/>
        <vers num="12.2(23)sv1"/>
        <vers num="12.2(23)sw"/>
        <vers num="12.2(23.6)"/>
        <vers num="12.2(23a)"/>
        <vers num="12.2(23f)"/>
        <vers num="12.2(24)"/>
        <vers num="12.2(24)sv"/>
        <vers num="12.2(24)sv1"/>
        <vers num="12.2(25)ewa"/>
        <vers num="12.2(25)ewa1"/>
        <vers num="12.2(25)ewa3"/>
        <vers num="12.2(25)ewa4"/>
        <vers num="12.2(25)ex"/>
        <vers num="12.2(25)ey"/>
        <vers num="12.2(25)ey2"/>
        <vers num="12.2(25)ey3"/>
        <vers num="12.2(25)ez"/>
        <vers num="12.2(25)ez1"/>
        <vers num="12.2(25)fx"/>
        <vers num="12.2(25)fy"/>
        <vers num="12.2(25)s"/>
        <vers num="12.2(25)s1"/>
        <vers num="12.2(25)s3"/>
        <vers num="12.2(25)s4"/>
        <vers num="12.2(25)s6"/>
        <vers num="12.2(25)se"/>
        <vers num="12.2(25)seb"/>
        <vers num="12.2(25)seb2"/>
        <vers num="12.2(25)seb3"/>
        <vers num="12.2(25)seb4"/>
        <vers num="12.2(25)sec1"/>
        <vers num="12.2(25)sec2"/>
        <vers num="12.2(25)sed"/>
        <vers num="12.2(25)sg"/>
        <vers num="12.2(25)sv2"/>
        <vers num="12.2(25)sw"/>
        <vers num="12.2(25)sw3a"/>
        <vers num="12.2(25)sw4"/>
        <vers num="12.2(25)sw4a"/>
        <vers num="12.2(26)sv"/>
        <vers num="12.2(26)sv1"/>
        <vers num="12.2(26b)"/>
        <vers num="12.2(27)sbc"/>
        <vers num="12.2(27)sv1"/>
        <vers num="12.2(27b)"/>
        <vers num="12.2(28)"/>
        <vers num="12.2(28c)"/>
        <vers num="12.2(29a)"/>
        <vers num="12.2(3)"/>
        <vers num="12.2(3.4)bp"/>
        <vers num="12.2(30)s1"/>
        <vers num="12.2(31)"/>
        <vers num="12.2(3d)"/>
        <vers num="12.2(4)"/>
        <vers num="12.2(4)b"/>
        <vers num="12.2(4)b1"/>
        <vers num="12.2(4)b2"/>
        <vers num="12.2(4)b3"/>
        <vers num="12.2(4)b4"/>
        <vers num="12.2(4)bc1"/>
        <vers num="12.2(4)bc1a"/>
        <vers num="12.2(4)bx"/>
        <vers num="12.2(4)ja"/>
        <vers num="12.2(4)ja1"/>
        <vers num="12.2(4)mb12"/>
        <vers num="12.2(4)mb13b"/>
        <vers num="12.2(4)mb13c"/>
        <vers num="12.2(4)mb3"/>
        <vers num="12.2(4)mx"/>
        <vers num="12.2(4)mx1"/>
        <vers num="12.2(4)t"/>
        <vers num="12.2(4)t1"/>
        <vers num="12.2(4)t3"/>
        <vers num="12.2(4)t6"/>
        <vers num="12.2(4)xl"/>
        <vers num="12.2(4)xl4"/>
        <vers num="12.2(4)xm"/>
        <vers num="12.2(4)xm2"/>
        <vers num="12.2(4)xr"/>
        <vers num="12.2(4)xw"/>
        <vers num="12.2(4)xw1"/>
        <vers num="12.2(4)ya"/>
        <vers num="12.2(4)ya1"/>
        <vers num="12.2(4)ya10"/>
        <vers num="12.2(4)ya11"/>
        <vers num="12.2(4)ya7"/>
        <vers num="12.2(4)ya8"/>
        <vers num="12.2(4)ya9"/>
        <vers num="12.2(4)yb"/>
        <vers num="12.2(5)"/>
        <vers num="12.2(5)ca1"/>
        <vers num="12.2(5d)"/>
        <vers num="12.2(6.8)t0a"/>
        <vers num="12.2(6.8)t1a"/>
        <vers num="12.2(6.8a)"/>
        <vers num="12.2(6c)"/>
        <vers num="12.2(7)"/>
        <vers num="12.2(7)da"/>
        <vers num="12.2(7.4)s"/>
        <vers num="12.2(7a)"/>
        <vers num="12.2(7b)"/>
        <vers num="12.2(7c)"/>
        <vers num="12.2(8)bc1"/>
        <vers num="12.2(8)ja"/>
        <vers num="12.2(8)t"/>
        <vers num="12.2(8)t10"/>
        <vers num="12.2(8)tpc10a"/>
        <vers num="12.2(8)yd"/>
        <vers num="12.2(8)yw2"/>
        <vers num="12.2(8)yw3"/>
        <vers num="12.2(8)yy"/>
        <vers num="12.2(8)yy3"/>
        <vers num="12.2(8)zb7"/>
        <vers num="12.2(9)s"/>
        <vers num="12.2(9.4)da"/>
        <vers num="12.2b"/>
        <vers num="12.2bc"/>
        <vers num="12.2bw"/>
        <vers num="12.2bx"/>
        <vers num="12.2by"/>
        <vers num="12.2bz"/>
        <vers num="12.2ca"/>
        <vers num="12.2cx"/>
        <vers num="12.2cy"/>
        <vers num="12.2cz"/>
        <vers num="12.2da"/>
        <vers num="12.2dd"/>
        <vers num="12.2dx"/>
        <vers num="12.2e"/>
        <vers num="12.2eu"/>
        <vers num="12.2ew"/>
        <vers num="12.2ewa"/>
        <vers num="12.2ex"/>
        <vers num="12.2ey"/>
        <vers num="12.2ez"/>
        <vers num="12.2f"/>
        <vers num="12.2fx"/>
        <vers num="12.2fy"/>
        <vers num="12.2ja"/>
        <vers num="12.2jk"/>
        <vers num="12.2jx"/>
        <vers num="12.2mb"/>
        <vers num="12.2mc"/>
        <vers num="12.2mx"/>
        <vers num="12.2n"/>
        <vers num="12.2pb"/>
        <vers num="12.2pi"/>
        <vers num="12.2s"/>
        <vers num="12.2sa"/>
        <vers num="12.2sbc"/>
        <vers num="12.2se"/>
        <vers num="12.2sea"/>
        <vers num="12.2seb"/>
        <vers num="12.2sec"/>
        <vers num="12.2sg"/>
        <vers num="12.2sh"/>
        <vers num="12.2so"/>
        <vers num="12.2su"/>
        <vers num="12.2sv"/>
        <vers num="12.2sw"/>
        <vers num="12.2sx"/>
        <vers num="12.2sxa"/>
        <vers num="12.2sxb"/>
        <vers num="12.2sxd"/>
        <vers num="12.2sxe"/>
        <vers num="12.2sxf"/>
        <vers num="12.2sy"/>
        <vers num="12.2sz"/>
        <vers num="12.2t"/>
        <vers num="12.2tpc"/>
        <vers num="12.2x"/>
        <vers num="12.2xa"/>
        <vers num="12.2xb"/>
        <vers num="12.2xc"/>
        <vers num="12.2xd"/>
        <vers num="12.2xe"/>
        <vers num="12.2xf"/>
        <vers num="12.2xg"/>
        <vers num="12.2xh"/>
        <vers num="12.2xi"/>
        <vers num="12.2xj"/>
        <vers num="12.2xk"/>
        <vers num="12.2xl"/>
        <vers num="12.2xm"/>
        <vers num="12.2xn"/>
        <vers num="12.2xq"/>
        <vers num="12.2xr"/>
        <vers num="12.2xs"/>
        <vers num="12.2xt"/>
        <vers num="12.2xu"/>
        <vers num="12.2xv"/>
        <vers num="12.2xw"/>
        <vers num="12.2xz"/>
        <vers num="12.2ya"/>
        <vers num="12.2yb"/>
        <vers num="12.2yc"/>
        <vers num="12.2yd"/>
        <vers num="12.2ye"/>
        <vers num="12.2yf"/>
        <vers num="12.2yg"/>
        <vers num="12.2yh"/>
        <vers num="12.2yj"/>
        <vers num="12.2yk"/>
        <vers num="12.2yl"/>
        <vers num="12.2ym"/>
        <vers num="12.2yn"/>
        <vers num="12.2yo"/>
        <vers num="12.2yp"/>
        <vers num="12.2yq"/>
        <vers num="12.2yr"/>
        <vers num="12.2ys"/>
        <vers num="12.2yt"/>
        <vers num="12.2yu"/>
        <vers num="12.2yv"/>
        <vers num="12.2yw"/>
        <vers num="12.2yx"/>
        <vers num="12.2yy"/>
        <vers num="12.2yz"/>
        <vers num="12.2za"/>
        <vers num="12.2zb"/>
        <vers num="12.2zd"/>
        <vers num="12.2ze"/>
        <vers num="12.2zf"/>
        <vers num="12.2zg"/>
        <vers num="12.2zh"/>
        <vers num="12.2zi"/>
        <vers num="12.2zj"/>
        <vers num="12.2zk"/>
        <vers num="12.2zl"/>
        <vers num="12.2zm"/>
        <vers num="12.2zn"/>
        <vers num="12.2zo"/>
        <vers num="12.2zp"/>
        <vers num="12.2zq"/>
        <vers num="12.2zu"/>
        <vers num="12.2zx"/>
        <vers num="12.2zy"/>
        <vers num="12.2zya"/>
        <vers num="12.3"/>
        <vers num="12.3(10)"/>
        <vers num="12.3(10c)"/>
        <vers num="12.3(10d)"/>
        <vers num="12.3(10e)"/>
        <vers num="12.3(11)"/>
        <vers num="12.3(11)t"/>
        <vers num="12.3(11)t4"/>
        <vers num="12.3(11)t5"/>
        <vers num="12.3(11)t6"/>
        <vers num="12.3(11)t8"/>
        <vers num="12.3(11)t9"/>
        <vers num="12.3(11)xl"/>
        <vers num="12.3(11)xl3"/>
        <vers num="12.3(11)yf"/>
        <vers num="12.3(11)yf2"/>
        <vers num="12.3(11)yf3"/>
        <vers num="12.3(11)yf4"/>
        <vers num="12.3(11)yj"/>
        <vers num="12.3(11)yk"/>
        <vers num="12.3(11)yk1"/>
        <vers num="12.3(11)yk2"/>
        <vers num="12.3(11)yl"/>
        <vers num="12.3(11)yn"/>
        <vers num="12.3(11)yr"/>
        <vers num="12.3(11)ys"/>
        <vers num="12.3(11)ys1"/>
        <vers num="12.3(11)yw"/>
        <vers num="12.3(12)"/>
        <vers num="12.3(12b)"/>
        <vers num="12.3(12e)"/>
        <vers num="12.3(13)"/>
        <vers num="12.3(13a)"/>
        <vers num="12.3(13a)bc"/>
        <vers num="12.3(13a)bc1"/>
        <vers num="12.3(13b)"/>
        <vers num="12.3(14)t"/>
        <vers num="12.3(14)t2"/>
        <vers num="12.3(14)t4"/>
        <vers num="12.3(14)t5"/>
        <vers num="12.3(14)ym4"/>
        <vers num="12.3(14)yq"/>
        <vers num="12.3(14)yq1"/>
        <vers num="12.3(14)yq3"/>
        <vers num="12.3(14)yq4"/>
        <vers num="12.3(14)yt"/>
        <vers num="12.3(14)yt1"/>
        <vers num="12.3(14)yu"/>
        <vers num="12.3(14)yu1"/>
        <vers num="12.3(15)"/>
        <vers num="12.3(15b)"/>
        <vers num="12.3(16)"/>
        <vers num="12.3(1a)"/>
        <vers num="12.3(2)ja"/>
        <vers num="12.3(2)ja5"/>
        <vers num="12.3(2)jk"/>
        <vers num="12.3(2)jk1"/>
        <vers num="12.3(2)t3"/>
        <vers num="12.3(2)t8"/>
        <vers num="12.3(2)xa4"/>
        <vers num="12.3(2)xa5"/>
        <vers num="12.3(2)xc1"/>
        <vers num="12.3(2)xc2"/>
        <vers num="12.3(2)xc3"/>
        <vers num="12.3(2)xc4"/>
        <vers num="12.3(2)xe3"/>
        <vers num="12.3(2)xe4"/>
        <vers num="12.3(3e)"/>
        <vers num="12.3(3h)"/>
        <vers num="12.3(3i)"/>
        <vers num="12.3(4)eo1"/>
        <vers num="12.3(4)ja"/>
        <vers num="12.3(4)ja1"/>
        <vers num="12.3(4)t"/>
        <vers num="12.3(4)t1"/>
        <vers num="12.3(4)t2"/>
        <vers num="12.3(4)t3"/>
        <vers num="12.3(4)t4"/>
        <vers num="12.3(4)t8"/>
        <vers num="12.3(4)tpc11a"/>
        <vers num="12.3(4)xd"/>
        <vers num="12.3(4)xd1"/>
        <vers num="12.3(4)xd2"/>
        <vers num="12.3(4)xe4"/>
        <vers num="12.3(4)xg1"/>
        <vers num="12.3(4)xg2"/>
        <vers num="12.3(4)xg4"/>
        <vers num="12.3(4)xg5"/>
        <vers num="12.3(4)xh"/>
        <vers num="12.3(4)xk"/>
        <vers num="12.3(4)xk1"/>
        <vers num="12.3(4)xk3"/>
        <vers num="12.3(4)xk4"/>
        <vers num="12.3(4)xq"/>
        <vers num="12.3(4)xq1"/>
        <vers num="12.3(5)"/>
        <vers num="12.3(5)b1"/>
        <vers num="12.3(5a)"/>
        <vers num="12.3(5a)b"/>
        <vers num="12.3(5a)b2"/>
        <vers num="12.3(5a)b5"/>
        <vers num="12.3(5b)"/>
        <vers num="12.3(5c)"/>
        <vers num="12.3(5e)"/>
        <vers num="12.3(5f)"/>
        <vers num="12.3(6)"/>
        <vers num="12.3(6a)"/>
        <vers num="12.3(6d)"/>
        <vers num="12.3(6e)"/>
        <vers num="12.3(6f)"/>
        <vers num="12.3(7)ja"/>
        <vers num="12.3(7)ja1"/>
        <vers num="12.3(7)jx"/>
        <vers num="12.3(7)t"/>
        <vers num="12.3(7)t10"/>
        <vers num="12.3(7)t12"/>
        <vers num="12.3(7)t4"/>
        <vers num="12.3(7)t8"/>
        <vers num="12.3(7)t9"/>
        <vers num="12.3(7)xi3"/>
        <vers num="12.3(7)xi4"/>
        <vers num="12.3(7)xi7"/>
        <vers num="12.3(7)xr3"/>
        <vers num="12.3(7)xr4"/>
        <vers num="12.3(7)xr6"/>
        <vers num="12.3(7.7)"/>
        <vers num="12.3(8)ja"/>
        <vers num="12.3(8)ja1"/>
        <vers num="12.3(8)t11"/>
        <vers num="12.3(8)t4"/>
        <vers num="12.3(8)t7"/>
        <vers num="12.3(8)t8"/>
        <vers num="12.3(8)t9"/>
        <vers num="12.3(8)xu2"/>
        <vers num="12.3(8)xy4"/>
        <vers num="12.3(8)xy5"/>
        <vers num="12.3(8)xy6"/>
        <vers num="12.3(8)ya1"/>
        <vers num="12.3(8)yd"/>
        <vers num="12.3(8)yf"/>
        <vers num="12.3(8)yg"/>
        <vers num="12.3(8)yg1"/>
        <vers num="12.3(8)yg2"/>
        <vers num="12.3(8)yg3"/>
        <vers num="12.3(8)yh"/>
        <vers num="12.3(8)yi"/>
        <vers num="12.3(8)yi1"/>
        <vers num="12.3(8)yi3"/>
        <vers num="12.3(9)"/>
        <vers num="12.3(9a)bc"/>
        <vers num="12.3(9a)bc2"/>
        <vers num="12.3(9a)bc6"/>
        <vers num="12.3(9a)bc7"/>
        <vers num="12.3(9d)"/>
        <vers num="12.3(9e)"/>
        <vers num="12.3b"/>
        <vers num="12.3bc"/>
        <vers num="12.3bw"/>
        <vers num="12.3j"/>
        <vers num="12.3ja"/>
        <vers num="12.3jea"/>
        <vers num="12.3jeb"/>
        <vers num="12.3jec"/>
        <vers num="12.3jk"/>
        <vers num="12.3jx"/>
        <vers num="12.3t"/>
        <vers num="12.3tpc"/>
        <vers num="12.3xa"/>
        <vers num="12.3xb"/>
        <vers num="12.3xc"/>
        <vers num="12.3xd"/>
        <vers num="12.3xe"/>
        <vers num="12.3xf"/>
        <vers num="12.3xg"/>
        <vers num="12.3xh"/>
        <vers num="12.3xi"/>
        <vers num="12.3xj"/>
        <vers num="12.3xk"/>
        <vers num="12.3xl"/>
        <vers num="12.3xm"/>
        <vers num="12.3xn"/>
        <vers num="12.3xq"/>
        <vers num="12.3xr"/>
        <vers num="12.3xs"/>
        <vers num="12.3xt"/>
        <vers num="12.3xu"/>
        <vers num="12.3xv"/>
        <vers num="12.3xw"/>
        <vers num="12.3xx"/>
        <vers num="12.3xy"/>
        <vers num="12.3xz"/>
        <vers num="12.3ya"/>
        <vers num="12.3yb"/>
        <vers num="12.3yc"/>
        <vers num="12.3yd"/>
        <vers num="12.3ye"/>
        <vers num="12.3yf"/>
        <vers num="12.3yg"/>
        <vers num="12.3yh"/>
        <vers num="12.3yi"/>
        <vers num="12.3yj"/>
        <vers num="12.3yk"/>
        <vers num="12.3yl"/>
        <vers num="12.3ym"/>
        <vers num="12.3yn"/>
        <vers num="12.3yq"/>
        <vers num="12.3yr"/>
        <vers num="12.3ys"/>
        <vers num="12.3yt"/>
        <vers num="12.3yu"/>
        <vers num="12.3yw"/>
        <vers num="12.3yx"/>
        <vers num="12.3yz"/>
        <vers num="12.4"/>
        <vers num="12.4(1)"/>
        <vers num="12.4(1b)"/>
        <vers num="12.4(1c)"/>
        <vers num="12.4(2)mr"/>
        <vers num="12.4(2)mr1"/>
        <vers num="12.4(2)t"/>
        <vers num="12.4(2)t1"/>
        <vers num="12.4(2)t2"/>
        <vers num="12.4(2)t3"/>
        <vers num="12.4(2)t4"/>
        <vers num="12.4(2)xa"/>
        <vers num="12.4(2)xb"/>
        <vers num="12.4(2)xb2"/>
        <vers num="12.4(23)"/>
        <vers num="12.4(3)"/>
        <vers num="12.4(3)t2"/>
        <vers num="12.4(3a)"/>
        <vers num="12.4(3b)"/>
        <vers num="12.4(3d)"/>
        <vers num="12.4(4)mr"/>
        <vers num="12.4(4)t"/>
        <vers num="12.4(4)t2"/>
        <vers num="12.4(5)"/>
        <vers num="12.4(5b)"/>
        <vers num="12.4(6)t"/>
        <vers num="12.4(6)t1"/>
        <vers num="12.4(7)"/>
        <vers num="12.4(7a)"/>
        <vers num="12.4(8)"/>
        <vers num="12.4(9)t"/>
        <vers num="12.4ja"/>
        <vers num="12.4jda"/>
        <vers num="12.4jk"/>
        <vers num="12.4jl"/>
        <vers num="12.4jma"/>
        <vers num="12.4jmb"/>
        <vers num="12.4jx"/>
        <vers num="12.4md"/>
        <vers num="12.4mr"/>
        <vers num="12.4sw"/>
        <vers num="12.4t"/>
        <vers num="12.4xa"/>
        <vers num="12.4xb"/>
        <vers num="12.4xc"/>
        <vers num="12.4xd"/>
        <vers num="12.4xe"/>
        <vers num="12.4xf"/>
        <vers num="12.4xg"/>
        <vers num="12.4xj"/>
        <vers num="12.4xk"/>
        <vers num="12.4xl"/>
        <vers num="12.4xm"/>
        <vers num="12.4xn"/>
        <vers num="12.4xp"/>
        <vers num="12.4xt"/>
        <vers num="12.4xv"/>
        <vers num="12.4xw"/>
        <vers num="15.0"/>
        <vers num="15.0(1)s1"/>
        <vers num="15.0(1)s2"/>
        <vers num="15.0m"/>
        <vers num="15.0mr"/>
        <vers num="15.0mra"/>
        <vers num="15.0s"/>
        <vers num="15.0sa"/>
        <vers num="15.0sg"/>
        <vers num="15.0xa"/>
        <vers num="15.0xo"/>
        <vers num="15.1"/>
        <vers num="15.1(1)xb1"/>
        <vers num="15.1(2)t"/>
        <vers num="15.1(3)t"/>
        <vers num="15.1(4)m"/>
        <vers num="15.1(4)m1"/>
        <vers num="15.1ey"/>
        <vers num="15.1gc"/>
        <vers num="15.1m"/>
        <vers num="15.1s"/>
        <vers num="15.1t"/>
        <vers num="15.1xb"/>
        <vers num="15.2"/>
      </prod>
      <prod vendor="cisco" name="ios_xe">
        <vers num="2.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.3"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.1t"/>
        <vers num="2.3.2"/>
        <vers num="2.4"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="3.1.0s"/>
        <vers num="3.1.0sg"/>
        <vers num="3.1.1s"/>
        <vers num="3.1.1sg"/>
        <vers num="3.1.2s"/>
        <vers num="3.1.3s"/>
        <vers num="3.1.4s"/>
        <vers num="3.2.0s"/>
        <vers num="3.2.0sg"/>
        <vers num="3.2.1s"/>
        <vers num="3.2.1sg"/>
        <vers num="3.2.2s"/>
        <vers num="3.3.0s"/>
        <vers num="3.3.1s"/>
        <vers num="3.3.2s"/>
        <vers num="3.3.3s"/>
        <vers num="3.4.0s"/>
        <vers num="3.4.1s"/>
        <vers num="3.5.0s"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0382" published="2012-03-29" name="CVE-2012-0382" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1.xSG and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) via encapsulated IGMP data in an MSDP packet, aka Bug ID CSCtr28857.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74431" source="XF">ciscoios-msdp-dos(74431)</ref>
      <ref url="http://www.securitytracker.com/id?1026868" source="SECTRACK">1026868</ref>
      <ref url="http://www.securityfocus.com/bid/52759" source="BID">52759</ref>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-msdp" source="CISCO" adv="1">20120328 Cisco IOS Software Multicast Source Discovery Protocol Vulnerability</ref>
      <ref url="http://secunia.com/advisories/48633" source="SECUNIA">48633</ref>
      <ref url="http://secunia.com/advisories/48630" source="SECUNIA">48630</ref>
      <ref url="http://osvdb.org/80693" source="OSVDB">80693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2"/>
        <vers num="12.2(1)"/>
        <vers num="12.2(1)dx"/>
        <vers num="12.2(1)s"/>
        <vers num="12.2(1)t"/>
        <vers num="12.2(1)xa"/>
        <vers num="12.2(1)xd"/>
        <vers num="12.2(1)xd1"/>
        <vers num="12.2(1)xd3"/>
        <vers num="12.2(1)xd4"/>
        <vers num="12.2(1)xe"/>
        <vers num="12.2(1)xe2"/>
        <vers num="12.2(1)xe3"/>
        <vers num="12.2(1)xh"/>
        <vers num="12.2(1)xq"/>
        <vers num="12.2(1)xs"/>
        <vers num="12.2(1)xs1"/>
        <vers num="12.2(1.1)"/>
        <vers num="12.2(1.1)pi"/>
        <vers num="12.2(1.4)s"/>
        <vers num="12.2(10)da2"/>
        <vers num="12.2(10)da4"/>
        <vers num="12.2(10.5)s"/>
        <vers num="12.2(10g)"/>
        <vers num="12.2(11)bc3c"/>
        <vers num="12.2(11)ja"/>
        <vers num="12.2(11)ja1"/>
        <vers num="12.2(11)t"/>
        <vers num="12.2(11)t2"/>
        <vers num="12.2(11)t3"/>
        <vers num="12.2(11)t8"/>
        <vers num="12.2(11)t9"/>
        <vers num="12.2(11)yp1"/>
        <vers num="12.2(11)yu"/>
        <vers num="12.2(11)yv"/>
        <vers num="12.2(11)yx1"/>
        <vers num="12.2(11)yz2"/>
        <vers num="12.2(12)"/>
        <vers num="12.2(12)da3"/>
        <vers num="12.2(12)da8"/>
        <vers num="12.2(12)da9"/>
        <vers num="12.2(12.02)s"/>
        <vers num="12.2(12.02)t"/>
        <vers num="12.2(12.05)"/>
        <vers num="12.2(12.05)s"/>
        <vers num="12.2(12.05)t"/>
        <vers num="12.2(12b)"/>
        <vers num="12.2(12c)"/>
        <vers num="12.2(12g)"/>
        <vers num="12.2(12h)"/>
        <vers num="12.2(12i)"/>
        <vers num="12.2(12m)"/>
        <vers num="12.2(13)"/>
        <vers num="12.2(13)ja1"/>
        <vers num="12.2(13)mc1"/>
        <vers num="12.2(13)t"/>
        <vers num="12.2(13)t1"/>
        <vers num="12.2(13)t14"/>
        <vers num="12.2(13)t16"/>
        <vers num="12.2(13)t9"/>
        <vers num="12.2(13)zc"/>
        <vers num="12.2(13)zd"/>
        <vers num="12.2(13)zd3"/>
        <vers num="12.2(13)zd4"/>
        <vers num="12.2(13)ze"/>
        <vers num="12.2(13)zf"/>
        <vers num="12.2(13)zg"/>
        <vers num="12.2(13)zh"/>
        <vers num="12.2(13)zh3"/>
        <vers num="12.2(13)zh8"/>
        <vers num="12.2(13)zj"/>
        <vers num="12.2(13)zk"/>
        <vers num="12.2(13)zl"/>
        <vers num="12.2(13.03)b"/>
        <vers num="12.2(13a)"/>
        <vers num="12.2(13e)"/>
        <vers num="12.2(14)s"/>
        <vers num="12.2(14)s13"/>
        <vers num="12.2(14)s14"/>
        <vers num="12.2(14)s15"/>
        <vers num="12.2(14)su2"/>
        <vers num="12.2(14)sx1"/>
        <vers num="12.2(14)sy"/>
        <vers num="12.2(14)sy03"/>
        <vers num="12.2(14)sy1"/>
        <vers num="12.2(14)sz"/>
        <vers num="12.2(14)sz1"/>
        <vers num="12.2(14)sz2"/>
        <vers num="12.2(14)za"/>
        <vers num="12.2(14)za2"/>
        <vers num="12.2(14)za8"/>
        <vers num="12.2(14.5)"/>
        <vers num="12.2(14.5)t"/>
        <vers num="12.2(15)b"/>
        <vers num="12.2(15)bc"/>
        <vers num="12.2(15)bc1"/>
        <vers num="12.2(15)bc1f"/>
        <vers num="12.2(15)bc2f"/>
        <vers num="12.2(15)bc2h"/>
        <vers num="12.2(15)bc2i"/>
        <vers num="12.2(15)bx"/>
        <vers num="12.2(15)bz"/>
        <vers num="12.2(15)cx"/>
        <vers num="12.2(15)cz3"/>
        <vers num="12.2(15)jk2"/>
        <vers num="12.2(15)jk4"/>
        <vers num="12.2(15)jk5"/>
        <vers num="12.2(15)mc1"/>
        <vers num="12.2(15)mc2c"/>
        <vers num="12.2(15)mc2e"/>
        <vers num="12.2(15)sl1"/>
        <vers num="12.2(15)t"/>
        <vers num="12.2(15)t15"/>
        <vers num="12.2(15)t16"/>
        <vers num="12.2(15)t17"/>
        <vers num="12.2(15)t5"/>
        <vers num="12.2(15)t7"/>
        <vers num="12.2(15)t8"/>
        <vers num="12.2(15)t9"/>
        <vers num="12.2(15)xr"/>
        <vers num="12.2(15)xr2"/>
        <vers num="12.2(15)ys"/>
        <vers num="12.2(15)ys_1.2(1)"/>
        <vers num="12.2(15)zj"/>
        <vers num="12.2(15)zj1"/>
        <vers num="12.2(15)zj2"/>
        <vers num="12.2(15)zj3"/>
        <vers num="12.2(15)zk"/>
        <vers num="12.2(15)zl"/>
        <vers num="12.2(15)zl1"/>
        <vers num="12.2(15)zn"/>
        <vers num="12.2(15)zo"/>
        <vers num="12.2(15.1)s"/>
        <vers num="12.2(16)b"/>
        <vers num="12.2(16)b1"/>
        <vers num="12.2(16)bx"/>
        <vers num="12.2(16.1)b"/>
        <vers num="12.2(16.5)s"/>
        <vers num="12.2(16f)"/>
        <vers num="12.2(17)"/>
        <vers num="12.2(17)a"/>
        <vers num="12.2(17)zd3"/>
        <vers num="12.2(17a)"/>
        <vers num="12.2(17a)sxa"/>
        <vers num="12.2(17b)sxa"/>
        <vers num="12.2(17d)"/>
        <vers num="12.2(17d)sx"/>
        <vers num="12.2(17d)sxb"/>
        <vers num="12.2(17d)sxb10"/>
        <vers num="12.2(17d)sxb7"/>
        <vers num="12.2(17d)sxb8"/>
        <vers num="12.2(17f)"/>
        <vers num="12.2(18)ew"/>
        <vers num="12.2(18)ew2"/>
        <vers num="12.2(18)ew3"/>
        <vers num="12.2(18)ew5"/>
        <vers num="12.2(18)ewa"/>
        <vers num="12.2(18)s"/>
        <vers num="12.2(18)s10"/>
        <vers num="12.2(18)s6"/>
        <vers num="12.2(18)s8"/>
        <vers num="12.2(18)s9"/>
        <vers num="12.2(18)se"/>
        <vers num="12.2(18)so4"/>
        <vers num="12.2(18)sv"/>
        <vers num="12.2(18)sv3"/>
        <vers num="12.2(18)sw"/>
        <vers num="12.2(18)sxd1"/>
        <vers num="12.2(18)sxd4"/>
        <vers num="12.2(18)sxd5"/>
        <vers num="12.2(18)sxd6"/>
        <vers num="12.2(18)sxd7"/>
        <vers num="12.2(18)sxe"/>
        <vers num="12.2(18)sxe1"/>
        <vers num="12.2(18)sxe3"/>
        <vers num="12.2(18)sxf"/>
        <vers num="12.2(18.2)"/>
        <vers num="12.2(19)"/>
        <vers num="12.2(19)b"/>
        <vers num="12.2(1b)"/>
        <vers num="12.2(1b)da1"/>
        <vers num="12.2(1d)"/>
        <vers num="12.2(2)b"/>
        <vers num="12.2(2)bx"/>
        <vers num="12.2(2)by"/>
        <vers num="12.2(2)by2"/>
        <vers num="12.2(2)dd3"/>
        <vers num="12.2(2)t"/>
        <vers num="12.2(2)t1"/>
        <vers num="12.2(2)t4"/>
        <vers num="12.2(2)xa"/>
        <vers num="12.2(2)xa1"/>
        <vers num="12.2(2)xa5"/>
        <vers num="12.2(2)xb"/>
        <vers num="12.2(2)xb11"/>
        <vers num="12.2(2)xb14"/>
        <vers num="12.2(2)xb15"/>
        <vers num="12.2(2)xb3"/>
        <vers num="12.2(2)xb4"/>
        <vers num="12.2(2)xc1"/>
        <vers num="12.2(2)xf"/>
        <vers num="12.2(2)xg"/>
        <vers num="12.2(2)xh"/>
        <vers num="12.2(2)xh2"/>
        <vers num="12.2(2)xh3"/>
        <vers num="12.2(2)xi"/>
        <vers num="12.2(2)xi1"/>
        <vers num="12.2(2)xi2"/>
        <vers num="12.2(2)xj"/>
        <vers num="12.2(2)xj1"/>
        <vers num="12.2(2)xk"/>
        <vers num="12.2(2)xk2"/>
        <vers num="12.2(2)xn"/>
        <vers num="12.2(2)xr"/>
        <vers num="12.2(2)xt"/>
        <vers num="12.2(2)xt3"/>
        <vers num="12.2(2)xu"/>
        <vers num="12.2(2)xu2"/>
        <vers num="12.2(2)yc"/>
        <vers num="12.2(2.2)t"/>
        <vers num="12.2(20)eu"/>
        <vers num="12.2(20)eu1"/>
        <vers num="12.2(20)eu2"/>
        <vers num="12.2(20)ew"/>
        <vers num="12.2(20)ew2"/>
        <vers num="12.2(20)ew3"/>
        <vers num="12.2(20)ewa"/>
        <vers num="12.2(20)ewa2"/>
        <vers num="12.2(20)ewa3"/>
        <vers num="12.2(20)s"/>
        <vers num="12.2(20)s1"/>
        <vers num="12.2(20)s2"/>
        <vers num="12.2(20)s4"/>
        <vers num="12.2(20)s7"/>
        <vers num="12.2(20)s8"/>
        <vers num="12.2(20)s9"/>
        <vers num="12.2(20)se3"/>
        <vers num="12.2(21)"/>
        <vers num="12.2(21a)"/>
        <vers num="12.2(21b)"/>
        <vers num="12.2(22)ea6"/>
        <vers num="12.2(22)s"/>
        <vers num="12.2(22)s2"/>
        <vers num="12.2(22)sv1"/>
        <vers num="12.2(23)"/>
        <vers num="12.2(23)sv1"/>
        <vers num="12.2(23)sw"/>
        <vers num="12.2(23.6)"/>
        <vers num="12.2(23a)"/>
        <vers num="12.2(23f)"/>
        <vers num="12.2(24)"/>
        <vers num="12.2(24)sv"/>
        <vers num="12.2(24)sv1"/>
        <vers num="12.2(25)ewa"/>
        <vers num="12.2(25)ewa1"/>
        <vers num="12.2(25)ewa3"/>
        <vers num="12.2(25)ewa4"/>
        <vers num="12.2(25)ex"/>
        <vers num="12.2(25)ey"/>
        <vers num="12.2(25)ey2"/>
        <vers num="12.2(25)ey3"/>
        <vers num="12.2(25)ez"/>
        <vers num="12.2(25)ez1"/>
        <vers num="12.2(25)fx"/>
        <vers num="12.2(25)fy"/>
        <vers num="12.2(25)s"/>
        <vers num="12.2(25)s1"/>
        <vers num="12.2(25)s3"/>
        <vers num="12.2(25)s4"/>
        <vers num="12.2(25)s6"/>
        <vers num="12.2(25)se"/>
        <vers num="12.2(25)seb"/>
        <vers num="12.2(25)seb2"/>
        <vers num="12.2(25)seb3"/>
        <vers num="12.2(25)seb4"/>
        <vers num="12.2(25)sec1"/>
        <vers num="12.2(25)sec2"/>
        <vers num="12.2(25)sed"/>
        <vers num="12.2(25)sg"/>
        <vers num="12.2(25)sv2"/>
        <vers num="12.2(25)sw"/>
        <vers num="12.2(25)sw3a"/>
        <vers num="12.2(25)sw4"/>
        <vers num="12.2(25)sw4a"/>
        <vers num="12.2(26)sv"/>
        <vers num="12.2(26)sv1"/>
        <vers num="12.2(26b)"/>
        <vers num="12.2(27)sbc"/>
        <vers num="12.2(27)sv1"/>
        <vers num="12.2(27b)"/>
        <vers num="12.2(28)"/>
        <vers num="12.2(28c)"/>
        <vers num="12.2(29a)"/>
        <vers num="12.2(3)"/>
        <vers num="12.2(3.4)bp"/>
        <vers num="12.2(30)s1"/>
        <vers num="12.2(31)"/>
        <vers num="12.2(3d)"/>
        <vers num="12.2(4)"/>
        <vers num="12.2(4)b"/>
        <vers num="12.2(4)b1"/>
        <vers num="12.2(4)b2"/>
        <vers num="12.2(4)b3"/>
        <vers num="12.2(4)b4"/>
        <vers num="12.2(4)bc1"/>
        <vers num="12.2(4)bc1a"/>
        <vers num="12.2(4)bx"/>
        <vers num="12.2(4)ja"/>
        <vers num="12.2(4)ja1"/>
        <vers num="12.2(4)mb12"/>
        <vers num="12.2(4)mb13b"/>
        <vers num="12.2(4)mb13c"/>
        <vers num="12.2(4)mb3"/>
        <vers num="12.2(4)mx"/>
        <vers num="12.2(4)mx1"/>
        <vers num="12.2(4)t"/>
        <vers num="12.2(4)t1"/>
        <vers num="12.2(4)t3"/>
        <vers num="12.2(4)t6"/>
        <vers num="12.2(4)xl"/>
        <vers num="12.2(4)xl4"/>
        <vers num="12.2(4)xm"/>
        <vers num="12.2(4)xm2"/>
        <vers num="12.2(4)xr"/>
        <vers num="12.2(4)xw"/>
        <vers num="12.2(4)xw1"/>
        <vers num="12.2(4)ya"/>
        <vers num="12.2(4)ya1"/>
        <vers num="12.2(4)ya10"/>
        <vers num="12.2(4)ya11"/>
        <vers num="12.2(4)ya7"/>
        <vers num="12.2(4)ya8"/>
        <vers num="12.2(4)ya9"/>
        <vers num="12.2(4)yb"/>
        <vers num="12.2(5)"/>
        <vers num="12.2(5)ca1"/>
        <vers num="12.2(5d)"/>
        <vers num="12.2(6.8)t0a"/>
        <vers num="12.2(6.8)t1a"/>
        <vers num="12.2(6.8a)"/>
        <vers num="12.2(6c)"/>
        <vers num="12.2(7)"/>
        <vers num="12.2(7)da"/>
        <vers num="12.2(7.4)s"/>
        <vers num="12.2(7a)"/>
        <vers num="12.2(7b)"/>
        <vers num="12.2(7c)"/>
        <vers num="12.2(8)bc1"/>
        <vers num="12.2(8)ja"/>
        <vers num="12.2(8)t"/>
        <vers num="12.2(8)t10"/>
        <vers num="12.2(8)tpc10a"/>
        <vers num="12.2(8)yd"/>
        <vers num="12.2(8)yw2"/>
        <vers num="12.2(8)yw3"/>
        <vers num="12.2(8)yy"/>
        <vers num="12.2(8)yy3"/>
        <vers num="12.2(8)zb7"/>
        <vers num="12.2(9)s"/>
        <vers num="12.2(9.4)da"/>
        <vers num="12.2b"/>
        <vers num="12.2bc"/>
        <vers num="12.2bw"/>
        <vers num="12.2bx"/>
        <vers num="12.2by"/>
        <vers num="12.2bz"/>
        <vers num="12.2ca"/>
        <vers num="12.2cx"/>
        <vers num="12.2cy"/>
        <vers num="12.2cz"/>
        <vers num="12.2da"/>
        <vers num="12.2dd"/>
        <vers num="12.2dx"/>
        <vers num="12.2e"/>
        <vers num="12.2eu"/>
        <vers num="12.2ew"/>
        <vers num="12.2ewa"/>
        <vers num="12.2ex"/>
        <vers num="12.2ey"/>
        <vers num="12.2ez"/>
        <vers num="12.2f"/>
        <vers num="12.2fx"/>
        <vers num="12.2fy"/>
        <vers num="12.2ja"/>
        <vers num="12.2jk"/>
        <vers num="12.2jx"/>
        <vers num="12.2mb"/>
        <vers num="12.2mc"/>
        <vers num="12.2mx"/>
        <vers num="12.2n"/>
        <vers num="12.2pb"/>
        <vers num="12.2pi"/>
        <vers num="12.2s"/>
        <vers num="12.2sa"/>
        <vers num="12.2sbc"/>
        <vers num="12.2se"/>
        <vers num="12.2sea"/>
        <vers num="12.2seb"/>
        <vers num="12.2sec"/>
        <vers num="12.2sg"/>
        <vers num="12.2sh"/>
        <vers num="12.2so"/>
        <vers num="12.2su"/>
        <vers num="12.2sv"/>
        <vers num="12.2sw"/>
        <vers num="12.2sx"/>
        <vers num="12.2sxa"/>
        <vers num="12.2sxb"/>
        <vers num="12.2sxd"/>
        <vers num="12.2sxe"/>
        <vers num="12.2sxf"/>
        <vers num="12.2sy"/>
        <vers num="12.2sz"/>
        <vers num="12.2t"/>
        <vers num="12.2tpc"/>
        <vers num="12.2x"/>
        <vers num="12.2xa"/>
        <vers num="12.2xb"/>
        <vers num="12.2xc"/>
        <vers num="12.2xd"/>
        <vers num="12.2xe"/>
        <vers num="12.2xf"/>
        <vers num="12.2xg"/>
        <vers num="12.2xh"/>
        <vers num="12.2xi"/>
        <vers num="12.2xj"/>
        <vers num="12.2xk"/>
        <vers num="12.2xl"/>
        <vers num="12.2xm"/>
        <vers num="12.2xn"/>
        <vers num="12.2xq"/>
        <vers num="12.2xr"/>
        <vers num="12.2xs"/>
        <vers num="12.2xt"/>
        <vers num="12.2xu"/>
        <vers num="12.2xv"/>
        <vers num="12.2xw"/>
        <vers num="12.2xz"/>
        <vers num="12.2ya"/>
        <vers num="12.2yb"/>
        <vers num="12.2yc"/>
        <vers num="12.2yd"/>
        <vers num="12.2ye"/>
        <vers num="12.2yf"/>
        <vers num="12.2yg"/>
        <vers num="12.2yh"/>
        <vers num="12.2yj"/>
        <vers num="12.2yk"/>
        <vers num="12.2yl"/>
        <vers num="12.2ym"/>
        <vers num="12.2yn"/>
        <vers num="12.2yo"/>
        <vers num="12.2yp"/>
        <vers num="12.2yq"/>
        <vers num="12.2yr"/>
        <vers num="12.2ys"/>
        <vers num="12.2yt"/>
        <vers num="12.2yu"/>
        <vers num="12.2yv"/>
        <vers num="12.2yw"/>
        <vers num="12.2yx"/>
        <vers num="12.2yy"/>
        <vers num="12.2yz"/>
        <vers num="12.2za"/>
        <vers num="12.2zb"/>
        <vers num="12.2zd"/>
        <vers num="12.2ze"/>
        <vers num="12.2zf"/>
        <vers num="12.2zg"/>
        <vers num="12.2zh"/>
        <vers num="12.2zi"/>
        <vers num="12.2zj"/>
        <vers num="12.2zk"/>
        <vers num="12.2zl"/>
        <vers num="12.2zm"/>
        <vers num="12.2zn"/>
        <vers num="12.2zo"/>
        <vers num="12.2zp"/>
        <vers num="12.2zq"/>
        <vers num="12.2zu"/>
        <vers num="12.2zx"/>
        <vers num="12.2zy"/>
        <vers num="12.2zya"/>
        <vers num="12.3"/>
        <vers num="12.3(10)"/>
        <vers num="12.3(10c)"/>
        <vers num="12.3(10d)"/>
        <vers num="12.3(10e)"/>
        <vers num="12.3(11)"/>
        <vers num="12.3(11)t"/>
        <vers num="12.3(11)t4"/>
        <vers num="12.3(11)t5"/>
        <vers num="12.3(11)t6"/>
        <vers num="12.3(11)t8"/>
        <vers num="12.3(11)t9"/>
        <vers num="12.3(11)xl"/>
        <vers num="12.3(11)xl3"/>
        <vers num="12.3(11)yf"/>
        <vers num="12.3(11)yf2"/>
        <vers num="12.3(11)yf3"/>
        <vers num="12.3(11)yf4"/>
        <vers num="12.3(11)yj"/>
        <vers num="12.3(11)yk"/>
        <vers num="12.3(11)yk1"/>
        <vers num="12.3(11)yk2"/>
        <vers num="12.3(11)yl"/>
        <vers num="12.3(11)yn"/>
        <vers num="12.3(11)yr"/>
        <vers num="12.3(11)ys"/>
        <vers num="12.3(11)ys1"/>
        <vers num="12.3(11)yw"/>
        <vers num="12.3(12)"/>
        <vers num="12.3(12b)"/>
        <vers num="12.3(12e)"/>
        <vers num="12.3(13)"/>
        <vers num="12.3(13a)"/>
        <vers num="12.3(13a)bc"/>
        <vers num="12.3(13a)bc1"/>
        <vers num="12.3(13b)"/>
        <vers num="12.3(14)t"/>
        <vers num="12.3(14)t2"/>
        <vers num="12.3(14)t4"/>
        <vers num="12.3(14)t5"/>
        <vers num="12.3(14)ym4"/>
        <vers num="12.3(14)yq"/>
        <vers num="12.3(14)yq1"/>
        <vers num="12.3(14)yq3"/>
        <vers num="12.3(14)yq4"/>
        <vers num="12.3(14)yt"/>
        <vers num="12.3(14)yt1"/>
        <vers num="12.3(14)yu"/>
        <vers num="12.3(14)yu1"/>
        <vers num="12.3(15)"/>
        <vers num="12.3(15b)"/>
        <vers num="12.3(16)"/>
        <vers num="12.3(1a)"/>
        <vers num="12.3(2)ja"/>
        <vers num="12.3(2)ja5"/>
        <vers num="12.3(2)jk"/>
        <vers num="12.3(2)jk1"/>
        <vers num="12.3(2)t3"/>
        <vers num="12.3(2)t8"/>
        <vers num="12.3(2)xa4"/>
        <vers num="12.3(2)xa5"/>
        <vers num="12.3(2)xc1"/>
        <vers num="12.3(2)xc2"/>
        <vers num="12.3(2)xc3"/>
        <vers num="12.3(2)xc4"/>
        <vers num="12.3(2)xe3"/>
        <vers num="12.3(2)xe4"/>
        <vers num="12.3(3e)"/>
        <vers num="12.3(3h)"/>
        <vers num="12.3(3i)"/>
        <vers num="12.3(4)eo1"/>
        <vers num="12.3(4)ja"/>
        <vers num="12.3(4)ja1"/>
        <vers num="12.3(4)t"/>
        <vers num="12.3(4)t1"/>
        <vers num="12.3(4)t2"/>
        <vers num="12.3(4)t3"/>
        <vers num="12.3(4)t4"/>
        <vers num="12.3(4)t8"/>
        <vers num="12.3(4)tpc11a"/>
        <vers num="12.3(4)xd"/>
        <vers num="12.3(4)xd1"/>
        <vers num="12.3(4)xd2"/>
        <vers num="12.3(4)xe4"/>
        <vers num="12.3(4)xg1"/>
        <vers num="12.3(4)xg2"/>
        <vers num="12.3(4)xg4"/>
        <vers num="12.3(4)xg5"/>
        <vers num="12.3(4)xh"/>
        <vers num="12.3(4)xk"/>
        <vers num="12.3(4)xk1"/>
        <vers num="12.3(4)xk3"/>
        <vers num="12.3(4)xk4"/>
        <vers num="12.3(4)xq"/>
        <vers num="12.3(4)xq1"/>
        <vers num="12.3(5)"/>
        <vers num="12.3(5)b1"/>
        <vers num="12.3(5a)"/>
        <vers num="12.3(5a)b"/>
        <vers num="12.3(5a)b2"/>
        <vers num="12.3(5a)b5"/>
        <vers num="12.3(5b)"/>
        <vers num="12.3(5c)"/>
        <vers num="12.3(5e)"/>
        <vers num="12.3(5f)"/>
        <vers num="12.3(6)"/>
        <vers num="12.3(6a)"/>
        <vers num="12.3(6d)"/>
        <vers num="12.3(6e)"/>
        <vers num="12.3(6f)"/>
        <vers num="12.3(7)ja"/>
        <vers num="12.3(7)ja1"/>
        <vers num="12.3(7)jx"/>
        <vers num="12.3(7)t"/>
        <vers num="12.3(7)t10"/>
        <vers num="12.3(7)t12"/>
        <vers num="12.3(7)t4"/>
        <vers num="12.3(7)t8"/>
        <vers num="12.3(7)t9"/>
        <vers num="12.3(7)xi3"/>
        <vers num="12.3(7)xi4"/>
        <vers num="12.3(7)xi7"/>
        <vers num="12.3(7)xr3"/>
        <vers num="12.3(7)xr4"/>
        <vers num="12.3(7)xr6"/>
        <vers num="12.3(7.7)"/>
        <vers num="12.3(8)ja"/>
        <vers num="12.3(8)ja1"/>
        <vers num="12.3(8)t11"/>
        <vers num="12.3(8)t4"/>
        <vers num="12.3(8)t7"/>
        <vers num="12.3(8)t8"/>
        <vers num="12.3(8)t9"/>
        <vers num="12.3(8)xu2"/>
        <vers num="12.3(8)xy4"/>
        <vers num="12.3(8)xy5"/>
        <vers num="12.3(8)xy6"/>
        <vers num="12.3(8)ya1"/>
        <vers num="12.3(8)yd"/>
        <vers num="12.3(8)yf"/>
        <vers num="12.3(8)yg"/>
        <vers num="12.3(8)yg1"/>
        <vers num="12.3(8)yg2"/>
        <vers num="12.3(8)yg3"/>
        <vers num="12.3(8)yh"/>
        <vers num="12.3(8)yi"/>
        <vers num="12.3(8)yi1"/>
        <vers num="12.3(8)yi3"/>
        <vers num="12.3(9)"/>
        <vers num="12.3(9a)bc"/>
        <vers num="12.3(9a)bc2"/>
        <vers num="12.3(9a)bc6"/>
        <vers num="12.3(9a)bc7"/>
        <vers num="12.3(9d)"/>
        <vers num="12.3(9e)"/>
        <vers num="12.3b"/>
        <vers num="12.3bc"/>
        <vers num="12.3bw"/>
        <vers num="12.3j"/>
        <vers num="12.3ja"/>
        <vers num="12.3jea"/>
        <vers num="12.3jeb"/>
        <vers num="12.3jec"/>
        <vers num="12.3jk"/>
        <vers num="12.3jx"/>
        <vers num="12.3t"/>
        <vers num="12.3tpc"/>
        <vers num="12.3xa"/>
        <vers num="12.3xb"/>
        <vers num="12.3xc"/>
        <vers num="12.3xd"/>
        <vers num="12.3xe"/>
        <vers num="12.3xf"/>
        <vers num="12.3xg"/>
        <vers num="12.3xh"/>
        <vers num="12.3xi"/>
        <vers num="12.3xj"/>
        <vers num="12.3xk"/>
        <vers num="12.3xl"/>
        <vers num="12.3xm"/>
        <vers num="12.3xn"/>
        <vers num="12.3xq"/>
        <vers num="12.3xr"/>
        <vers num="12.3xs"/>
        <vers num="12.3xt"/>
        <vers num="12.3xu"/>
        <vers num="12.3xv"/>
        <vers num="12.3xw"/>
        <vers num="12.3xx"/>
        <vers num="12.3xy"/>
        <vers num="12.3xz"/>
        <vers num="12.3ya"/>
        <vers num="12.3yb"/>
        <vers num="12.3yc"/>
        <vers num="12.3yd"/>
        <vers num="12.3ye"/>
        <vers num="12.3yf"/>
        <vers num="12.3yg"/>
        <vers num="12.3yh"/>
        <vers num="12.3yi"/>
        <vers num="12.3yj"/>
        <vers num="12.3yk"/>
        <vers num="12.3yl"/>
        <vers num="12.3ym"/>
        <vers num="12.3yn"/>
        <vers num="12.3yq"/>
        <vers num="12.3yr"/>
        <vers num="12.3ys"/>
        <vers num="12.3yt"/>
        <vers num="12.3yu"/>
        <vers num="12.3yw"/>
        <vers num="12.3yx"/>
        <vers num="12.3yz"/>
        <vers num="12.4"/>
        <vers num="12.4(1)"/>
        <vers num="12.4(1b)"/>
        <vers num="12.4(1c)"/>
        <vers num="12.4(2)mr"/>
        <vers num="12.4(2)mr1"/>
        <vers num="12.4(2)t"/>
        <vers num="12.4(2)t1"/>
        <vers num="12.4(2)t2"/>
        <vers num="12.4(2)t3"/>
        <vers num="12.4(2)t4"/>
        <vers num="12.4(2)xa"/>
        <vers num="12.4(2)xb"/>
        <vers num="12.4(2)xb2"/>
        <vers num="12.4(23)"/>
        <vers num="12.4(3)"/>
        <vers num="12.4(3)t2"/>
        <vers num="12.4(3a)"/>
        <vers num="12.4(3b)"/>
        <vers num="12.4(3d)"/>
        <vers num="12.4(4)mr"/>
        <vers num="12.4(4)t"/>
        <vers num="12.4(4)t2"/>
        <vers num="12.4(5)"/>
        <vers num="12.4(5b)"/>
        <vers num="12.4(6)t"/>
        <vers num="12.4(6)t1"/>
        <vers num="12.4(7)"/>
        <vers num="12.4(7a)"/>
        <vers num="12.4(8)"/>
        <vers num="12.4(9)t"/>
        <vers num="12.4ja"/>
        <vers num="12.4jda"/>
        <vers num="12.4jk"/>
        <vers num="12.4jl"/>
        <vers num="12.4jma"/>
        <vers num="12.4jmb"/>
        <vers num="12.4jx"/>
        <vers num="12.4md"/>
        <vers num="12.4mr"/>
        <vers num="12.4sw"/>
        <vers num="12.4t"/>
        <vers num="12.4xa"/>
        <vers num="12.4xb"/>
        <vers num="12.4xc"/>
        <vers num="12.4xd"/>
        <vers num="12.4xe"/>
        <vers num="12.4xf"/>
        <vers num="12.4xg"/>
        <vers num="12.4xj"/>
        <vers num="12.4xk"/>
        <vers num="12.4xl"/>
        <vers num="12.4xm"/>
        <vers num="12.4xn"/>
        <vers num="12.4xp"/>
        <vers num="12.4xt"/>
        <vers num="12.4xv"/>
        <vers num="12.4xw"/>
        <vers num="15.0"/>
        <vers num="15.0(1)s1"/>
        <vers num="15.0(1)s2"/>
        <vers num="15.0m"/>
        <vers num="15.0mr"/>
        <vers num="15.0mra"/>
        <vers num="15.0s"/>
        <vers num="15.0sa"/>
        <vers num="15.0sg"/>
        <vers num="15.0xa"/>
        <vers num="15.0xo"/>
        <vers num="15.1"/>
        <vers num="15.1(1)xb1"/>
        <vers num="15.1(2)t"/>
        <vers num="15.1(3)t"/>
        <vers num="15.1(4)m"/>
        <vers num="15.1(4)m1"/>
        <vers num="15.1ey"/>
        <vers num="15.1gc"/>
        <vers num="15.1m"/>
        <vers num="15.1s"/>
        <vers num="15.1t"/>
        <vers num="15.1xb"/>
        <vers num="15.2"/>
      </prod>
      <prod vendor="cisco" name="ios_xe">
        <vers num="2.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.3"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.1t"/>
        <vers num="2.3.2"/>
        <vers num="2.4"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="3.1.0s"/>
        <vers num="3.1.0sg"/>
        <vers num="3.1.1s"/>
        <vers num="3.1.1sg"/>
        <vers num="3.1.2s"/>
        <vers num="3.1.3s"/>
        <vers num="3.1.4s"/>
        <vers num="3.2.0s"/>
        <vers num="3.2.1s"/>
        <vers num="3.2.2s"/>
        <vers num="3.3.0s"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0383" published="2012-03-29" name="CVE-2012-0383" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Memory leak in the NAT feature in Cisco IOS 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (memory consumption, and device hang or reload) via SIP packets that require translation, related to a "memory starvation vulnerability," aka Bug ID CSCti35326.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74432" source="XF">ciscoios-nat-feature-dos(74432)</ref>
      <ref url="http://www.securitytracker.com/id?1026864" source="SECTRACK">1026864</ref>
      <ref url="http://www.securityfocus.com/bid/52758" source="BID">52758</ref>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-nat" source="CISCO" adv="1">20120328 Cisco IOS Software Network Address Translation Vulnerability</ref>
      <ref url="http://secunia.com/advisories/48515" source="SECUNIA">48515</ref>
      <ref url="http://osvdb.org/80701" source="OSVDB">80701</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.4"/>
        <vers num="15.0"/>
        <vers num="15.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0384" published="2012-03-29" name="CVE-2012-0384" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA authorization is enabled, allow remote authenticated users to bypass intended access restrictions and execute commands via a (1) HTTP or (2) HTTPS session, aka Bug ID CSCtr91106.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1026860" source="SECTRACK">1026860</ref>
      <ref url="http://www.securityfocus.com/bid/52755" source="BID">52755</ref>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-pai" source="CISCO" adv="1">20120328 Cisco IOS Software Command Authorization Bypass</ref>
      <ref url="http://secunia.com/advisories/48614" source="SECUNIA">48614</ref>
      <ref url="http://osvdb.org/80704" source="OSVDB">80704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2"/>
        <vers num="12.2(1)"/>
        <vers num="12.2(1)dx"/>
        <vers num="12.2(1)s"/>
        <vers num="12.2(1)t"/>
        <vers num="12.2(1)xa"/>
        <vers num="12.2(1)xd"/>
        <vers num="12.2(1)xd1"/>
        <vers num="12.2(1)xd3"/>
        <vers num="12.2(1)xd4"/>
        <vers num="12.2(1)xe"/>
        <vers num="12.2(1)xe2"/>
        <vers num="12.2(1)xe3"/>
        <vers num="12.2(1)xh"/>
        <vers num="12.2(1)xq"/>
        <vers num="12.2(1)xs"/>
        <vers num="12.2(1)xs1"/>
        <vers num="12.2(1.1)"/>
        <vers num="12.2(1.1)pi"/>
        <vers num="12.2(1.4)s"/>
        <vers num="12.2(10)da2"/>
        <vers num="12.2(10)da4"/>
        <vers num="12.2(10.5)s"/>
        <vers num="12.2(10g)"/>
        <vers num="12.2(11)bc3c"/>
        <vers num="12.2(11)ja"/>
        <vers num="12.2(11)ja1"/>
        <vers num="12.2(11)t"/>
        <vers num="12.2(11)t2"/>
        <vers num="12.2(11)t3"/>
        <vers num="12.2(11)t8"/>
        <vers num="12.2(11)t9"/>
        <vers num="12.2(11)yp1"/>
        <vers num="12.2(11)yu"/>
        <vers num="12.2(11)yv"/>
        <vers num="12.2(11)yx1"/>
        <vers num="12.2(11)yz2"/>
        <vers num="12.2(12)"/>
        <vers num="12.2(12)da3"/>
        <vers num="12.2(12)da8"/>
        <vers num="12.2(12)da9"/>
        <vers num="12.2(12.02)s"/>
        <vers num="12.2(12.02)t"/>
        <vers num="12.2(12.05)"/>
        <vers num="12.2(12.05)s"/>
        <vers num="12.2(12.05)t"/>
        <vers num="12.2(12b)"/>
        <vers num="12.2(12c)"/>
        <vers num="12.2(12g)"/>
        <vers num="12.2(12h)"/>
        <vers num="12.2(12i)"/>
        <vers num="12.2(12m)"/>
        <vers num="12.2(13)"/>
        <vers num="12.2(13)ja1"/>
        <vers num="12.2(13)mc1"/>
        <vers num="12.2(13)t"/>
        <vers num="12.2(13)t1"/>
        <vers num="12.2(13)t14"/>
        <vers num="12.2(13)t16"/>
        <vers num="12.2(13)t9"/>
        <vers num="12.2(13)zc"/>
        <vers num="12.2(13)zd"/>
        <vers num="12.2(13)zd3"/>
        <vers num="12.2(13)zd4"/>
        <vers num="12.2(13)ze"/>
        <vers num="12.2(13)zf"/>
        <vers num="12.2(13)zg"/>
        <vers num="12.2(13)zh"/>
        <vers num="12.2(13)zh3"/>
        <vers num="12.2(13)zh8"/>
        <vers num="12.2(13)zj"/>
        <vers num="12.2(13)zk"/>
        <vers num="12.2(13)zl"/>
        <vers num="12.2(13.03)b"/>
        <vers num="12.2(13a)"/>
        <vers num="12.2(13e)"/>
        <vers num="12.2(14)s"/>
        <vers num="12.2(14)s13"/>
        <vers num="12.2(14)s14"/>
        <vers num="12.2(14)s15"/>
        <vers num="12.2(14)su2"/>
        <vers num="12.2(14)sx1"/>
        <vers num="12.2(14)sy"/>
        <vers num="12.2(14)sy03"/>
        <vers num="12.2(14)sy1"/>
        <vers num="12.2(14)sz"/>
        <vers num="12.2(14)sz1"/>
        <vers num="12.2(14)sz2"/>
        <vers num="12.2(14)za"/>
        <vers num="12.2(14)za2"/>
        <vers num="12.2(14)za8"/>
        <vers num="12.2(14.5)"/>
        <vers num="12.2(14.5)t"/>
        <vers num="12.2(15)b"/>
        <vers num="12.2(15)bc"/>
        <vers num="12.2(15)bc1"/>
        <vers num="12.2(15)bc1f"/>
        <vers num="12.2(15)bc2f"/>
        <vers num="12.2(15)bc2h"/>
        <vers num="12.2(15)bc2i"/>
        <vers num="12.2(15)bx"/>
        <vers num="12.2(15)bz"/>
        <vers num="12.2(15)cx"/>
        <vers num="12.2(15)cz3"/>
        <vers num="12.2(15)jk2"/>
        <vers num="12.2(15)jk4"/>
        <vers num="12.2(15)jk5"/>
        <vers num="12.2(15)mc1"/>
        <vers num="12.2(15)mc2c"/>
        <vers num="12.2(15)mc2e"/>
        <vers num="12.2(15)sl1"/>
        <vers num="12.2(15)t"/>
        <vers num="12.2(15)t15"/>
        <vers num="12.2(15)t16"/>
        <vers num="12.2(15)t17"/>
        <vers num="12.2(15)t5"/>
        <vers num="12.2(15)t7"/>
        <vers num="12.2(15)t8"/>
        <vers num="12.2(15)t9"/>
        <vers num="12.2(15)xr"/>
        <vers num="12.2(15)xr2"/>
        <vers num="12.2(15)ys"/>
        <vers num="12.2(15)ys_1.2(1)"/>
        <vers num="12.2(15)zj"/>
        <vers num="12.2(15)zj1"/>
        <vers num="12.2(15)zj2"/>
        <vers num="12.2(15)zj3"/>
        <vers num="12.2(15)zk"/>
        <vers num="12.2(15)zl"/>
        <vers num="12.2(15)zl1"/>
        <vers num="12.2(15)zn"/>
        <vers num="12.2(15)zo"/>
        <vers num="12.2(15.1)s"/>
        <vers num="12.2(16)b"/>
        <vers num="12.2(16)b1"/>
        <vers num="12.2(16)bx"/>
        <vers num="12.2(16.1)b"/>
        <vers num="12.2(16.5)s"/>
        <vers num="12.2(16f)"/>
        <vers num="12.2(17)"/>
        <vers num="12.2(17)a"/>
        <vers num="12.2(17)zd3"/>
        <vers num="12.2(17a)"/>
        <vers num="12.2(17a)sxa"/>
        <vers num="12.2(17b)sxa"/>
        <vers num="12.2(17d)"/>
        <vers num="12.2(17d)sx"/>
        <vers num="12.2(17d)sxb"/>
        <vers num="12.2(17d)sxb10"/>
        <vers num="12.2(17d)sxb7"/>
        <vers num="12.2(17d)sxb8"/>
        <vers num="12.2(17f)"/>
        <vers num="12.2(18)ew"/>
        <vers num="12.2(18)ew2"/>
        <vers num="12.2(18)ew3"/>
        <vers num="12.2(18)ew5"/>
        <vers num="12.2(18)ewa"/>
        <vers num="12.2(18)s"/>
        <vers num="12.2(18)s10"/>
        <vers num="12.2(18)s6"/>
        <vers num="12.2(18)s8"/>
        <vers num="12.2(18)s9"/>
        <vers num="12.2(18)se"/>
        <vers num="12.2(18)so4"/>
        <vers num="12.2(18)sv"/>
        <vers num="12.2(18)sv3"/>
        <vers num="12.2(18)sw"/>
        <vers num="12.2(18)sxd1"/>
        <vers num="12.2(18)sxd4"/>
        <vers num="12.2(18)sxd5"/>
        <vers num="12.2(18)sxd6"/>
        <vers num="12.2(18)sxd7"/>
        <vers num="12.2(18)sxe"/>
        <vers num="12.2(18)sxe1"/>
        <vers num="12.2(18)sxe3"/>
        <vers num="12.2(18)sxf"/>
        <vers num="12.2(18.2)"/>
        <vers num="12.2(19)"/>
        <vers num="12.2(19)b"/>
        <vers num="12.2(1b)"/>
        <vers num="12.2(1b)da1"/>
        <vers num="12.2(1d)"/>
        <vers num="12.2(2)b"/>
        <vers num="12.2(2)bx"/>
        <vers num="12.2(2)by"/>
        <vers num="12.2(2)by2"/>
        <vers num="12.2(2)dd3"/>
        <vers num="12.2(2)t"/>
        <vers num="12.2(2)t1"/>
        <vers num="12.2(2)t4"/>
        <vers num="12.2(2)xa"/>
        <vers num="12.2(2)xa1"/>
        <vers num="12.2(2)xa5"/>
        <vers num="12.2(2)xb"/>
        <vers num="12.2(2)xb11"/>
        <vers num="12.2(2)xb14"/>
        <vers num="12.2(2)xb15"/>
        <vers num="12.2(2)xb3"/>
        <vers num="12.2(2)xb4"/>
        <vers num="12.2(2)xc1"/>
        <vers num="12.2(2)xf"/>
        <vers num="12.2(2)xg"/>
        <vers num="12.2(2)xh"/>
        <vers num="12.2(2)xh2"/>
        <vers num="12.2(2)xh3"/>
        <vers num="12.2(2)xi"/>
        <vers num="12.2(2)xi1"/>
        <vers num="12.2(2)xi2"/>
        <vers num="12.2(2)xj"/>
        <vers num="12.2(2)xj1"/>
        <vers num="12.2(2)xk"/>
        <vers num="12.2(2)xk2"/>
        <vers num="12.2(2)xn"/>
        <vers num="12.2(2)xr"/>
        <vers num="12.2(2)xt"/>
        <vers num="12.2(2)xt3"/>
        <vers num="12.2(2)xu"/>
        <vers num="12.2(2)xu2"/>
        <vers num="12.2(2)yc"/>
        <vers num="12.2(2.2)t"/>
        <vers num="12.2(20)eu"/>
        <vers num="12.2(20)eu1"/>
        <vers num="12.2(20)eu2"/>
        <vers num="12.2(20)ew"/>
        <vers num="12.2(20)ew2"/>
        <vers num="12.2(20)ew3"/>
        <vers num="12.2(20)ewa"/>
        <vers num="12.2(20)ewa2"/>
        <vers num="12.2(20)ewa3"/>
        <vers num="12.2(20)s"/>
        <vers num="12.2(20)s1"/>
        <vers num="12.2(20)s2"/>
        <vers num="12.2(20)s4"/>
        <vers num="12.2(20)s7"/>
        <vers num="12.2(20)s8"/>
        <vers num="12.2(20)s9"/>
        <vers num="12.2(20)se3"/>
        <vers num="12.2(21)"/>
        <vers num="12.2(21a)"/>
        <vers num="12.2(21b)"/>
        <vers num="12.2(22)ea6"/>
        <vers num="12.2(22)s"/>
        <vers num="12.2(22)s2"/>
        <vers num="12.2(22)sv1"/>
        <vers num="12.2(23)"/>
        <vers num="12.2(23)sv1"/>
        <vers num="12.2(23)sw"/>
        <vers num="12.2(23.6)"/>
        <vers num="12.2(23a)"/>
        <vers num="12.2(23f)"/>
        <vers num="12.2(24)"/>
        <vers num="12.2(24)sv"/>
        <vers num="12.2(24)sv1"/>
        <vers num="12.2(25)ewa"/>
        <vers num="12.2(25)ewa1"/>
        <vers num="12.2(25)ewa3"/>
        <vers num="12.2(25)ewa4"/>
        <vers num="12.2(25)ex"/>
        <vers num="12.2(25)ey"/>
        <vers num="12.2(25)ey2"/>
        <vers num="12.2(25)ey3"/>
        <vers num="12.2(25)ez"/>
        <vers num="12.2(25)ez1"/>
        <vers num="12.2(25)fx"/>
        <vers num="12.2(25)fy"/>
        <vers num="12.2(25)s"/>
        <vers num="12.2(25)s1"/>
        <vers num="12.2(25)s3"/>
        <vers num="12.2(25)s4"/>
        <vers num="12.2(25)s6"/>
        <vers num="12.2(25)se"/>
        <vers num="12.2(25)seb"/>
        <vers num="12.2(25)seb2"/>
        <vers num="12.2(25)seb3"/>
        <vers num="12.2(25)seb4"/>
        <vers num="12.2(25)sec1"/>
        <vers num="12.2(25)sec2"/>
        <vers num="12.2(25)sed"/>
        <vers num="12.2(25)sg"/>
        <vers num="12.2(25)sv2"/>
        <vers num="12.2(25)sw"/>
        <vers num="12.2(25)sw3a"/>
        <vers num="12.2(25)sw4"/>
        <vers num="12.2(25)sw4a"/>
        <vers num="12.2(26)sv"/>
        <vers num="12.2(26)sv1"/>
        <vers num="12.2(26b)"/>
        <vers num="12.2(27)sbc"/>
        <vers num="12.2(27)sv1"/>
        <vers num="12.2(27b)"/>
        <vers num="12.2(28)"/>
        <vers num="12.2(28c)"/>
        <vers num="12.2(29a)"/>
        <vers num="12.2(3)"/>
        <vers num="12.2(3.4)bp"/>
        <vers num="12.2(30)s1"/>
        <vers num="12.2(31)"/>
        <vers num="12.2(3d)"/>
        <vers num="12.2(4)"/>
        <vers num="12.2(4)b"/>
        <vers num="12.2(4)b1"/>
        <vers num="12.2(4)b2"/>
        <vers num="12.2(4)b3"/>
        <vers num="12.2(4)b4"/>
        <vers num="12.2(4)bc1"/>
        <vers num="12.2(4)bc1a"/>
        <vers num="12.2(4)bx"/>
        <vers num="12.2(4)ja"/>
        <vers num="12.2(4)ja1"/>
        <vers num="12.2(4)mb12"/>
        <vers num="12.2(4)mb13b"/>
        <vers num="12.2(4)mb13c"/>
        <vers num="12.2(4)mb3"/>
        <vers num="12.2(4)mx"/>
        <vers num="12.2(4)mx1"/>
        <vers num="12.2(4)t"/>
        <vers num="12.2(4)t1"/>
        <vers num="12.2(4)t3"/>
        <vers num="12.2(4)t6"/>
        <vers num="12.2(4)xl"/>
        <vers num="12.2(4)xl4"/>
        <vers num="12.2(4)xm"/>
        <vers num="12.2(4)xm2"/>
        <vers num="12.2(4)xr"/>
        <vers num="12.2(4)xw"/>
        <vers num="12.2(4)xw1"/>
        <vers num="12.2(4)ya"/>
        <vers num="12.2(4)ya1"/>
        <vers num="12.2(4)ya10"/>
        <vers num="12.2(4)ya11"/>
        <vers num="12.2(4)ya7"/>
        <vers num="12.2(4)ya8"/>
        <vers num="12.2(4)ya9"/>
        <vers num="12.2(4)yb"/>
        <vers num="12.2(5)"/>
        <vers num="12.2(5)ca1"/>
        <vers num="12.2(5d)"/>
        <vers num="12.2(6.8)t0a"/>
        <vers num="12.2(6.8)t1a"/>
        <vers num="12.2(6.8a)"/>
        <vers num="12.2(6c)"/>
        <vers num="12.2(7)"/>
        <vers num="12.2(7)da"/>
        <vers num="12.2(7.4)s"/>
        <vers num="12.2(7a)"/>
        <vers num="12.2(7b)"/>
        <vers num="12.2(7c)"/>
        <vers num="12.2(8)bc1"/>
        <vers num="12.2(8)ja"/>
        <vers num="12.2(8)t"/>
        <vers num="12.2(8)t10"/>
        <vers num="12.2(8)tpc10a"/>
        <vers num="12.2(8)yd"/>
        <vers num="12.2(8)yw2"/>
        <vers num="12.2(8)yw3"/>
        <vers num="12.2(8)yy"/>
        <vers num="12.2(8)yy3"/>
        <vers num="12.2(8)zb7"/>
        <vers num="12.2(9)s"/>
        <vers num="12.2(9.4)da"/>
        <vers num="12.2b"/>
        <vers num="12.2bc"/>
        <vers num="12.2bw"/>
        <vers num="12.2bx"/>
        <vers num="12.2by"/>
        <vers num="12.2bz"/>
        <vers num="12.2ca"/>
        <vers num="12.2cx"/>
        <vers num="12.2cy"/>
        <vers num="12.2cz"/>
        <vers num="12.2da"/>
        <vers num="12.2dd"/>
        <vers num="12.2dx"/>
        <vers num="12.2e"/>
        <vers num="12.2eu"/>
        <vers num="12.2ew"/>
        <vers num="12.2ewa"/>
        <vers num="12.2ex"/>
        <vers num="12.2ey"/>
        <vers num="12.2ez"/>
        <vers num="12.2f"/>
        <vers num="12.2fx"/>
        <vers num="12.2fy"/>
        <vers num="12.2ja"/>
        <vers num="12.2jk"/>
        <vers num="12.2jx"/>
        <vers num="12.2mb"/>
        <vers num="12.2mc"/>
        <vers num="12.2mx"/>
        <vers num="12.2n"/>
        <vers num="12.2pb"/>
        <vers num="12.2pi"/>
        <vers num="12.2s"/>
        <vers num="12.2sa"/>
        <vers num="12.2sbc"/>
        <vers num="12.2se"/>
        <vers num="12.2sea"/>
        <vers num="12.2seb"/>
        <vers num="12.2sec"/>
        <vers num="12.2sg"/>
        <vers num="12.2sh"/>
        <vers num="12.2so"/>
        <vers num="12.2su"/>
        <vers num="12.2sv"/>
        <vers num="12.2sw"/>
        <vers num="12.2sx"/>
        <vers num="12.2sxa"/>
        <vers num="12.2sxb"/>
        <vers num="12.2sxd"/>
        <vers num="12.2sxe"/>
        <vers num="12.2sxf"/>
        <vers num="12.2sy"/>
        <vers num="12.2sz"/>
        <vers num="12.2t"/>
        <vers num="12.2tpc"/>
        <vers num="12.2x"/>
        <vers num="12.2xa"/>
        <vers num="12.2xb"/>
        <vers num="12.2xc"/>
        <vers num="12.2xd"/>
        <vers num="12.2xe"/>
        <vers num="12.2xf"/>
        <vers num="12.2xg"/>
        <vers num="12.2xh"/>
        <vers num="12.2xi"/>
        <vers num="12.2xj"/>
        <vers num="12.2xk"/>
        <vers num="12.2xl"/>
        <vers num="12.2xm"/>
        <vers num="12.2xn"/>
        <vers num="12.2xq"/>
        <vers num="12.2xr"/>
        <vers num="12.2xs"/>
        <vers num="12.2xt"/>
        <vers num="12.2xu"/>
        <vers num="12.2xv"/>
        <vers num="12.2xw"/>
        <vers num="12.2xz"/>
        <vers num="12.2ya"/>
        <vers num="12.2yb"/>
        <vers num="12.2yc"/>
        <vers num="12.2yd"/>
        <vers num="12.2ye"/>
        <vers num="12.2yf"/>
        <vers num="12.2yg"/>
        <vers num="12.2yh"/>
        <vers num="12.2yj"/>
        <vers num="12.2yk"/>
        <vers num="12.2yl"/>
        <vers num="12.2ym"/>
        <vers num="12.2yn"/>
        <vers num="12.2yo"/>
        <vers num="12.2yp"/>
        <vers num="12.2yq"/>
        <vers num="12.2yr"/>
        <vers num="12.2ys"/>
        <vers num="12.2yt"/>
        <vers num="12.2yu"/>
        <vers num="12.2yv"/>
        <vers num="12.2yw"/>
        <vers num="12.2yx"/>
        <vers num="12.2yy"/>
        <vers num="12.2yz"/>
        <vers num="12.2za"/>
        <vers num="12.2zb"/>
        <vers num="12.2zd"/>
        <vers num="12.2ze"/>
        <vers num="12.2zf"/>
        <vers num="12.2zg"/>
        <vers num="12.2zh"/>
        <vers num="12.2zi"/>
        <vers num="12.2zj"/>
        <vers num="12.2zk"/>
        <vers num="12.2zl"/>
        <vers num="12.2zm"/>
        <vers num="12.2zn"/>
        <vers num="12.2zo"/>
        <vers num="12.2zp"/>
        <vers num="12.2zq"/>
        <vers num="12.2zu"/>
        <vers num="12.2zx"/>
        <vers num="12.2zy"/>
        <vers num="12.2zya"/>
        <vers num="12.3"/>
        <vers num="12.3(10)"/>
        <vers num="12.3(10c)"/>
        <vers num="12.3(10d)"/>
        <vers num="12.3(10e)"/>
        <vers num="12.3(11)"/>
        <vers num="12.3(11)t"/>
        <vers num="12.3(11)t4"/>
        <vers num="12.3(11)t5"/>
        <vers num="12.3(11)t6"/>
        <vers num="12.3(11)t8"/>
        <vers num="12.3(11)t9"/>
        <vers num="12.3(11)xl"/>
        <vers num="12.3(11)xl3"/>
        <vers num="12.3(11)yf"/>
        <vers num="12.3(11)yf2"/>
        <vers num="12.3(11)yf3"/>
        <vers num="12.3(11)yf4"/>
        <vers num="12.3(11)yj"/>
        <vers num="12.3(11)yk"/>
        <vers num="12.3(11)yk1"/>
        <vers num="12.3(11)yk2"/>
        <vers num="12.3(11)yl"/>
        <vers num="12.3(11)yn"/>
        <vers num="12.3(11)yr"/>
        <vers num="12.3(11)ys"/>
        <vers num="12.3(11)ys1"/>
        <vers num="12.3(11)yw"/>
        <vers num="12.3(12)"/>
        <vers num="12.3(12b)"/>
        <vers num="12.3(12e)"/>
        <vers num="12.3(13)"/>
        <vers num="12.3(13a)"/>
        <vers num="12.3(13a)bc"/>
        <vers num="12.3(13a)bc1"/>
        <vers num="12.3(13b)"/>
        <vers num="12.3(14)t"/>
        <vers num="12.3(14)t2"/>
        <vers num="12.3(14)t4"/>
        <vers num="12.3(14)t5"/>
        <vers num="12.3(14)ym4"/>
        <vers num="12.3(14)yq"/>
        <vers num="12.3(14)yq1"/>
        <vers num="12.3(14)yq3"/>
        <vers num="12.3(14)yq4"/>
        <vers num="12.3(14)yt"/>
        <vers num="12.3(14)yt1"/>
        <vers num="12.3(14)yu"/>
        <vers num="12.3(14)yu1"/>
        <vers num="12.3(15)"/>
        <vers num="12.3(15b)"/>
        <vers num="12.3(16)"/>
        <vers num="12.3(1a)"/>
        <vers num="12.3(2)ja"/>
        <vers num="12.3(2)ja5"/>
        <vers num="12.3(2)jk"/>
        <vers num="12.3(2)jk1"/>
        <vers num="12.3(2)t3"/>
        <vers num="12.3(2)t8"/>
        <vers num="12.3(2)xa4"/>
        <vers num="12.3(2)xa5"/>
        <vers num="12.3(2)xc1"/>
        <vers num="12.3(2)xc2"/>
        <vers num="12.3(2)xc3"/>
        <vers num="12.3(2)xc4"/>
        <vers num="12.3(2)xe3"/>
        <vers num="12.3(2)xe4"/>
        <vers num="12.3(3e)"/>
        <vers num="12.3(3h)"/>
        <vers num="12.3(3i)"/>
        <vers num="12.3(4)eo1"/>
        <vers num="12.3(4)ja"/>
        <vers num="12.3(4)ja1"/>
        <vers num="12.3(4)t"/>
        <vers num="12.3(4)t1"/>
        <vers num="12.3(4)t2"/>
        <vers num="12.3(4)t3"/>
        <vers num="12.3(4)t4"/>
        <vers num="12.3(4)t8"/>
        <vers num="12.3(4)tpc11a"/>
        <vers num="12.3(4)xd"/>
        <vers num="12.3(4)xd1"/>
        <vers num="12.3(4)xd2"/>
        <vers num="12.3(4)xe4"/>
        <vers num="12.3(4)xg1"/>
        <vers num="12.3(4)xg2"/>
        <vers num="12.3(4)xg4"/>
        <vers num="12.3(4)xg5"/>
        <vers num="12.3(4)xh"/>
        <vers num="12.3(4)xk"/>
        <vers num="12.3(4)xk1"/>
        <vers num="12.3(4)xk3"/>
        <vers num="12.3(4)xk4"/>
        <vers num="12.3(4)xq"/>
        <vers num="12.3(4)xq1"/>
        <vers num="12.3(5)"/>
        <vers num="12.3(5)b1"/>
        <vers num="12.3(5a)"/>
        <vers num="12.3(5a)b"/>
        <vers num="12.3(5a)b2"/>
        <vers num="12.3(5a)b5"/>
        <vers num="12.3(5b)"/>
        <vers num="12.3(5c)"/>
        <vers num="12.3(5e)"/>
        <vers num="12.3(5f)"/>
        <vers num="12.3(6)"/>
        <vers num="12.3(6a)"/>
        <vers num="12.3(6d)"/>
        <vers num="12.3(6e)"/>
        <vers num="12.3(6f)"/>
        <vers num="12.3(7)ja"/>
        <vers num="12.3(7)ja1"/>
        <vers num="12.3(7)jx"/>
        <vers num="12.3(7)t"/>
        <vers num="12.3(7)t10"/>
        <vers num="12.3(7)t12"/>
        <vers num="12.3(7)t4"/>
        <vers num="12.3(7)t8"/>
        <vers num="12.3(7)t9"/>
        <vers num="12.3(7)xi3"/>
        <vers num="12.3(7)xi4"/>
        <vers num="12.3(7)xi7"/>
        <vers num="12.3(7)xr3"/>
        <vers num="12.3(7)xr4"/>
        <vers num="12.3(7)xr6"/>
        <vers num="12.3(7.7)"/>
        <vers num="12.3(8)ja"/>
        <vers num="12.3(8)ja1"/>
        <vers num="12.3(8)t11"/>
        <vers num="12.3(8)t4"/>
        <vers num="12.3(8)t7"/>
        <vers num="12.3(8)t8"/>
        <vers num="12.3(8)t9"/>
        <vers num="12.3(8)xu2"/>
        <vers num="12.3(8)xy4"/>
        <vers num="12.3(8)xy5"/>
        <vers num="12.3(8)xy6"/>
        <vers num="12.3(8)ya1"/>
        <vers num="12.3(8)yd"/>
        <vers num="12.3(8)yf"/>
        <vers num="12.3(8)yg"/>
        <vers num="12.3(8)yg1"/>
        <vers num="12.3(8)yg2"/>
        <vers num="12.3(8)yg3"/>
        <vers num="12.3(8)yh"/>
        <vers num="12.3(8)yi"/>
        <vers num="12.3(8)yi1"/>
        <vers num="12.3(8)yi3"/>
        <vers num="12.3(9)"/>
        <vers num="12.3(9a)bc"/>
        <vers num="12.3(9a)bc2"/>
        <vers num="12.3(9a)bc6"/>
        <vers num="12.3(9a)bc7"/>
        <vers num="12.3(9d)"/>
        <vers num="12.3(9e)"/>
        <vers num="12.3b"/>
        <vers num="12.3bc"/>
        <vers num="12.3bw"/>
        <vers num="12.3j"/>
        <vers num="12.3ja"/>
        <vers num="12.3jea"/>
        <vers num="12.3jeb"/>
        <vers num="12.3jec"/>
        <vers num="12.3jk"/>
        <vers num="12.3jx"/>
        <vers num="12.3t"/>
        <vers num="12.3tpc"/>
        <vers num="12.3xa"/>
        <vers num="12.3xb"/>
        <vers num="12.3xc"/>
        <vers num="12.3xd"/>
        <vers num="12.3xe"/>
        <vers num="12.3xf"/>
        <vers num="12.3xg"/>
        <vers num="12.3xh"/>
        <vers num="12.3xi"/>
        <vers num="12.3xj"/>
        <vers num="12.3xk"/>
        <vers num="12.3xl"/>
        <vers num="12.3xm"/>
        <vers num="12.3xn"/>
        <vers num="12.3xq"/>
        <vers num="12.3xr"/>
        <vers num="12.3xs"/>
        <vers num="12.3xt"/>
        <vers num="12.3xu"/>
        <vers num="12.3xv"/>
        <vers num="12.3xw"/>
        <vers num="12.3xx"/>
        <vers num="12.3xy"/>
        <vers num="12.3xz"/>
        <vers num="12.3ya"/>
        <vers num="12.3yb"/>
        <vers num="12.3yc"/>
        <vers num="12.3yd"/>
        <vers num="12.3ye"/>
        <vers num="12.3yf"/>
        <vers num="12.3yg"/>
        <vers num="12.3yh"/>
        <vers num="12.3yi"/>
        <vers num="12.3yj"/>
        <vers num="12.3yk"/>
        <vers num="12.3yl"/>
        <vers num="12.3ym"/>
        <vers num="12.3yn"/>
        <vers num="12.3yq"/>
        <vers num="12.3yr"/>
        <vers num="12.3ys"/>
        <vers num="12.3yt"/>
        <vers num="12.3yu"/>
        <vers num="12.3yw"/>
        <vers num="12.3yx"/>
        <vers num="12.3yz"/>
        <vers num="12.4"/>
        <vers num="12.4(1)"/>
        <vers num="12.4(1b)"/>
        <vers num="12.4(1c)"/>
        <vers num="12.4(2)mr"/>
        <vers num="12.4(2)mr1"/>
        <vers num="12.4(2)t"/>
        <vers num="12.4(2)t1"/>
        <vers num="12.4(2)t2"/>
        <vers num="12.4(2)t3"/>
        <vers num="12.4(2)t4"/>
        <vers num="12.4(2)xa"/>
        <vers num="12.4(2)xb"/>
        <vers num="12.4(2)xb2"/>
        <vers num="12.4(23)"/>
        <vers num="12.4(3)"/>
        <vers num="12.4(3)t2"/>
        <vers num="12.4(3a)"/>
        <vers num="12.4(3b)"/>
        <vers num="12.4(3d)"/>
        <vers num="12.4(4)mr"/>
        <vers num="12.4(4)t"/>
        <vers num="12.4(4)t2"/>
        <vers num="12.4(5)"/>
        <vers num="12.4(5b)"/>
        <vers num="12.4(6)t"/>
        <vers num="12.4(6)t1"/>
        <vers num="12.4(7)"/>
        <vers num="12.4(7a)"/>
        <vers num="12.4(8)"/>
        <vers num="12.4(9)t"/>
        <vers num="12.4ja"/>
        <vers num="12.4jda"/>
        <vers num="12.4jk"/>
        <vers num="12.4jl"/>
        <vers num="12.4jma"/>
        <vers num="12.4jmb"/>
        <vers num="12.4jx"/>
        <vers num="12.4md"/>
        <vers num="12.4mr"/>
        <vers num="12.4sw"/>
        <vers num="12.4t"/>
        <vers num="12.4xa"/>
        <vers num="12.4xb"/>
        <vers num="12.4xc"/>
        <vers num="12.4xd"/>
        <vers num="12.4xe"/>
        <vers num="12.4xf"/>
        <vers num="12.4xg"/>
        <vers num="12.4xj"/>
        <vers num="12.4xk"/>
        <vers num="12.4xl"/>
        <vers num="12.4xm"/>
        <vers num="12.4xn"/>
        <vers num="12.4xp"/>
        <vers num="12.4xt"/>
        <vers num="12.4xv"/>
        <vers num="12.4xw"/>
        <vers num="15.0"/>
        <vers num="15.0(1)s1"/>
        <vers num="15.0(1)s2"/>
        <vers num="15.0m"/>
        <vers num="15.0mr"/>
        <vers num="15.0mra"/>
        <vers num="15.0s"/>
        <vers num="15.0sa"/>
        <vers num="15.0sg"/>
        <vers num="15.0xa"/>
        <vers num="15.0xo"/>
        <vers num="15.1"/>
        <vers num="15.1(1)xb1"/>
        <vers num="15.1(2)t"/>
        <vers num="15.1(3)t"/>
        <vers num="15.1(4)m"/>
        <vers num="15.1(4)m1"/>
        <vers num="15.1ey"/>
        <vers num="15.1gc"/>
        <vers num="15.1m"/>
        <vers num="15.1s"/>
        <vers num="15.1t"/>
        <vers num="15.1xb"/>
        <vers num="15.2"/>
      </prod>
      <prod vendor="cisco" name="ios_xe">
        <vers num="2.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.3"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.1t"/>
        <vers num="2.3.2"/>
        <vers num="2.4"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="3.1.0s"/>
        <vers num="3.1.0sg"/>
        <vers num="3.1.1s"/>
        <vers num="3.1.1sg"/>
        <vers num="3.1.2s"/>
        <vers num="3.1.3s"/>
        <vers num="3.1.4s"/>
        <vers num="3.2.0s"/>
        <vers num="3.2.1s"/>
        <vers num="3.2.2s"/>
        <vers num="3.3.0s"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0385" published="2012-03-29" name="CVE-2012-0385" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Smart Install feature in Cisco IOS 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (device reload) by sending a malformed Smart Install message over TCP, aka Bug ID CSCtt16051.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74430" source="XF">ciscoios-smartinstall-dos(74430)</ref>
      <ref url="http://www.securitytracker.com/id?1026867" source="SECTRACK">1026867</ref>
      <ref url="http://www.securityfocus.com/bid/52756" source="BID">52756</ref>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-smartinstall" source="CISCO" adv="1">20120328 Cisco IOS Software Smart Install Denial of Service Vulnerability</ref>
      <ref url="http://osvdb.org/80694" source="OSVDB">80694</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2"/>
        <vers num="15.0"/>
        <vers num="15.1"/>
        <vers num="15.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0386" published="2012-03-29" name="CVE-2012-0386" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows remote attackers to cause a denial of service (device reload) via a crafted username in a reverse SSH login attempt, aka Bug ID CSCtr49064.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74404" source="XF">ciscoios-sshv2-dos(74404)</ref>
      <ref url="http://www.securityfocus.com/bid/52752" source="BID">52752</ref>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-ssh" source="CISCO" adv="1">20120328 Cisco IOS Software Reverse SSH Denial of Service Vulnerability</ref>
      <ref url="http://osvdb.org/80695" source="OSVDB">80695</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2"/>
        <vers num="12.4"/>
        <vers num="15.0"/>
        <vers num="15.1"/>
        <vers num="15.2"/>
      </prod>
      <prod vendor="cisco" name="ios_xe">
        <vers num="2.3"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.1t"/>
        <vers num="2.3.2"/>
        <vers num="2.4"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="3.1.0s"/>
        <vers num="3.1.0sg"/>
        <vers num="3.1.1s"/>
        <vers num="3.1.1sg"/>
        <vers num="3.1.2s"/>
        <vers num="3.1.3s"/>
        <vers num="3.1.4s"/>
        <vers num="3.2.0s"/>
        <vers num="3.2.1s"/>
        <vers num="3.2.2s"/>
        <vers num="3.3.0s"/>
        <vers num="3.4.0s"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0387" published="2012-03-29" name="CVE-2012-0387" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Memory leak in the HTTP Inspection Engine feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit HTTP traffic, aka Bug ID CSCtq36153.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74435" source="XF">ciscoios-inspectionengine-dos(74435)</ref>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-zbfw" source="CISCO" adv="1">20120328 Cisco IOS Software Zone-Based Firewall Vulnerabilities</ref>
      <ref url="http://osvdb.org/80697" source="OSVDB">80697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.4"/>
        <vers num="15.0"/>
        <vers num="15.1"/>
        <vers num="15.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0388" published="2012-03-29" name="CVE-2012-0388" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Memory leak in the H.323 inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed transit H.323 traffic, aka Bug ID CSCtq45553.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74436" source="XF">ciscoios-h323messages-dos(74436)</ref>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-zbfw" source="CISCO" adv="1">20120328 Cisco IOS Software Zone-Based Firewall Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.4"/>
        <vers num="15.0"/>
        <vers num="15.1"/>
        <vers num="15.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0389" published="2012-01-24" name="CVE-2012-0389" modified="2012-02-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.53, and 6.x before 6.03 allows remote attackers to inject arbitrary web script or HTML via the Username parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.mailenable.com/kb/Content/Article.asp?ID=me020567" source="CONFIRM" patch="1" adv="1">http://www.mailenable.com/kb/Content/Article.asp?ID=me020567</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/72380" source="XF">mailenable-forgottenpassword-xss(72380)</ref>
      <ref url="http://www.securitytracker.com/id?1026519" source="SECTRACK">1026519</ref>
      <ref url="http://www.securityfocus.com/bid/51401" source="BID">51401</ref>
      <ref url="http://www.nerv.fi/CVE-2012-0389.txt" source="MISC">http://www.nerv.fi/CVE-2012-0389.txt</ref>
      <ref url="http://www.exploit-db.com/exploits/18447" source="EXPLOIT-DB">18447</ref>
      <ref url="http://secunia.com/advisories/47562" source="SECUNIA" adv="1">47562</ref>
      <ref url="http://secunia.com/advisories/47518" source="SECUNIA" adv="1">47518</ref>
      <ref url="http://osvdb.org/78242" source="OSVDB">78242</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-01/0090.html" source="BUGTRAQ">20120112 ME020567: MailEnable webmail cross-site scripting vulnerability CVE-2012-0389</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable">
        <vers num="1.00" edition=""/>
        <vers num="1.00" edition=":enterprise"/>
        <vers num="1.01" edition=""/>
        <vers num="1.01" edition=":enterprise"/>
        <vers num="1.02" edition=""/>
        <vers num="1.02" edition=":enterprise"/>
        <vers num="1.03" edition=""/>
        <vers num="1.03" edition=":enterprise"/>
        <vers num="1.04" edition=""/>
        <vers num="1.04" edition=":enterprise"/>
        <vers num="1.1" edition=""/>
        <vers num="1.1" edition=":enterprise"/>
        <vers num="1.17" edition=""/>
        <vers num="1.17" edition=":professional"/>
        <vers num="1.18" edition=""/>
        <vers num="1.18" edition=":professional"/>
        <vers num="1.19" edition=""/>
        <vers num="1.19" edition=":professional"/>
        <vers num="1.2" edition=""/>
        <vers num="1.2" edition=":enterprise"/>
        <vers num="1.2" edition=":professional"/>
        <vers num="1.21" edition=""/>
        <vers num="1.21" edition=":enterprise"/>
        <vers num="1.22" edition=""/>
        <vers num="1.22" edition=":enterprise"/>
        <vers num="1.23" edition=""/>
        <vers num="1.23" edition=":enterprise"/>
        <vers num="1.24" edition=""/>
        <vers num="1.24" edition=":enterprise"/>
        <vers num="1.25" edition=""/>
        <vers num="1.25" edition=":enterprise"/>
        <vers num="1.26" edition=""/>
        <vers num="1.26" edition=":enterprise"/>
        <vers num="1.2a" edition=""/>
        <vers num="1.2a" edition=":professional"/>
        <vers num="1.5" edition=""/>
        <vers num="1.5" edition=":professional"/>
        <vers num="1.51" edition=""/>
        <vers num="1.51" edition=":professional"/>
        <vers num="1.52" edition=""/>
        <vers num="1.52" edition=":professional"/>
        <vers num="1.53" edition=""/>
        <vers num="1.53" edition=":professional"/>
        <vers num="1.54" edition=""/>
        <vers num="1.54" edition=":professional"/>
        <vers num="1.6" edition=""/>
        <vers num="1.6" edition=":professional"/>
        <vers num="1.7" edition=""/>
        <vers num="1.7" edition=":professional"/>
        <vers num="1.70" edition=""/>
        <vers num="1.70" edition=":professional"/>
        <vers num="1.71" edition=""/>
        <vers num="1.71" edition=":professional"/>
        <vers num="1.72" edition=""/>
        <vers num="1.72" edition=":professional"/>
        <vers num="1.73" edition=""/>
        <vers num="1.73" edition=":professional"/>
        <vers num="1.74" edition=""/>
        <vers num="1.74" edition=":professional"/>
        <vers num="1.75" edition=""/>
        <vers num="1.75" edition=":professional"/>
        <vers num="1.76" edition=""/>
        <vers num="1.76" edition=":professional"/>
        <vers num="1.77" edition=""/>
        <vers num="1.77" edition=":professional"/>
        <vers num="1.78" edition=""/>
        <vers num="1.78" edition=":professional"/>
        <vers num="1.79" edition=""/>
        <vers num="1.79" edition=":professional"/>
        <vers num="3.0" edition="-"/>
        <vers num="3.0" edition="-:pro"/>
        <vers num="3.0" edition="-:enterprise"/>
        <vers num="3.01" edition="-"/>
        <vers num="3.01" edition="-:pro"/>
        <vers num="3.01" edition="-:enterprise"/>
        <vers num="3.02" edition="-"/>
        <vers num="3.02" edition="-:enterprise"/>
        <vers num="3.02" edition="-:pro"/>
        <vers num="3.03" edition="-"/>
        <vers num="3.03" edition="-:enterprise"/>
        <vers num="3.03" edition="-:pro"/>
        <vers num="3.04" edition="-"/>
        <vers num="3.04" edition="-:enterprise"/>
        <vers num="3.04" edition="-:pro"/>
        <vers num="3.10" edition="-"/>
        <vers num="3.10" edition="-:enterprise"/>
        <vers num="3.10" edition="-:pro"/>
        <vers num="3.11" edition="-"/>
        <vers num="3.11" edition="-:enterprise"/>
        <vers num="3.11" edition="-:pro"/>
        <vers num="3.12" edition="-"/>
        <vers num="3.12" edition="-:pro"/>
        <vers num="3.12" edition="-:enterprise"/>
        <vers num="3.13" edition="-"/>
        <vers num="3.13" edition="-:pro"/>
        <vers num="3.13" edition="-:enterprise"/>
        <vers num="3.14" edition="-"/>
        <vers num="3.14" edition="-:pro"/>
        <vers num="3.14" edition="-:enterprise"/>
        <vers num="3.5" edition="-"/>
        <vers num="3.5" edition="-:pro"/>
        <vers num="3.5" edition="-:enterprise"/>
        <vers num="3.51" edition="-"/>
        <vers num="3.51" edition="-:enterprise"/>
        <vers num="3.51" edition="-:pro"/>
        <vers num="3.52" edition=""/>
        <vers num="3.52" edition=":professional"/>
        <vers num="3.52" edition=":enterprise"/>
        <vers num="3.52" edition="-"/>
        <vers num="3.52" edition="-:pro"/>
        <vers num="3.52" edition="-:enterprise"/>
        <vers num="3.53" edition="-"/>
        <vers num="3.53" edition="-:enterprise"/>
        <vers num="3.53" edition="-:pro"/>
        <vers num="3.6" edition="-"/>
        <vers num="3.6" edition="-:enterprise"/>
        <vers num="3.6" edition="-:pro"/>
        <vers num="3.61" edition="-"/>
        <vers num="3.61" edition="-:pro"/>
        <vers num="3.61" edition="-:enterprise"/>
        <vers num="3.62" edition="-"/>
        <vers num="3.62" edition="-:enterprise"/>
        <vers num="3.62" edition="-:pro"/>
        <vers num="3.63" edition="-"/>
        <vers num="3.63" edition="-:pro"/>
        <vers num="3.63" edition="-:enterprise"/>
        <vers num="4.0" edition="-"/>
        <vers num="4.0" edition="-:enterprise"/>
        <vers num="4.0" edition="-:pro"/>
        <vers num="4.01" edition="-"/>
        <vers num="4.01" edition="-:enterprise"/>
        <vers num="4.01" edition="-:pro"/>
        <vers num="4.1" edition=""/>
        <vers num="4.1" edition=":premium"/>
        <vers num="4.1" edition="-"/>
        <vers num="4.1" edition="-:enterprise"/>
        <vers num="4.1" edition="-:pro"/>
        <vers num="4.11" edition="-"/>
        <vers num="4.11" edition="-:pro"/>
        <vers num="4.11" edition="-:enterprise"/>
        <vers num="4.12" edition="-"/>
        <vers num="4.12" edition="-:enterprise"/>
        <vers num="4.12" edition="-:pro"/>
        <vers num="4.13" edition="-"/>
        <vers num="4.13" edition="-:enterprise"/>
        <vers num="4.13" edition="-:pro"/>
        <vers num="4.14" edition="-"/>
        <vers num="4.14" edition="-:enterprise"/>
        <vers num="4.14" edition="-:pro"/>
        <vers num="4.15" edition="-"/>
        <vers num="4.15" edition="-:enterprise"/>
        <vers num="4.15" edition="-:pro"/>
        <vers num="4.16" edition="-"/>
        <vers num="4.16" edition="-:pro"/>
        <vers num="4.16" edition="-:enterprise"/>
        <vers num="4.17" edition="-"/>
        <vers num="4.17" edition="-:pro"/>
        <vers num="4.17" edition="-:enterprise"/>
        <vers num="4.2" edition=""/>
        <vers num="4.2" edition=":premium"/>
        <vers num="4.21" edition=""/>
        <vers num="4.21" edition=":premium"/>
        <vers num="4.22" edition=""/>
        <vers num="4.22" edition=":premium"/>
        <vers num="4.22" edition="-"/>
        <vers num="4.22" edition="-:pro"/>
        <vers num="4.22" edition="-:enterprise"/>
        <vers num="4.23" edition=""/>
        <vers num="4.23" edition=":premium"/>
        <vers num="4.23" edition="-"/>
        <vers num="4.23" edition="-:enterprise"/>
        <vers num="4.23" edition="-:pro"/>
        <vers num="4.24" edition=""/>
        <vers num="4.24" edition=":premium"/>
        <vers num="4.24" edition="-"/>
        <vers num="4.24" edition="-:enterprise"/>
        <vers num="4.24" edition="-:pro"/>
        <vers num="4.25" edition=""/>
        <vers num="4.25" edition=":premium"/>
        <vers num="4.25" edition="-"/>
        <vers num="4.25" edition="-:pro"/>
        <vers num="4.25" edition="-:enterprise"/>
        <vers prev="1" num="4.26" edition=""/>
        <vers prev="1" num="4.26" edition=":premium"/>
        <vers prev="1" num="4.26" edition="-"/>
        <vers prev="1" num="4.26" edition="-:pro"/>
        <vers prev="1" num="4.26" edition="-:enterprise"/>
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":premium"/>
        <vers num="5.0" edition=":professional"/>
        <vers num="5.0" edition=":enterprise"/>
        <vers num="5.01" edition=""/>
        <vers num="5.01" edition=":professional"/>
        <vers num="5.01" edition=":enterprise"/>
        <vers num="5.01" edition=":premium"/>
        <vers num="5.02" edition=""/>
        <vers num="5.02" edition=":professional"/>
        <vers num="5.02" edition=":enterprise"/>
        <vers num="5.02" edition=":premium"/>
        <vers num="5.03" edition=""/>
        <vers num="5.03" edition=":premium"/>
        <vers num="5.03" edition=":professional"/>
        <vers num="5.03" edition=":enterprise"/>
        <vers num="5.04" edition=""/>
        <vers num="5.04" edition=":professional"/>
        <vers num="5.04" edition=":premium"/>
        <vers num="5.04" edition=":enterprise"/>
        <vers num="5.05" edition=""/>
        <vers num="5.05" edition=":enterprise"/>
        <vers num="5.05" edition=":premium"/>
        <vers num="5.05" edition=":professional"/>
        <vers num="5.06" edition=""/>
        <vers num="5.06" edition=":premium"/>
        <vers num="5.06" edition=":enterprise"/>
        <vers num="5.06" edition=":professional"/>
        <vers num="5.07" edition=""/>
        <vers num="5.07" edition=":premium"/>
        <vers num="5.07" edition=":professional"/>
        <vers num="5.07" edition=":enterprise"/>
        <vers num="5.10" edition=""/>
        <vers num="5.10" edition=":premium"/>
        <vers num="5.10" edition=":enterprise"/>
        <vers num="5.10" edition=":professional"/>
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":premium"/>
        <vers num="5.11" edition=":professional"/>
        <vers num="5.11" edition=":enterprise"/>
        <vers num="5.5" edition=""/>
        <vers num="5.5" edition=":professional"/>
        <vers num="5.5" edition=":premium"/>
        <vers num="5.5" edition=":enterprise"/>
        <vers num="5.51" edition=""/>
        <vers num="5.51" edition=":professional"/>
        <vers num="5.51" edition=":enterprise"/>
        <vers num="5.51" edition=":premium"/>
        <vers num="5.52" edition=""/>
        <vers num="5.52" edition=":professional"/>
        <vers num="5.52" edition=":premium"/>
        <vers num="5.52" edition=":enterprise"/>
        <vers num="6.0" edition=""/>
        <vers num="6.0" edition=":enterprise"/>
        <vers num="6.0" edition=":premium"/>
        <vers num="6.0" edition=":professional"/>
        <vers num="6.01" edition=""/>
        <vers num="6.01" edition=":premium"/>
        <vers num="6.01" edition=":professional"/>
        <vers num="6.01" edition=":enterprise"/>
        <vers num="6.02" edition=""/>
        <vers num="6.02" edition=":enterprise"/>
        <vers num="6.02" edition=":professional"/>
        <vers num="6.02" edition=":premium"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0390" published="2012-01-05" name="CVE-2012-0390" modified="2012-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.isg.rhul.ac.uk/~kp/dtls.pdf" source="MISC">http://www.isg.rhul.ac.uk/~kp/dtls.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gnutls">
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.1-x86"/>
        <vers num="2.10.2"/>
        <vers num="2.10.2-x86"/>
        <vers num="2.10.3"/>
        <vers num="2.10.4"/>
        <vers num="2.10.5"/>
        <vers num="2.10.5-x86"/>
        <vers num="2.12.0"/>
        <vers num="2.12.1"/>
        <vers num="2.12.10"/>
        <vers num="2.12.11"/>
        <vers num="2.12.12"/>
        <vers num="2.12.13"/>
        <vers num="2.12.14"/>
        <vers num="2.12.2"/>
        <vers num="2.12.3"/>
        <vers num="2.12.4"/>
        <vers num="2.12.5"/>
        <vers num="2.12.6"/>
        <vers num="2.12.6.1"/>
        <vers num="2.12.7"/>
        <vers num="2.12.8"/>
        <vers num="2.12.9"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="2.8.2"/>
        <vers num="2.8.3"/>
        <vers num="2.8.4"/>
        <vers num="2.8.5"/>
        <vers num="2.8.6"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers prev="1" num="3.0.10"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0391" published="2012-01-08" name="CVE-2012-0391" modified="2012-01-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt" source="MISC">https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt</ref>
      <ref url="https://issues.apache.org/jira/browse/WW-3668" source="CONFIRM">https://issues.apache.org/jira/browse/WW-3668</ref>
      <ref url="http://www.exploit-db.com/exploits/18329" source="EXPLOIT-DB">18329</ref>
      <ref url="http://struts.apache.org/2.x/docs/version-notes-2311.html" source="CONFIRM">http://struts.apache.org/2.x/docs/version-notes-2311.html</ref>
      <ref url="http://struts.apache.org/2.x/docs/s2-008.html" source="CONFIRM" adv="1">http://struts.apache.org/2.x/docs/s2-008.html</ref>
      <ref url="http://secunia.com/advisories/47393" source="SECUNIA" adv="1">47393</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html" source="BUGTRAQ">20120105 SEC Consult SA-20120104-0 :: Multiple critical vulnerabilities in Apache Struts2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="struts">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.11.1"/>
        <vers num="2.0.11.2"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.8"/>
        <vers num="2.1.8.1"/>
        <vers num="2.2.1"/>
        <vers num="2.2.1.1"/>
        <vers prev="1" num="2.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0392" published="2012-01-08" name="CVE-2012-0392" modified="2012-01-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt" source="MISC">https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt</ref>
      <ref url="https://lists.immunityinc.com/pipermail/dailydave/2012-January/000011.html" source="MLIST">[dailydave] 20120106 Apache Struts</ref>
      <ref url="http://www.exploit-db.com/exploits/18329" source="EXPLOIT-DB">18329</ref>
      <ref url="http://struts.apache.org/2.x/docs/version-notes-2311.html" source="CONFIRM">http://struts.apache.org/2.x/docs/version-notes-2311.html</ref>
      <ref url="http://struts.apache.org/2.x/docs/s2-008.html" source="CONFIRM" adv="1">http://struts.apache.org/2.x/docs/s2-008.html</ref>
      <ref url="http://secunia.com/advisories/47393" source="SECUNIA" adv="1">47393</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html" source="BUGTRAQ">20120105 SEC Consult SA-20120104-0 :: Multiple critical vulnerabilities in Apache Struts2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="struts">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.11.1"/>
        <vers num="2.0.11.2"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.8"/>
        <vers num="2.1.8.1"/>
        <vers num="2.2.1"/>
        <vers num="2.2.1.1"/>
        <vers prev="1" num="2.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0393" published="2012-01-08" name="CVE-2012-0393" modified="2012-01-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt" source="MISC">https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt</ref>
      <ref url="http://www.exploit-db.com/exploits/18329" source="EXPLOIT-DB">18329</ref>
      <ref url="http://struts.apache.org/2.x/docs/version-notes-2311.html" source="CONFIRM">http://struts.apache.org/2.x/docs/version-notes-2311.html</ref>
      <ref url="http://struts.apache.org/2.x/docs/s2-008.html" source="CONFIRM" adv="1">http://struts.apache.org/2.x/docs/s2-008.html</ref>
      <ref url="http://secunia.com/advisories/47393" source="SECUNIA" adv="1">47393</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html" source="BUGTRAQ">20120105 SEC Consult SA-20120104-0 :: Multiple critical vulnerabilities in Apache Struts2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="struts">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.11.1"/>
        <vers num="2.0.11.2"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.8"/>
        <vers num="2.1.8.1"/>
        <vers num="2.2.1"/>
        <vers num="2.2.1.1"/>
        <vers num="2.2.3"/>
        <vers prev="1" num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0394" published="2012-01-08" name="CVE-2012-0394" modified="2012-01-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">** DISPUTED ** The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors.  NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt" source="MISC">https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt</ref>
      <ref url="http://www.exploit-db.com/exploits/18329" source="EXPLOIT-DB">18329</ref>
      <ref url="http://struts.apache.org/2.x/docs/version-notes-2311.html" source="MISC">http://struts.apache.org/2.x/docs/version-notes-2311.html</ref>
      <ref url="http://struts.apache.org/2.x/docs/s2-008.html" source="MISC" adv="1">http://struts.apache.org/2.x/docs/s2-008.html</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html" source="BUGTRAQ">20120105 SEC Consult SA-20120104-0 :: Multiple critical vulnerabilities in Apache Struts2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="struts">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.11.1"/>
        <vers num="2.0.11.2"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.8"/>
        <vers num="2.1.8.1"/>
        <vers num="2.2.1"/>
        <vers num="2.2.1.1"/>
        <vers prev="1" num="2.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0395" published="2012-01-26" name="CVE-2012-0395" modified="2012-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the server in EMC NetWorker 7.5.x and 7.6.x before 7.6.3 SP1 Cumulative Release build 851 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/521374" source="BUGTRAQ">20120126 ESA-2012-005: EMC NetWorker buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="networker">
        <vers num="7.5" edition="sp1"/>
        <vers num="7.5" edition="sp2"/>
        <vers num="7.5" edition="sp3"/>
        <vers num="7.5.2.0"/>
        <vers num="7.5.2.1"/>
        <vers num="7.5.2.2"/>
        <vers num="7.5.2.3"/>
        <vers num="7.5.2.4"/>
        <vers num="7.5.3"/>
        <vers num="7.5.3.1"/>
        <vers num="7.5.3.2"/>
        <vers num="7.5.3.3"/>
        <vers num="7.5.3.4"/>
        <vers num="7.5.3.5"/>
        <vers num="7.5.4"/>
        <vers num="7.5.4.1"/>
        <vers num="7.5.4.2"/>
        <vers num="7.5.4.3"/>
        <vers num="7.6" edition="sp1"/>
        <vers num="7.6" edition="sp2"/>
        <vers num="7.6.0.2"/>
        <vers num="7.6.0.3"/>
        <vers num="7.6.0.4"/>
        <vers num="7.6.0.5"/>
        <vers num="7.6.0.6"/>
        <vers num="7.6.0.7"/>
        <vers num="7.6.0.8"/>
        <vers num="7.6.0.9"/>
        <vers num="7.6.1"/>
        <vers num="7.6.1.1"/>
        <vers num="7.6.1.2"/>
        <vers num="7.6.1.3"/>
        <vers num="7.6.1.4"/>
        <vers num="7.6.1.5"/>
        <vers num="7.6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0396" published="2012-02-06" name="CVE-2012-0396" modified="2012-02-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">EMC Documentum xPlore 1.0, 1.1 before P07, and 1.2 does not properly enforce the requirement for BROWSE permission, which allows remote authenticated users to determine the existence of an object, or read object metadata, via a search.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/72994" source="XF">emc-documentum-info-disc(72994)</ref>
      <ref url="http://www.securityfocus.com/bid/51863" source="BID">51863</ref>
      <ref url="http://securitytracker.com/id?1026639" source="SECTRACK">1026639</ref>
      <ref url="http://secunia.com/advisories/47920" source="SECUNIA" adv="1">47920</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-02/0020.html" source="BUGTRAQ">20120203 ESA-2012-010: EMC Documentum xPlore information disclosure vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="documentum_xplore">
        <vers num="1.0"/>
        <vers num="1.1" edition="p01"/>
        <vers num="1.1" edition="p03"/>
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0397" published="2012-03-06" name="CVE-2012-0397" modified="2012-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in EMC RSA SecurID Software Token Converter before 2.6.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/521885" source="BUGTRAQ">20120305 ESA-2012-013: RSA SecurID(r) Software Token Converter buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="securid_software_token_converter">
        <vers prev="1" num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0398" published="2012-03-14" name="CVE-2012-0398" modified="2012-03-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EMC Documentum eRoom before 7.4.4 does not properly validate session cookies, which allows remote attackers to hijack or replay sessions via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-03/0057.html" source="BUGTRAQ">20120313 ESA-2012-012: EMC Documentum eRoom Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="documentum_eroom">
        <vers num="7.3.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers prev="1" num="7.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0399" published="2012-03-20" name="CVE-2012-0399" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/52557" source="BID">52557</ref>
      <ref url="http://secunia.com/advisories/48484" source="SECUNIA">48484</ref>
      <ref url="http://osvdb.org/80206" source="OSVDB">80206</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-03/0081.html" source="BUGTRAQ">20120318 ESA-2012-014: RSA enVision Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="envision">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0400" published="2012-03-20" name="CVE-2012-0400" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="7.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="5.5" CVSS_base_score="7.9">
    <desc>
      <descript source="cve">EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74140" source="XF">envision-weak-security(74140)</ref>
      <ref url="http://www.securityfocus.com/bid/52557" source="BID">52557</ref>
      <ref url="http://secunia.com/advisories/48484" source="SECUNIA">48484</ref>
      <ref url="http://osvdb.org/80207" source="OSVDB">80207</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-03/0081.html" source="BUGTRAQ">20120318 ESA-2012-014: RSA enVision Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="envision">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0401" published="2012-03-20" name="CVE-2012-0401" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74137" source="XF">envision-unspec-sql-injection(74137)</ref>
      <ref url="http://www.securityfocus.com/bid/52557" source="BID">52557</ref>
      <ref url="http://secunia.com/advisories/48484" source="SECUNIA">48484</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-03/0081.html" source="BUGTRAQ">20120318 ESA-2012-014: RSA enVision Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="envision">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0402" published="2012-03-20" name="CVE-2012-0402" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74138" source="XF">envision-default-account(74138)</ref>
      <ref url="http://www.securityfocus.com/bid/52557" source="BID">52557</ref>
      <ref url="http://secunia.com/advisories/48484" source="SECUNIA">48484</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-03/0081.html" source="BUGTRAQ">20120318 ESA-2012-014: RSA enVision Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="envision">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0403" published="2012-03-20" name="CVE-2012-0403" modified="2013-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:N/A:N)" CVSS_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_base_score="6.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in EMC RSA enVision 4.x before 4.1 Patch 4 allows remote authenticated users to have an unspecified impact via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/74139" source="XF">envision-unspec-dir-traversal(74139)</ref>
      <ref url="http://www.securityfocus.com/bid/52557" source="BID">52557</ref>
      <ref url="http://secunia.com/advisories/48484" source="SECUNIA">48484</ref>
      <ref url="http://osvdb.org/80210" source="OSVDB">80210</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-03/0081.html" source="BUGTRAQ">20120318 ESA-2012-014: RSA enVision Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="envision">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0404" published="2012-03-14" name="CVE-2012-0404" modified="2012-03-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in EMC Documentum eRoom before 7.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-03/0057.html" source="BUGTRAQ">20120313 ESA-2012-012: EMC Documentum eRoom Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="documentum_eroom">
        <vers num="7.3.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers prev="1" num="7.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0406" published="2012-04-20" name="CVE-2012-0406" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an AUTHENTICATECONNECTION command that (1) lacks a password field or (2) has an empty password.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1026956" source="SECTRACK">1026956</ref>
      <ref url="http://www.securityfocus.com/archive/1/522408/30/0/threaded" source="BUGTRAQ">20120418 ESA-2012-018: EMC Data Protection Advisor Multiple Vulnerabilities</ref>
      <ref url="http://www.exploit-db.com/exploits/18688/" source="EXPLOIT-DB">18688</ref>
      <ref url="http://aluigi.altervista.org/adv/dpa_1-adv.txt" source="MISC">http://aluigi.altervista.org/adv/dpa_1-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="data_protection_advisor">
        <vers num="5.5" edition="sp1"/>
        <vers num="5.6" edition="sp1"/>
        <vers num="5.7" edition="sp1"/>
        <vers num="5.8" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0407" published="2012-04-20" name="CVE-2012-0407" modified="2012-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the DPA_Utilities library in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (infinite loop) via a negative 64-bit value in a certain size field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1026956" source="SECTRACK">1026956</ref>
      <ref url="http://www.securityfocus.com/archive/1/522408/30/0/threaded" source="BUGTRAQ">20120418 ESA-2012-018: EMC Data Protection Advisor Multiple Vulnerabilities</ref>
      <ref url="http://www.exploit-db.com/exploits/18688/" source="EXPLOIT-DB">18688</ref>
      <ref url="http://aluigi.altervista.org/adv/dpa_1-adv.txt" source="MISC">http://aluigi.altervista.org/adv/dpa_1-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="data_protection_advisor">
        <vers num="5.5" edition="sp1"/>
        <vers num="5.6" edition="sp1"/>
        <vers num="5.7" edition="sp1"/>
        <vers num="5.8" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0409" published="2012-06-01" name="CVE-2012-0409" modified="2012-10-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in EMC AutoStart 5.3.x and 5.4.x before 5.4.3 allow remote attackers to cause a denial of service (agent crash) or possibly execute arbitrary code via crafted packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1027100" source="SECTRACK">1027100</ref>
      <ref url="http://www.securityfocus.com/bid/53682" source="BID">53682</ref>
      <ref url="http://www.securityfocus.com/archive/1/522835" source="BUGTRAQ">20120522 ESA-2012-020: EMC AutoStart Multiple Buffer Overflow Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="autostart">
        <vers num="5.3" edition="sp1"/>
        <vers num="5.3" edition="sp2"/>
        <vers num="5.3" edition="sp3"/>
        <vers num="5.4"/>
        <vers num="5.4.1"/>
        <vers num="5.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0410" published="2012-07-05" name="CVE-2012-0410" modified="2013-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WebAccess in Novell GroupWise before 8.03 allows remote attackers to read arbitrary files via the User.interface parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=712163" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=712163</ref>
      <ref url="http://www.securitytracker.com/id?1027217" source="SECTRACK">1027217</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7000708" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7000708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="5.2"/>
        <vers num="5.5"/>
        <vers num="5.57e"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition="sp1"/>
        <vers num="6.5" edition="sp1"/>
        <vers num="6.5" edition="sp2"/>
        <vers num="6.5" edition="sp3"/>
        <vers num="6.5" edition="sp4"/>
        <vers num="6.5" edition="sp5"/>
        <vers num="6.5" edition="sp6"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="7.0"/>
        <vers num="7.0.3" edition="hp4"/>
        <vers num="7.0.3" edition="hp5"/>
        <vers num="7.0.4" edition="ftf"/>
        <vers num="7.01" edition="ir1"/>
        <vers num="7.02" edition="hp1"/>
        <vers num="7.02" edition="hp1a"/>
        <vers num="7.02" edition="hp2"/>
        <vers num="7.02" edition="hp2r1"/>
        <vers num="7.03" edition="hp"/>
        <vers num="7.03" edition="hp2"/>
        <vers num="7.03" edition="hp3"/>
        <vers num="7.03" edition="hp3+ftf"/>
        <vers num="8.0"/>
        <vers num="8.00" edition="hp1"/>
        <vers num="8.00" edition="hp2"/>
        <vers num="8.01" edition="hp"/>
        <vers prev="1" num="8.02" edition="hp1"/>
        <vers prev="1" num="8.02" edition="hp2"/>
        <vers prev="1" num="8.02" edition="hp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0411" published="2012-12-24" name="CVE-2012-0411" modified="2013-01-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Novell iPrint Client before 5.82 allows remote attackers to execute arbitrary code via an op-client-interface-version action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7008708" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7008708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="iprint">
        <vers num="4.26"/>
        <vers num="4.27"/>
        <vers num="4.28"/>
        <vers num="4.30"/>
        <vers num="4.32"/>
        <vers num="4.34"/>
        <vers num="4.36"/>
        <vers num="4.38"/>
        <vers num="5.04"/>
        <vers num="5.12"/>
        <vers num="5.20b"/>
        <vers num="5.30"/>
        <vers num="5.32"/>
        <vers num="5.40"/>
        <vers num="5.42"/>
        <vers num="5.44"/>
        <vers num="5.50"/>
        <vers num="5.52"/>
        <vers num="5.56"/>
        <vers num="5.60"/>
        <vers num="5.64"/>
        <vers num="5.68"/>
        <vers num="5.72"/>
        <vers num="5.74"/>
        <vers prev="1" num="5.78"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0417" published="2012-09-28" name="CVE-2012-0417" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://download.novell.com/Download?buildid=O5hTjIiMdMo~" source="CONFIRM" patch="1">http://download.novell.com/Download?buildid=O5hTjIiMdMo~</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=740041" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=740041</ref>
      <ref url="http://www.securitytracker.com/id?1027599" source="SECTRACK">1027599</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7010770" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7010770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="2012"/>
        <vers num="8.0"/>
        <vers num="8.00" edition="hp1"/>
        <vers num="8.00" edition="hp2"/>
        <vers num="8.00" edition="hp3"/>
        <vers num="8.01" edition="hp"/>
        <vers num="8.02" edition="hp1"/>
        <vers num="8.02" edition="hp2"/>
        <vers num="8.02" edition="hp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0418" published="2012-09-28" name="CVE-2012-0418" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the client in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://download.novell.com/Download?buildid=O5hTjIiMdMo~" source="CONFIRM" patch="1">http://download.novell.com/Download?buildid=O5hTjIiMdMo~</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=752521" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=752521</ref>
      <ref url="http://www.securityfocus.com/bid/55729" source="BID">55729</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7010771" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7010771</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="2012"/>
        <vers num="8.0"/>
        <vers num="8.00" edition="hp1"/>
        <vers num="8.00" edition="hp2"/>
        <vers num="8.00" edition="hp3"/>
        <vers num="8.01" edition="hp"/>
        <vers num="8.02" edition="hp1"/>
        <vers num="8.02" edition="hp2"/>
        <vers num="8.02" edition="hp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0419" published="2012-09-28" name="CVE-2012-0419" modified="2013-04-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrary files via directory traversal sequences in a request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://download.novell.com/Download?buildid=O5hTjIiMdMo~" source="CONFIRM" patch="1">http://download.novell.com/Download?buildid=O5hTjIiMdMo~</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=756924" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=756924</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=756330" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=756330</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7010772" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7010772</ref>
      <ref url="http://seclists.org/fulldisclosure/2012/Sep/161" source="FULLDISC">20120921 DDIVRT-2012-42 Novell GroupWise Agents Arbitrary File Retrieval (CVE-2012-0419)</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2012-09/0106.html" source="BUGTRAQ">20120921 DDIVRT-2012-42 Novell GroupWise Agents Arbitrary File Retrieval (CVE-2012-0419)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="2012"/>
        <vers num="8.0"/>
        <vers num="8.00" edition="hp1"/>
        <vers num="8.00" edition="hp2"/>
        <vers num="8.00" edition="hp3"/>
        <vers num="8.01" edition="hp"/>
        <vers num="8.02" edition="hp1"/>
        <vers num="8.02" edition="hp2"/>
        <vers num="8.02" edition="hp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-0421" published="2012-08-08" name="CVE-2012-0421" modified="2012-08-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The SUSE Audit Log Keeper daemon before 0.2.1-0.4.6.1 for SUSE Manager and Spacewalk uses world-readable permissions for /etc/auditlog-keeper.conf, which allows local users to obtain passwords by reading this file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/771335" source="CONFIRM">https://bugzilla.novell.com/771335</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00001.html" source="SUSE" adv="1">SUSE-SU-2012:0958</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="suse_audit_log_keeper">
        <vers prev="1" num="0.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0428" published="2012-12-25" name="CVE-2012-0428" modified="2013-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=772899" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=772899</ref>
      <ref url="http://www.securitytracker.com/id?1027911" source="SECTRACK">1027911</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7011539" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7011539</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=3426981" source="CONFIRM">http://www.novell.com/support/kb/doc.php?id=3426981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netiq" name="edirectory">
        <vers num="8.8.6.0"/>
        <vers num="8.8.6.1"/>
        <vers num="8.8.6.2"/>
        <vers num="8.8.6.3"/>
        <vers num="8.8.6.4"/>
        <vers num="8.8.6.5"/>
        <vers num="8.8.6.6"/>
        <vers num="8.8.7.0"/>
        <vers num="8.8.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0429" published="2012-12-25" name="CVE-2012-0429" modified="2013-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">dhost in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote authenticated users to cause a denial of service (daemon crash) via crafted characters in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=772895" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=772895</ref>
      <ref url="http://www.securitytracker.com/id?1027912" source="SECTRACK">1027912</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7011533" source="CONFIRM">http://www.novell.com/support/kb/doc.php?id=7011533</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=3426981" source="CONFIRM">http://www.novell.com/support/kb/doc.php?id=3426981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netiq" name="edirectory">
        <vers num="8.8.6.0" edition="-"/>
        <vers num="8.8.6.0" edition="-:~~~windows~~"/>
        <vers num="8.8.6.1" edition="-"/>
        <vers num="8.8.6.1" edition="-:~~~windows~~"/>
        <vers num="8.8.6.2" edition="-"/>
        <vers num="8.8.6.2" edition="-:~~~windows~~"/>
        <vers num="8.8.6.3" edition="-"/>
        <vers num="8.8.6.3" edition="-:~~~windows~~"/>
        <vers num="8.8.6.4" edition="-"/>
        <vers num="8.8.6.4" edition="-:~~~windows~~"/>
        <vers num="8.8.6.5" edition="-"/>
        <vers num="8.8.6.5" edition="-:~~~windows~~"/>
        <vers num="8.8.6.6" edition="-"/>
        <vers num="8.8.6.6" edition="-:~~~windows~~"/>
        <vers num="8.8.7.0" edition="-"/>
        <vers num="8.8.7.0" edition="-:~~~windows~~"/>
        <vers num="8.8.7.1" edition="-"/>
        <vers num="8.8.7.1" edition="-:~~~windows~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0430" published="2012-12-25" name="CVE-2012-0430" modified="2013-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an administrator cookie and bypass authorization checks via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=772898" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=772898</ref>
      <ref url="http://www.securitytracker.com/id?1027910" source="SECTRACK">1027910</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7011538" source="CONFIRM">http://www.novell.com/support/kb/doc.php?id=7011538</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=3426981" source="CONFIRM">http://www.novell.com/support/kb/doc.php?id=3426981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netiq" name="edirectory">
        <vers num="8.8.6.0" edition="-"/>
        <vers num="8.8.6.0" edition="-:~~~windows~~"/>
        <vers num="8.8.6.1" edition="-"/>
        <vers num="8.8.6.1" edition="-:~~~windows~~"/>
        <vers num="8.8.6.2" edition="-"/>
        <vers num="8.8.6.2" edition="-:~~~windows~~"/>
        <vers num="8.8.6.3" edition="-"/>
        <vers num="8.8.6.3" edition="-:~~~windows~~"/>
        <vers num="8.8.6.4" edition="-"/>
        <vers num="8.8.6.4" edition="-:~~~windows~~"/>
        <vers num="8.8.6.5" edition="-"/>
        <vers num="8.8.6.5" edition="-:~~~windows~~"/>
        <vers num="8.8.6.6" edition="-"/>
        <vers num="8.8.6.6" edition="-:~~~windows~~"/>
        <vers num="8.8.7.0" edition="-"/>
        <vers num="8.8.7.0" edition="-:~~~windows~~"/>
        <vers num="8.8.7.1" edition="-"/>
        <vers num="8.8.7.1" edition="-:~~~windows~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0432" published="2012-12-25" name="CVE-2012-0432" modified="2013-01-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=785272" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=785272</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=3426981" source="CONFIRM">http://www.novell.com/support/kb/doc.php?id=3426981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netiq" name="edirectory">
        <vers num="8.8.7.0"/>
        <vers num="8.8.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0435" published="2013-01-26" name="CVE-2012-0435" modified="2013-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">SUSE WebYaST before 1.2 0.2.63-0.6.1 allows remote attackers to modify the hosts list, and subsequently conduct man-in-the-middle attacks, via a crafted /host request on TCP port 4984.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/806908" source="CERT-VN">VU#806908</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=792712" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=792712</ref>
      <ref url="http://support.novell.com/security/cve/CVE-2012-0435.html" source="CONFIRM">http://support.novell.com/security/cve/CVE-2012-0435.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00008.html" source="SUSE">SUSE-SU-2013:0053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="webyast">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-0439" published="2013-02-23" name="CVE-2012-0439" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=743674" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=743674</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=712144" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=712144</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-13-008/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-13-008/</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7011688" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7011688</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="2012" edition="sp1"/>
        <vers num="8.0"/>
        <vers num="8.00" edition="hp1"/>
        <vers num="8.00" edition="hp2"/>
        <vers num="8.00" edition="hp3"/>
        <vers num="8.01" edition="hp"/>
        <vers num="8.02" edition="hp1"/>
        <vers num="8.02" edition="hp2"/>
        <vers num="8.02" edition="hp3"/>
        <vers num="8.03" edition="hp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0440" published="2012-02-02" name="CVE-2012-0440" modified="2012-02-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 allows remote attackers to hijack the authentication of arbitrary users for requests that use the JSON-RPC API.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=718319" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=718319</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/72882" source="XF">bugzilla-jsonrpc-csrf(72882)</ref>
      <ref url="http://www.securitytracker.com/id?1026623" source="SECTRACK">1026623</ref>
      <ref url="http://www.bugzilla.org/security/3.4.13/" source="CONFIRM" adv="1">http://www.bugzilla.org/security/3.4.13/</ref>
      <ref url="http://secunia.com/advisories/47814" source="SECUNIA">47814</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.6" edition="rc1"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="4.0" edition="rc1"/>
        <vers num="4.0" edition="rc2"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.2" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-0441" published="2012-06-05" name="CVE-2012-0441" modified="2013-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=715073" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=715073</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1540-2" source="UBUNTU">USN-1540-2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1540-1" source="UBUNTU">USN-1540-1</ref>
      <ref url="http://www.securityfocus.com/bid/53798" source="BID">53798</ref>
      <ref url="http://www.mozilla.org/security/announce/2012/mfsa2012-39.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2012/mfsa2012-39.html</ref>
      <ref url="http://secunia.com/advisories/50316" source="SECUNIA">50316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="11.0"/>
        <vers num="12.0" edition="beta6"/>
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
        <vers num="4.0.1"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="8.0.1"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
      </prod>
      <prod vendor="mozilla" name="network_security_services">
        <vers num="3.11.2"/>
        <vers num="3.11.3"/>
        <vers num="3.11.4"/>
        <vers num="3.11.5"/>
        <vers num="3.12"/>
        <vers num="3.12.1"/>
        <vers num="3.12.2"/>
        <vers prev="1" num="3.12.3"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.4"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.5"/>
        <vers num="3.7.7"/>
        <vers num="3.8"/>
        <vers num="3.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
       