<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2013-06-19" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="Medium" seq="2013-0001" published="2013-01-09" name="CVE-2013-0001" modified="2013-01-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unmanaged memory location, aka "System Drawing Information Disclosure Vulnerability."</descript>
      <descript source="nvd">Per http://technet.microsoft.com/en-us/security/bulletin/ms13-004 Microsoft .NET Framework 3.0 Service Pack 2 is not vulnerable.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-004" source="MS" patch="1" adv="1">MS13-004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp3"/>
        <vers num="1.1" edition="sp1"/>
        <vers num="2.0" edition="sp2"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0002" published="2013-01-09" name="CVE-2013-0002" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memory copy operation, aka "WinForms Buffer Overflow Vulnerability."</descript>
      <descript source="nvd">Per http://technet.microsoft.com/en-us/security/bulletin/ms13-004 Microsoft .NET Framework 3.0 Service Pack 2 is not vulnerable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" source="CERT">TA13-008A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-004" source="MS" patch="1" adv="1">MS13-004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp3"/>
        <vers num="1.1" edition="sp1"/>
        <vers num="2.0" edition="sp2"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0003" published="2013-01-09" name="CVE-2013-0003" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory copy operation, aka "S.DS.P Buffer Overflow Vulnerability."</descript>
      <descript source="nvd">Per http://technet.microsoft.com/en-us/security/bulletin/ms13-004 Microsoft .NET Framework 3.0 Service Pack 2 is not vulnerable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" source="CERT">TA13-008A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-004" source="MS" patch="1" adv="1">MS13-004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="2.0" edition="sp2"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0004" published="2013-01-09" name="CVE-2013-0004" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Double Construction Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" source="CERT">TA13-008A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-004" source="MS" patch="1" adv="1">MS13-004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp3"/>
        <vers num="1.1" edition="sp1"/>
        <vers num="2.0" edition="sp2"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0005" published="2013-01-09" name="CVE-2013-0005" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" source="CERT">TA13-008A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-007" source="MS" adv="1">MS13-007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="3.5" edition="sp1"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
      </prod>
      <prod vendor="microsoft" name="management_odata_iis_extension">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0006" published="2013-01-09" name="CVE-2013-0006" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" source="CERT">TA13-008A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-002" source="MS" patch="1" adv="1">MS13-002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="expression_web">
        <vers num="" edition="sp1"/>
        <vers num="2"/>
      </prod>
      <prod vendor="microsoft" name="groove_server">
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="sharepoint_server">
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="word_viewer">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="xml_core_services">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x86"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_8">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_rt">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="-" edition="sp2:x64"/>
        <vers num="r2" edition="-"/>
        <vers num="r2" edition="-:x64"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2012">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0007" published="2013-01-09" name="CVE-2013-0007" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" source="CERT">TA13-008A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-002" source="MS" patch="1" adv="1">MS13-002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="expression_web">
        <vers num="" edition="sp1"/>
        <vers num="2"/>
      </prod>
      <prod vendor="microsoft" name="groove_server">
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="sharepoint_server">
        <vers num="2007" edition="sp2"/>
        <vers num="2007" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="word_viewer">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="xml_core_services">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x86"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_8">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_rt">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="-" edition="sp2:x64"/>
        <vers num="r2" edition="-"/>
        <vers num="r2" edition="-:x64"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2012">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0008" published="2013-01-09" name="CVE-2013-0008" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" source="CERT">TA13-008A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-005" source="MS" patch="1" adv="1">MS13-005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x86"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_8">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="-:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_rt">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2012">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0009" published="2013-01-09" name="CVE-2013-0009" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" source="CERT">TA13-008A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-003" source="MS" patch="1" adv="1">MS13-003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="system_center_operations_manager">
        <vers num="2007" edition="r2"/>
        <vers num="2007" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0010" published="2013-01-09" name="CVE-2013-0010" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" source="CERT">TA13-008A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-003" source="MS" patch="1" adv="1">MS13-003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="system_center_operations_manager">
        <vers num="2007" edition="r2"/>
        <vers num="2007" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0011" published="2013-01-09" name="CVE-2013-0011" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Print Spooler in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted print job, aka "Windows Print Spooler Components Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" source="CERT">TA13-008A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-001" source="MS" patch="1" adv="1">MS13-001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x86"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="r2:itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0013" published="2013-01-09" name="CVE-2013-0013" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to conduct SSLv2 downgrade attacks against (1) SSLv3 sessions or (2) TLS sessions by intercepting handshakes and injecting content, aka "Microsoft SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-008A.html" source="CERT">TA13-008A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-006" source="MS" patch="1" adv="1">MS13-006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x86"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_8">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="-:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_rt">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="r2:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2012">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0015" published="2013-02-13" name="CVE-2013-0015" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 9 does not properly perform auto-selection of the Shift JIS encoding, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers cross-domain scrolling events, aka "Shift JIS Character Encoding Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" patch="1" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0018" published="2013-02-13" name="CVE-2013-0018" modified="2013-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SetCapture Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" patch="1" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0019" published="2013-02-13" name="CVE-2013-0019" modified="2013-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer COmWindowProxy Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" patch="1" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0020" published="2013-02-13" name="CVE-2013-0020" modified="2013-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CMarkup Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" patch="1" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0021" published="2013-02-13" name="CVE-2013-0021" modified="2013-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer vtable Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" patch="1" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0022" published="2013-02-13" name="CVE-2013-0022" modified="2013-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer LsGetTrailInfo Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" patch="1" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0023" published="2013-02-13" name="CVE-2013-0023" modified="2013-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CDispNode Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" patch="1" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0024" published="2013-02-13" name="CVE-2013-0024" modified="2013-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer pasteHTML Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" patch="1" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="8"/>
        <vers num="9"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0025" published="2013-02-13" name="CVE-2013-0025" modified="2013-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" patch="1" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0026" published="2013-02-13" name="CVE-2013-0026" modified="2013-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer InsertElement Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" patch="1" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0027" published="2013-02-13" name="CVE-2013-0027" modified="2013-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CPasteCommand Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" patch="1" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0028" published="2013-02-13" name="CVE-2013-0028" modified="2013-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CObjectElement Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x86"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x86"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x86"/>
        <vers num="-" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="r2:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0029" published="2013-02-13" name="CVE-2013-0029" modified="2013-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CHTML Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-009" source="MS" patch="1" adv="1">MS13-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0030" published="2013-02-13" name="CVE-2013-0030" modified="2013-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Vector Markup Language (VML) implementation in Microsoft Internet Explorer 6 through 10 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via a crafted web site, aka "VML Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-010" source="MS" patch="1" adv="1">MS13-010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0073" published="2013-02-13" name="CVE-2013-0073" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "WinForms Callback Elevation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-015" source="MS" adv="1">MS13-015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="2.0" edition="sp2"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0074" published="2013-03-12" name="CVE-2013-0074" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-022" source="MS" adv="1">MS13-022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="silverlight">
        <vers num="5.0.60401.0"/>
        <vers num="5.0.60818.0" edition="rc"/>
        <vers prev="1" num="5.0.61118.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0075" published="2013-02-13" name="CVE-2013-0075" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-018" source="MS" patch="1" adv="1">MS13-018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x86"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_8">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="-:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_rt">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2012">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0076" published="2013-02-13" name="CVE-2013-0076" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Reference Count Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-019" source="MS" patch="1" adv="1">MS13-019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x86"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x86"/>
        <vers num="" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="r2:itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0077" published="2013-02-13" name="CVE-2013-0077" modified="2013-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Quartz.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via crafted media content in (1) a media file, (2) a media stream, or (3) a Microsoft Office document, aka "Media Decompression Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-011" source="MS" patch="1" adv="1">MS13-011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0078" published="2013-04-09" name="CVE-2013-0078" modified="2013-04-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.exe, which allows local users to gain privileges via a crafted application, aka "Microsoft Antimalware Improper Pathname Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-034" source="MS" adv="1">MS13-034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_defender">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0079" published="2013-03-12" name="CVE-2013-0079" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-023" source="MS" adv="1">MS13-023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_filter_pack">
        <vers num="2010" edition="sp1"/>
        <vers num="2010" edition="sp1:x86"/>
        <vers num="2010" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="visio">
        <vers num="2010" edition="sp1"/>
        <vers num="2010" edition="sp1:x64"/>
        <vers num="2010" edition="sp1:x86"/>
      </prod>
      <prod vendor="microsoft" name="visio_viewer">
        <vers num="2010" edition="sp1"/>
        <vers num="2010" edition="sp1:x86"/>
        <vers num="2010" edition="sp1:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0080" published="2013-03-12" name="CVE-2013-0080" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-024" source="MS" adv="1">MS13-024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_foundation">
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="sharepoint_server">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0083" published="2013-03-12" name="CVE-2013-0083" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via crafted content, leading to administrative command execution, aka "SharePoint XSS Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-024" source="MS" adv="1">MS13-024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_foundation">
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="sharepoint_server">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0084" published="2013-03-12" name="CVE-2013-0084" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-024" source="MS" adv="1">MS13-024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_foundation">
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="sharepoint_server">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0085" published="2013-03-12" name="CVE-2013-0085" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-024" source="MS" adv="1">MS13-024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_foundation">
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="sharepoint_server">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0086" published="2013-03-12" name="CVE-2013-0086" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-025" source="MS" adv="1">MS13-025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_foundation">
        <vers num="2010" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="sharepoint_server">
        <vers num="2010" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0087" published="2013-03-12" name="CVE-2013-0087" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer OnResize Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-021" source="MS" adv="1">MS13-021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0088" published="2013-03-12" name="CVE-2013-0088" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer saveHistory Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-021" source="MS" adv="1">MS13-021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0089" published="2013-03-12" name="CVE-2013-0089" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CMarkupBehaviorContext Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-021" source="MS" adv="1">MS13-021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0090" published="2013-03-12" name="CVE-2013-0090" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CCaret Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-021" source="MS" adv="1">MS13-021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0091" published="2013-03-12" name="CVE-2013-0091" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CElement Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-021" source="MS" adv="1">MS13-021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0092" published="2013-03-12" name="CVE-2013-0092" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer GetMarkupPtr Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-021" source="MS" adv="1">MS13-021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0093" published="2013-03-12" name="CVE-2013-0093" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer onBeforeCopy Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-021" source="MS" adv="1">MS13-021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0094" published="2013-03-12" name="CVE-2013-0094" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer removeChild Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-021" source="MS" adv="1">MS13-021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0095" published="2013-03-12" name="CVE-2013-0095" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/ncas/alerts/TA13-071A" source="CERT">TA13-071A</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-026" source="MS" adv="1">MS13-026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
        <vers num="2011" edition=""/>
        <vers num="2011" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0096" published="2013-05-14" name="CVE-2013-0096" modified="2013-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability."</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://technet.microsoft.com/en-us/security/bulletin/ms13-045

'There is no update available for Windows Essentials 2011. See update FAQ for details.'</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-045" source="MS" patch="1" adv="1">MS13-045</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_essentials">
        <vers num="2011"/>
        <vers num="2012"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0107" published="2013-01-26" name="CVE-2013-0107" modified="2013-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Foxit Advanced PDF Editor 3 before 3.04 might allow remote attackers to execute arbitrary code via a crafted document containing instructions that reconstruct a certain security cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/275219" source="CERT-VN">VU#275219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxitsoftware" name="foxit_advanced_pdf_editor">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0108" published="2013-02-24" name="CVE-2013-0108" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1, and R410.2; ComfortPoint Open Manager (aka CPO-M) Station R100; and HMIWeb Browser client packages allows remote attackers to execute arbitrary code via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://ics-cert.us-cert.gov/pdf/ICSA-13-053-02.pdf" source="MISC">http://ics-cert.us-cert.gov/pdf/ICSA-13-053-02.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="honeywell" name="comfortpoint_open_manager_station">
        <vers num="r100"/>
      </prod>
      <prod vendor="honeywell" name="enterprise_buildings_integrator">
        <vers num="r310"/>
        <vers num="r400.2"/>
        <vers num="r410.1"/>
        <vers num="r410.2"/>
      </prod>
      <prod vendor="honeywell" name="symmetre">
        <vers num="r310"/>
        <vers num="r400.2"/>
        <vers num="r410.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0109" published="2013-04-08" name="CVE-2013-0109" modified="2013-04-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not properly handle exceptions, which allows local users to gain privileges or cause a denial of service (memory overwrite) via a crafted application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/957036" source="CERT-VN">VU#957036</ref>
      <ref url="http://www.nvidia.com/object/product-security.html" source="CONFIRM" patch="1" adv="1">http://www.nvidia.com/object/product-security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nvidia" name="display_driver">
        <vers prev="1" num="307.00" edition="-"/>
        <vers prev="1" num="307.00" edition="-:~~~windows~~"/>
        <vers num="310.00" edition="-"/>
        <vers num="310.00" edition="-:~~~windows~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0110" published="2013-04-08" name="CVE-2013-0110" modified="2013-04-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">nvSCPAPISvr.exe in the NVIDIA Stereoscopic 3D Driver service, as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/957036" source="CERT-VN">VU#957036</ref>
      <ref url="http://www.nvidia.com/object/product-security.html" source="CONFIRM" adv="1">http://www.nvidia.com/object/product-security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nvidia" name="driver">
        <vers prev="1" num="307.00" edition="-"/>
        <vers prev="1" num="307.00" edition="-:~~~windows~~"/>
        <vers num="310.00" edition="-"/>
        <vers num="310.00" edition="-:~~~windows~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0111" published="2013-04-08" name="CVE-2013-0111" modified="2013-04-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">daemonu.exe (aka the NVIDIA Update Service Daemon), as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/957036" source="CERT-VN">VU#957036</ref>
      <ref url="http://www.nvidia.com/object/product-security.html" source="CONFIRM" adv="1">http://www.nvidia.com/object/product-security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nvidia" name="driver">
        <vers prev="1" num="307.00" edition="-"/>
        <vers prev="1" num="307.00" edition="-:~~~windows~~"/>
        <vers num="310.00" edition="-"/>
        <vers num="310.00" edition="-:~~~windows~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0113" published="2013-02-24" name="CVE-2013-0113" modified="2013-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Nuance PDF Reader 7.0 and PDF Viewer Plus 7.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/248449" source="CERT-VN">VU#248449</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nuance" name="pdf_reader">
        <vers num="7.0"/>
      </prod>
      <prod vendor="nuance" name="pdf_reader_plus">
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0118" published="2013-02-24" name="CVE-2013-0118" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CS-Cart before 3.0.6, when PayPal Standard Payments is configured, allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/583564" source="CERT-VN">VU#583564</ref>
      <ref url="http://www.kb.cert.org/vuls/id/BLUU-949PQL" source="CONFIRM">http://www.kb.cert.org/vuls/id/BLUU-949PQL</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cs-cart" name="cs-cart">
        <vers num="3.0"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers prev="1" num="3.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0120" published="2013-02-24" name="CVE-2013-0120" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The web interface on Dell PowerConnect 6248P switches allows remote attackers to cause a denial of service (device crash) via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/160460" source="CERT-VN">VU#160460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dell" name="powerconnect_6248p">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0122" published="2013-04-21" name="CVE-2013-0122" modified="2013-04-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The avast! Mobile Security application before 2.0.4400 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent to com.avast.android.mobilesecurity.app.scanner.DeleteFileActivity with zero arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/131263" source="CERT-VN">VU#131263</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avas!t" name="avast!_mobile_security">
        <vers prev="1" num="2.0.4304" edition="-"/>
        <vers prev="1" num="2.0.4304" edition="-:~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0123" published="2013-03-21" name="CVE-2013-0123" modified="2013-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the administration interface in ASKIA askiaweb allow remote attackers to execute arbitrary SQL commands via (1) the nHistoryId parameter to WebProd/pages/pgHistory.asp or (2) the OrderBy parameter to WebProd/pages/pgadmin.asp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/406596" source="CERT-VN">VU#406596</ref>
    </refs>
    <vuln_soft>
      <prod vendor="askia" name="askiaweb">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0124" published="2013-03-21" name="CVE-2013-0124" modified="2013-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in ASKIA askiaweb allow remote attackers to inject arbitrary web script or HTML via the (1) Number or (2) UpdatePage parameter to WebProd/cgi-bin/AskiaExt.dll.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/406596" source="CERT-VN">VU#406596</ref>
    </refs>
    <vuln_soft>
      <prod vendor="askia" name="askiaweb">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0125" published="2013-04-04" name="CVE-2013-0125" modified="2013-04-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in fileview.asp in C2 WebResource allows remote attackers to inject arbitrary web script or HTML via the File parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/418923" source="CERT-VN">VU#418923</ref>
    </refs>
    <vuln_soft>
      <prod vendor="c2enterprise" name="c2_webresource">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0126" published="2013-03-21" name="CVE-2013-0126" modified="2013-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via the username and user_level parameters or (2) enable remote administration via the is_telnet_primary and is_telnet_secondary parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/278204" source="CERT-VN">VU#278204</ref>
      <ref url="http://www.exploit-db.com/exploits/24860/" source="EXPLOIT-DB">24860</ref>
      <ref url="http://infosec42.blogspot.com/2013/03/verizon-fios-router-csrf-cve-2013-0126.html" source="MISC">http://infosec42.blogspot.com/2013/03/verizon-fios-router-csrf-cve-2013-0126.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verizon" name="fios_actiontec_mi424wr-gen31_router">
        <vers num="-"/>
      </prod>
      <prod vendor="verizon" name="fios_actiontec_mi424wr-gen31_router_firmware">
        <vers num="40.19.36"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0127" published="2013-05-01" name="CVE-2013-0127" modified="2013-05-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote attackers to bypass intended restrictions on Java code execution and X-Confirm-Reading-To functionality via a crafted message, aka SPRs JMOY95BLM6 and JMOY95BN49.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/912420" source="CERT-VN">VU#912420</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/83775" source="XF">ibm-notes-applet-tags(83775)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21633819" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21633819</ref>
      <ref url="http://seclists.org/fulldisclosure/2013/Apr/262" source="FULLDISC">20130501 n.runs-SA-2013.005 - IBM Lotus Notes - arbitrary code execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="8.0"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.0.2.0"/>
        <vers num="8.0.2.1"/>
        <vers num="8.0.2.2"/>
        <vers num="8.0.2.3"/>
        <vers num="8.0.2.4"/>
        <vers num="8.0.2.5"/>
        <vers num="8.0.2.6"/>
        <vers num="8.5"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.0"/>
        <vers num="8.5.1.1"/>
        <vers num="8.5.1.2"/>
        <vers num="8.5.1.3"/>
        <vers num="8.5.1.4"/>
        <vers num="8.5.1.5"/>
        <vers num="8.5.2.0"/>
        <vers num="8.5.2.1"/>
        <vers num="8.5.2.2"/>
        <vers num="8.5.2.3"/>
        <vers num="8.5.3"/>
        <vers num="8.5.3.1"/>
        <vers num="8.5.3.2"/>
        <vers num="8.5.3.3"/>
        <vers num="9.0.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0128" published="2013-04-04" name="CVE-2013-0128" modified="2013-04-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Contact Customer Support feature in the TigerText Free Private Texting app before 3.1.402 for iOS sends a log-file e-mail message with unencrypted credentials, which allows remote attackers to obtain sensitive information by sniffing the network or leveraging access to an e-mail endpoint.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/704916" source="CERT-VN">VU#704916</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tigertext" name="tigertext">
        <vers prev="1" num="3.1" edition="-"/>
        <vers prev="1" num="3.1" edition="-:~~~iphone_os~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0129" published="2013-04-19" name="CVE-2013-0129" modified="2013-04-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in pd-admin before 4.17 allow remote authenticated users to inject arbitrary web script or HTML via (1) the WebFTP Overview "Create new directory" field or (2) the body of an e-mail autoresponder message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/311644" source="CERT-VN">VU#311644</ref>
      <ref url="http://www.pdadmin-forum.de/thread.php?threadid=4051" source="CONFIRM">http://www.pdadmin-forum.de/thread.php?threadid=4051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pd-admin" name="pd-admin">
        <vers prev="1" num="4.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0130" published="2013-03-29" name="CVE-2013-0130" modified="2013-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple buffer overflows in Core FTP before 2.2 build 1769 allow remote FTP servers to execute arbitrary code or cause a denial of service (application crash) via a long directory name in a (1) DELE, (2) LIST, or (3) VIEW command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/370868" source="CERT-VN">VU#370868</ref>
      <ref url="http://www.coreftp.com/forums/viewtopic.php?t=222102" source="CONFIRM">http://www.coreftp.com/forums/viewtopic.php?t=222102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coreftp" name="coreftp">
        <vers prev="1" num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0131" published="2013-04-08" name="CVE-2013-0131" modified="2013-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and 313.x before 313.30 for the X Window System on UNIX, when NoScanout mode is enabled, allows remote authenticated users to execute arbitrary code via a large ARGB cursor.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/771620" source="CERT-VN">VU#771620</ref>
      <ref url="http://www.nvidia.com/object/product-security.html" source="CONFIRM" patch="1" adv="1">http://www.nvidia.com/object/product-security.html</ref>
      <ref url="http://nvidia.custhelp.com/app/answers/detail/a_id/3290" source="CONFIRM">http://nvidia.custhelp.com/app/answers/detail/a_id/3290</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nvidia" name="gpu_driver">
        <vers num="195.22" edition="-"/>
        <vers num="195.22" edition="-:~~linux_kernel~~~"/>
        <vers num="195.22" edition="-:~~sunos~~~"/>
        <vers num="195.22" edition="-:~~freebsd~~~"/>
        <vers num="195.22" edition="-:~~esx~~~"/>
        <vers prev="1" num="304.00" edition="-"/>
        <vers prev="1" num="304.00" edition="-:~~esx~~~"/>
        <vers prev="1" num="304.00" edition="-:~~freebsd~~~"/>
        <vers prev="1" num="304.00" edition="-:~~linux_kernel~~~"/>
        <vers prev="1" num="304.00" edition="-:~~sunos~~~"/>
        <vers num="310.00" edition="-"/>
        <vers num="310.00" edition="-:~~freebsd~~~"/>
        <vers num="310.00" edition="-:~~esx~~~"/>
        <vers num="310.00" edition="-:~~sunos~~~"/>
        <vers num="310.00" edition="-:~~linux_kernel~~~"/>
        <vers num="313.00" edition="-"/>
        <vers num="313.00" edition="-:~~freebsd~~~"/>
        <vers num="313.00" edition="-:~~esx~~~"/>
        <vers num="313.00" edition="-:~~sunos~~~"/>
        <vers num="313.00" edition="-:~~linux_kernel~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0132" published="2013-04-18" name="CVE-2013-0132" modified="2013-04-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to execute arbitrary PHP code via a request containing crafted environment variables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/310500" source="CERT-VN">VU#310500</ref>
    </refs>
    <vuln_soft>
      <prod vendor="parallels" name="parallels_plesk_panel">
        <vers num="11.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0133" published="2013-04-18" name="CVE-2013-0133" modified="2013-04-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in /usr/local/psa/admin/sbin/wrapper in Parallels Plesk Panel 11.0.9 allows local users to gain privileges via a crafted PATH environment variable.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/310500" source="CERT-VN">VU#310500</ref>
    </refs>
    <vuln_soft>
      <prod vendor="parallels" name="parallels_plesk_panel">
        <vers num="11.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0134" published="2013-04-08" name="CVE-2013-0134" modified="2013-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the web interface in AirDroid allows remote attackers to inject arbitrary web script or HTML via a crafted text message that is transmitted by a managed phone.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/557252" source="CERT-VN">VU#557252</ref>
    </refs>
    <vuln_soft>
      <prod vendor="airdroid" name="airdroid">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0135" published="2013-04-08" name="CVE-2013-0135" modified="2013-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) addressbook/register/edit_user_save.php; the email parameter to (4) addressbook/register/edit_user_save.php, (5) addressbook/register/reset_password.php, (6) addressbook/register/reset_password_save.php, or (7) addressbook/register/user_add_save.php; the username parameter to (8) addressbook/register/checklogin.php or (9) addressbook/register/reset_password_save.php; the (10) lastname, (11) firstname, (12) phone, (13) permissions, or (14) notes parameter to addressbook/register/edit_user_save.php; the (15) q parameter to addressbook/register/admin_index.php; the (16) site parameter to addressbook/register/linktick.php; the (17) password parameter to addressbook/register/reset_password.php; the (18) password_hint parameter to addressbook/register/reset_password_save.php; the (19) var parameter to addressbook/register/traffic.php; or a (20) BasicLogin cookie to addressbook/register/router.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/183692" source="CERT-VN">VU#183692</ref>
      <ref url="http://www.acadion.nl/labs/advisory/20130203-phpaddressbook.html" source="MISC">http://www.acadion.nl/labs/advisory/20130203-phpaddressbook.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chatelao" name="php_address_book">
        <vers num="8.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0136" published="2013-06-01" name="CVE-2013-0136" modified="2013-06-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/701572" source="CERT-VN">VU#701572</ref>
      <ref url="https://community.rapid7.com/community/metasploit/blog/2013/05/15/new-1day-exploits-mutiny-vulnerabilities" source="MISC">https://community.rapid7.com/community/metasploit/blog/2013/05/15/new-1day-exploits-mutiny-vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mutiny" name="mutiny">
        <vers num="5.0-1.00"/>
        <vers prev="1" num="5.0-1.10"/>
      </prod>
      <prod vendor="mutiny" name="mutiny_virtual_appliance">
        <vers num="-"/>
      </prod>
      <prod vendor="mutiny" name="mutiny_appliance">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0138" published="2013-04-21" name="CVE-2013-0138" modified="2013-04-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">BitZipper 2013 before Update 1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ZIP archive.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/BLUU-95GP23" source="CONFIRM">http://www.kb.cert.org/vuls/id/BLUU-95GP23</ref>
      <ref url="http://www.kb.cert.org/vuls/id/880916" source="CERT-VN">VU#880916</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitberry_software" name="bitzipper">
        <vers prev="1" num="2013"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0139" published="2013-04-18" name="CVE-2013-0139" modified="2013-04-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Arecont Vision AV1355DN MegaDome camera allows remote attackers to cause a denial of service (video-capture outage) via a packet to UDP port 69.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/375180" source="CERT-VN">VU#375180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arecont" name="vision_av1355dn_megadome_camera">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0140" published="2013-05-01" name="CVE-2013-0140" modified="2013-05-01" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="7.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="5.5" CVSS_base_score="7.9">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication channel.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/209131" source="CERT-VN">VU#209131</ref>
      <ref url="https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10042" source="CONFIRM" adv="1">https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10042</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="2.0"/>
        <vers num="2.5" edition="sp1"/>
        <vers num="2.5.1"/>
        <vers num="3.0" edition="sp2a"/>
        <vers num="3.5.0"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="4.0"/>
        <vers num="4.5.0"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers prev="1" num="4.5.6"/>
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0141" published="2013-05-01" name="CVE-2013-0141" modified="2013-05-01" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="5.5" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to upload arbitrary files via a crafted request over the Agent-Server communication channel, as demonstrated by writing to the Software/ directory.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/209131" source="CERT-VN">VU#209131</ref>
      <ref url="https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10042" source="CONFIRM" adv="1">https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10042</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="2.0"/>
        <vers num="2.5" edition="sp1"/>
        <vers num="2.5.1"/>
        <vers num="3.0" edition="sp2a"/>
        <vers num="3.5.0"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="4.0"/>
        <vers num="4.5.0"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers prev="1" num="4.5.6"/>
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0142" published="2013-06-07" name="CVE-2013-0142" modified="2013-06-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/927644" source="CERT-VN">VU#927644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnap" name="surveillance_station_pro">
        <vers num="-"/>
      </prod>
      <prod vendor="qnap" name="nas">
        <vers num="-"/>
      </prod>
      <prod vendor="qnap" name="viostor_network_video_recorder">
        <vers num="-"/>
      </prod>
      <prod vendor="qnap" name="viostor_network_video_recorder">
        <vers num="4.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0143" published="2013-06-07" name="CVE-2013-0143" modified="2013-06-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/927644" source="CERT-VN">VU#927644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnap" name="surveillance_station_pro">
        <vers num="-"/>
      </prod>
      <prod vendor="qnap" name="nas">
        <vers num="-"/>
      </prod>
      <prod vendor="qnap" name="viostor_network_video_recorder">
        <vers num="-"/>
      </prod>
      <prod vendor="qnap" name="viostor_network_video_recorder">
        <vers num="4.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0144" published="2013-06-07" name="CVE-2013-0144" modified="2013-06-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in cgi-bin/create_user.cgi on QNAP VioStor NVR devices with firmware 4.0.3 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts via a NEW USER action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/927644" source="CERT-VN">VU#927644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qnap" name="viostor_network_video_recorder">
        <vers num="-"/>
      </prod>
      <prod vendor="qnap" name="viostor_network_video_recorder">
        <vers num="4.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0145" published="2013-05-20" name="CVE-2013-0145" modified="2013-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in a read request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/127108" source="CERT-VN">VU#127108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vercot" name="serva32">
        <vers num="2.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0148" published="2013-06-16" name="CVE-2013-0148" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The Data Camouflage (aka Faircom Standard Encryption) algorithm in Faircom c-treeACE does not ensure that a decryption key is needed for accessing database contents, which allows context-dependent attackers to read cleartext database records by copying a database to another system that has a certain default configuration.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/900031" source="CERT-VN">VU#900031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="faircom" name="c-treeace">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0151" published="2013-03-07" name="CVE-2013-0151" modified="2013-03-07" CVSS_version="2.0" CVSS_vector="(AV:A/AC:H/Au:N/C:N/I:N/A:C)" CVSS_score="4.6" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.2" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The do_hvm_op function in xen/arch/x86/hvm/hvm.c in Xen 4.2.x on the x86_32 platform does not prevent HVM_PARAM_NESTEDHVM (aka nested virtualization) operations, which allows guest OS users to cause a denial of service (long-duration page mappings and host OS crash) by leveraging administrative access to an HVM guest in a domain with a large number of VCPUs.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=d60d7082289a74e44b3dc8f67df46c3404ca08bf" source="CONFIRM">http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=d60d7082289a74e44b3dc8f67df46c3404ca08bf</ref>
      <ref url="http://openwall.com/lists/oss-security/2013/01/22/10" source="MLIST">[oss-security] 20130122 Xen Security Advisory 34 (CVE-2013-0151) - nested virtualization on 32-bit exposes host crash</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xen" name="xen">
        <vers num="4.2.0" edition="-"/>
        <vers num="4.2.0" edition="-:~~~~x86~"/>
        <vers num="4.2.1" edition="-"/>
        <vers num="4.2.1" edition="-:~~~~x86~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0152" published="2013-02-12" name="CVE-2013-0152" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">Memory leak in Xen 4.2 and unstable allows local HVM guests to cause a denial of service (host memory consumption) by performing nested virtualization in a way that triggers errors that are not properly handled.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id/1028032" source="SECTRACK">1028032</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/23/8" source="MLIST">[oss-security] 20130123 Xen Security Advisory 35 (CVE-2013-0152) - Nested HVM exposes host to being driven out of memory by guest</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xen" name="xen">
        <vers num="4.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0153" published="2013-02-14" name="CVE-2013-0153" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The AMD IOMMU support in Xen 4.2.x, 4.1.x, 3.3, and other versions, when using AMD-Vi for PCI passthrough, uses the same interrupt remapping table for the host and all guests, which allows guests to cause a denial of service by injecting an interrupt into other guests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81831" source="XF">xen-amdiommu-dos(81831)</ref>
      <ref url="http://www.securityfocus.com/bid/57745" source="BID">57745</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/05/7" source="MLIST">[oss-security] 20130205 Xen Security Advisory 36 (CVE-2013-0153) - interrupt remap entries shared and old ones not cleared on AMD IOMMUs</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2636" source="DEBIAN">DSA-2636</ref>
      <ref url="http://secunia.com/advisories/51881" source="SECUNIA" adv="1">51881</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0847.html" source="REDHAT">RHSA-2013:0847</ref>
      <ref url="http://osvdb.org/89867" source="OSVDB">89867</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-04/msg00052.html" source="SUSE">openSUSE-SU-2013:0637</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-04/msg00051.html" source="SUSE">openSUSE-SU-2013:0636</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xen" name="xen">
        <vers num="3.3.0"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0154" published="2013-01-11" name="CVE-2013-0154" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The get_page_type function in xen/arch/x86/mm.c in Xen 4.2, when debugging is enabled, allows local PV or HVM guest administrators to cause a denial of service (assertion failure and hypervisor crash) via unspecified vectors related to a hypercall.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/80977" source="XF">xen-hypercall-dos(80977)</ref>
      <ref url="http://www.securitytracker.com/id?1027937" source="SECTRACK">1027937</ref>
      <ref url="http://www.securityfocus.com/bid/57159" source="BID">57159</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/04/2" source="MLIST">[oss-security] 20130104 Xen Security Advisory 37 (CVE-2013-0154) - Hypervisor crash due to incorrect ASSERT (debug build only)</ref>
      <ref url="http://seclists.org/oss-sec/2013/q1/att-17/xsa37-4_2.patch" source="CONFIRM">http://seclists.org/oss-sec/2013/q1/att-17/xsa37-4_2.patch</ref>
      <ref url="http://osvdb.org/88913" source="OSVDB">88913</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-04/msg00052.html" source="SUSE">openSUSE-SU-2013:0637</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-04/msg00051.html" source="SUSE">openSUSE-SU-2013:0636</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xen" name="xen">
        <vers num="4.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0155" published="2013-01-13" name="CVE-2013-0155" modified="2013-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660 and CVE-2012-2694.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://groups.google.com/group/rubyonrails-security/msg/bc6f13dafe130ee9?dmode=source&amp;output=gplain" source="MLIST">[rubyonrails-security] 20130108 Unsafe Query Generation Risk in Ruby on Rails (CVE-2013-0155)</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2609" source="DEBIAN">DSA-2609</ref>
      <ref url="http://support.apple.com/kb/HT5784" source="CONFIRM">http://support.apple.com/kb/HT5784</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0155.html" source="REDHAT">RHSA-2013:0155</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0154.html" source="REDHAT">RHSA-2013:0154</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html" source="APPLE">APPLE-SA-2013-06-04-1</ref>
      <ref url="http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A" source="MISC">http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rubyonrails" name="ruby_on_rails">
        <vers num="3.0.0" edition="beta"/>
        <vers num="3.0.0" edition="beta2"/>
        <vers num="3.0.0" edition="beta3"/>
        <vers num="3.0.0" edition="beta4"/>
        <vers num="3.0.0" edition="rc"/>
        <vers num="3.0.0" edition="rc2"/>
        <vers num="3.0.1" edition="pre"/>
        <vers num="3.0.10" edition="rc1"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12" edition="rc1"/>
        <vers num="3.0.13" edition="rc1"/>
        <vers num="3.0.14"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers prev="1" num="3.0.18"/>
        <vers num="3.0.2" edition="pre"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4" edition="rc"/>
        <vers num="3.0.4" edition="rc1"/>
        <vers num="3.0.5" edition="rc1"/>
        <vers num="3.0.6" edition="rc1"/>
        <vers num="3.0.6" edition="rc2"/>
        <vers num="3.0.7" edition="rc1"/>
        <vers num="3.0.7" edition="rc2"/>
        <vers num="3.0.8" edition="rc1"/>
        <vers num="3.0.8" edition="rc2"/>
        <vers num="3.0.8" edition="rc3"/>
        <vers num="3.0.8" edition="rc4"/>
        <vers num="3.0.9" edition="rc1"/>
        <vers num="3.0.9" edition="rc2"/>
        <vers num="3.0.9" edition="rc3"/>
        <vers num="3.0.9" edition="rc4"/>
        <vers num="3.0.9" edition="rc5"/>
        <vers num="3.1.0" edition="beta1"/>
        <vers num="3.1.0" edition="rc1"/>
        <vers num="3.1.0" edition="rc2"/>
        <vers num="3.1.0" edition="rc3"/>
        <vers num="3.1.0" edition="rc4"/>
        <vers num="3.1.0" edition="rc5"/>
        <vers num="3.1.0" edition="rc6"/>
        <vers num="3.1.0" edition="rc7"/>
        <vers num="3.1.0" edition="rc8"/>
        <vers num="3.1.1" edition="rc1"/>
        <vers num="3.1.1" edition="rc2"/>
        <vers num="3.1.1" edition="rc3"/>
        <vers num="3.1.2" edition="rc1"/>
        <vers num="3.1.2" edition="rc2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4" edition="rc1"/>
        <vers num="3.1.5" edition="rc1"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers prev="1" num="3.1.9"/>
        <vers num="3.2.0" edition="rc1"/>
        <vers num="3.2.0" edition="rc2"/>
        <vers num="3.2.1"/>
        <vers prev="1" num="3.2.10"/>
        <vers num="3.2.2" edition="rc1"/>
        <vers num="3.2.3" edition="rc1"/>
        <vers num="3.2.3" edition="rc2"/>
        <vers num="3.2.4" edition="rc1"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0156" published="2013-01-13" name="CVE-2013-0156" modified="2013-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/628463" source="CERT-VN">VU#628463</ref>
      <ref url="http://www.kb.cert.org/vuls/id/380039" source="CERT-VN">VU#380039</ref>
      <ref url="https://groups.google.com/group/rubyonrails-security/msg/c1432d0f8c70e89d?dmode=source&amp;output=gplain" source="MLIST" adv="1">[rubyonrails-security] 20130108 Multiple vulnerabilities in parameter parsing in Action Pack (CVE-2013-0156)</ref>
      <ref url="https://community.rapid7.com/community/metasploit/blog/2013/01/09/serialization-mischief-in-ruby-land-cve-2013-0156" source="MISC">https://community.rapid7.com/community/metasploit/blog/2013/01/09/serialization-mischief-in-ruby-land-cve-2013-0156</ref>
      <ref url="http://www.insinuator.net/2013/01/rails-yaml/" source="MISC">http://www.insinuator.net/2013/01/rails-yaml/</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2604" source="DEBIAN">DSA-2604</ref>
      <ref url="http://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/" source="CONFIRM">http://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0155.html" source="REDHAT">RHSA-2013:0155</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0154.html" source="REDHAT">RHSA-2013:0154</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0153.html" source="REDHAT">RHSA-2013:0153</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html" source="APPLE">APPLE-SA-2013-03-14-1</ref>
      <ref url="http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A" source="MISC">http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rubyonrails" name="rails">
        <vers num="1.2.4"/>
      </prod>
      <prod vendor="rubyonrails" name="ruby_on_rails">
        <vers num="0.10.0"/>
        <vers num="0.10.1"/>
        <vers num="0.11.0"/>
        <vers num="0.11.1"/>
        <vers num="0.12.0"/>
        <vers num="0.12.1"/>
        <vers num="0.13.0"/>
        <vers num="0.13.1"/>
        <vers num="0.14.1"/>
        <vers num="0.14.2"/>
        <vers num="0.14.3"/>
        <vers num="0.14.4"/>
        <vers num="0.5.0"/>
        <vers num="0.5.5"/>
        <vers num="0.5.6"/>
        <vers num="0.5.7"/>
        <vers num="0.6.0"/>
        <vers num="0.6.5"/>
        <vers num="0.7.0"/>
        <vers num="0.8.0"/>
        <vers num="0.8.5"/>
        <vers num="0.9.0"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.4.1"/>
        <vers num="1.0.0"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.9.5"/>
        <vers num="2.0.0" edition="rc1"/>
        <vers num="2.0.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.4"/>
        <vers num="2.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers prev="1" num="2.3.14"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.9"/>
        <vers num="3.0.0" edition="beta"/>
        <vers num="3.0.0" edition="beta2"/>
        <vers num="3.0.0" edition="beta3"/>
        <vers num="3.0.0" edition="beta4"/>
        <vers num="3.0.0" edition="rc"/>
        <vers num="3.0.0" edition="rc2"/>
        <vers num="3.0.1" edition="pre"/>
        <vers num="3.0.10" edition="rc1"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12" edition="rc1"/>
        <vers num="3.0.13" edition="rc1"/>
        <vers num="3.0.14"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers prev="1" num="3.0.18"/>
        <vers num="3.0.2" edition="pre"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4" edition="rc"/>
        <vers num="3.0.4" edition="rc1"/>
        <vers num="3.0.5" edition="rc1"/>
        <vers num="3.0.6" edition="rc1"/>
        <vers num="3.0.6" edition="rc2"/>
        <vers num="3.0.7" edition="rc1"/>
        <vers num="3.0.7" edition="rc2"/>
        <vers num="3.0.8" edition="rc1"/>
        <vers num="3.0.8" edition="rc2"/>
        <vers num="3.0.8" edition="rc3"/>
        <vers num="3.0.8" edition="rc4"/>
        <vers num="3.0.9" edition="rc1"/>
        <vers num="3.0.9" edition="rc2"/>
        <vers num="3.0.9" edition="rc3"/>
        <vers num="3.0.9" edition="rc4"/>
        <vers num="3.0.9" edition="rc5"/>
        <vers num="3.1.0" edition="beta1"/>
        <vers num="3.1.0" edition="rc1"/>
        <vers num="3.1.0" edition="rc2"/>
        <vers num="3.1.0" edition="rc3"/>
        <vers num="3.1.0" edition="rc4"/>
        <vers num="3.1.0" edition="rc5"/>
        <vers num="3.1.0" edition="rc6"/>
        <vers num="3.1.0" edition="rc7"/>
        <vers num="3.1.0" edition="rc8"/>
        <vers num="3.1.1" edition="rc1"/>
        <vers num="3.1.1" edition="rc2"/>
        <vers num="3.1.1" edition="rc3"/>
        <vers num="3.1.2" edition="rc1"/>
        <vers num="3.1.2" edition="rc2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4" edition="rc1"/>
        <vers num="3.1.5" edition="rc1"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers prev="1" num="3.1.9"/>
        <vers num="3.2.0" edition="rc1"/>
        <vers num="3.2.0" edition="rc2"/>
        <vers num="3.2.1"/>
        <vers prev="1" num="3.2.10"/>
        <vers num="3.2.2" edition="rc1"/>
        <vers num="3.2.3" edition="rc1"/>
        <vers num="3.2.3" edition="rc2"/>
        <vers num="3.2.4" edition="rc1"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0158" published="2013-02-24" name="CVE-2013-0158" modified="2013-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in CloudBees Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-01-04" source="CONFIRM" adv="1">https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-01-04</ref>
      <ref url="https://github.com/jenkinsci/jenkins/commit/c3d8e05a1b3d58b6c4dcff97394cb3a79608b4b2" source="CONFIRM">https://github.com/jenkinsci/jenkins/commit/c3d8e05a1b3d58b6c4dcff97394cb3a79608b4b2</ref>
      <ref url="https://github.com/jenkinsci/jenkins/commit/a9aff088f327278a8873aef47fa8f80d3c5932fd" source="CONFIRM">https://github.com/jenkinsci/jenkins/commit/a9aff088f327278a8873aef47fa8f80d3c5932fd</ref>
      <ref url="https://github.com/jenkinsci/jenkins/commit/94a8789b699132dd706021a6be1b78bc47f19602" source="CONFIRM">https://github.com/jenkinsci/jenkins/commit/94a8789b699132dd706021a6be1b78bc47f19602</ref>
      <ref url="https://github.com/jenkinsci/jenkins/commit/4895eaafca468b7f0f1a3166b2fca7414f0d5da5" source="CONFIRM">https://github.com/jenkinsci/jenkins/commit/4895eaafca468b7f0f1a3166b2fca7414f0d5da5</ref>
      <ref url="https://github.com/jenkinsci/jenkins/commit/3dc13b957b14cec649036e8dd517f0f9cb21fb04" source="CONFIRM">https://github.com/jenkinsci/jenkins/commit/3dc13b957b14cec649036e8dd517f0f9cb21fb04</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=892795" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=892795</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/07/4" source="MLIST">[oss-security] 20130107 Re: CVE Request: Jenkins possible remote code execution</ref>
      <ref url="http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-01-04.cb" source="CONFIRM" adv="1">http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-01-04.cb</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0220.html" source="REDHAT">RHSA-2013:0220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cloudbees" name="jenkins">
        <vers num="1.400" edition="-"/>
        <vers num="1.400" edition="-:lts"/>
        <vers num="1.401"/>
        <vers num="1.402"/>
        <vers num="1.403"/>
        <vers num="1.404"/>
        <vers num="1.405"/>
        <vers num="1.406"/>
        <vers num="1.407"/>
        <vers num="1.408"/>
        <vers num="1.409"/>
        <vers num="1.409.1" edition=""/>
        <vers num="1.409.1" edition=":lts"/>
        <vers num="1.409.1" edition="-"/>
        <vers num="1.409.1" edition="-:lts"/>
        <vers num="1.409.2" edition=""/>
        <vers num="1.409.2" edition=":lts"/>
        <vers num="1.409.2" edition="-"/>
        <vers num="1.409.2" edition="-:lts"/>
        <vers num="1.409.3" edition="-"/>
        <vers num="1.409.3" edition="-:lts"/>
        <vers num="1.410"/>
        <vers num="1.411"/>
        <vers num="1.412"/>
        <vers num="1.413"/>
        <vers num="1.414"/>
        <vers num="1.415"/>
        <vers num="1.416"/>
        <vers num="1.417"/>
        <vers num="1.418"/>
        <vers num="1.419"/>
        <vers num="1.420"/>
        <vers num="1.421"/>
        <vers num="1.422"/>
        <vers num="1.423"/>
        <vers num="1.424" edition="-"/>
        <vers num="1.424" edition="-:lts"/>
        <vers num="1.424.1" edition="-"/>
        <vers num="1.424.1" edition="-:lts"/>
        <vers num="1.424.2" edition="-"/>
        <vers num="1.424.2" edition="-:lts"/>
        <vers num="1.424.3" edition="-"/>
        <vers num="1.424.3" edition="-:lts"/>
        <vers num="1.424.4" edition="-"/>
        <vers num="1.424.4" edition="-:lts"/>
        <vers num="1.424.5" edition="-"/>
        <vers num="1.424.5" edition="-:lts"/>
        <vers num="1.424.6" edition="-"/>
        <vers num="1.424.6" edition="-:lts"/>
        <vers num="1.425"/>
        <vers num="1.426"/>
        <vers num="1.427"/>
        <vers num="1.428"/>
        <vers num="1.429"/>
        <vers num="1.430"/>
        <vers num="1.431"/>
        <vers num="1.432"/>
        <vers num="1.433"/>
        <vers num="1.434"/>
        <vers num="1.435"/>
        <vers num="1.436"/>
        <vers num="1.437"/>
        <vers num="1.447" edition="-"/>
        <vers num="1.447" edition="-:lts"/>
        <vers num="1.447.1" edition="-"/>
        <vers num="1.447.1" edition="-:lts"/>
        <vers num="1.447.1.1" edition="-"/>
        <vers num="1.447.1.1" edition="-:enterprise"/>
        <vers num="1.447.2" edition="-"/>
        <vers num="1.447.2" edition="-:lts"/>
        <vers num="1.447.2.2" edition="-"/>
        <vers num="1.447.2.2" edition="-:enterprise"/>
        <vers num="1.447.3.1" edition="-"/>
        <vers num="1.447.3.1" edition="-:enterprise"/>
        <vers num="1.466.1" edition="-"/>
        <vers num="1.466.1" edition="-:lts"/>
        <vers num="1.466.1.2" edition="-"/>
        <vers num="1.466.1.2" edition="-:enterprise"/>
        <vers prev="1" num="1.466.2" edition="-"/>
        <vers prev="1" num="1.466.2" edition="-:lts"/>
        <vers num="1.466.2.1" edition="-"/>
        <vers num="1.466.2.1" edition="-:enterprise"/>
        <vers prev="1" num="1.480.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0160" published="2013-02-17" name="CVE-2013-0160" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=892983" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=892983</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/08/3" source="MLIST">[oss-security] 20130107 Re: /dev/ptmx timing</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.html" source="SUSE">SUSE-SU-2013:0674</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.html" source="SUSE">openSUSE-SU-2013:0395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers num="3.7.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0162" published="2013-03-01" name="CVE-2013-0162" modified="2013-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=892806" source="MISC" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=892806</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0548.html" source="REDHAT">RHSA-2013:0548</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0544.html" source="REDHAT">RHSA-2013:0544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ryan_davis" name="ruby_parser">
        <vers num="1.0.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.1.0"/>
        <vers num="2.2.0"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0.a1"/>
        <vers num="3.0.0.a10"/>
        <vers num="3.0.0.a2"/>
        <vers num="3.0.0.a3"/>
        <vers num="3.0.0.a4"/>
        <vers num="3.0.0.a5"/>
        <vers num="3.0.0.a6"/>
        <vers num="3.0.0.a7"/>
        <vers num="3.0.0.a8"/>
        <vers num="3.0.0.a9"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.1.0"/>
        <vers prev="1" num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0164" published="2013-02-24" name="CVE-2013-0164" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/openshift/origin-server/pull/1136" source="CONFIRM">https://github.com/openshift/origin-server/pull/1136</ref>
      <ref url="https://github.com/openshift/origin-server/commit/524465f70a32d0eb6bf047e6a05c76c22d52bfa2" source="CONFIRM">https://github.com/openshift/origin-server/commit/524465f70a32d0eb6bf047e6a05c76c22d52bfa2</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=893307" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=893307</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0220.html" source="REDHAT">RHSA-2013:0220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="openshift">
        <vers prev="1" num="1.0" edition="-"/>
        <vers prev="1" num="1.0" edition="-:enterprise"/>
      </prod>
      <prod vendor="redhat" name="openshift_origin">
        <vers num="1.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0166" published="2013-02-08" name="CVE-2013-0166" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=908052" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=908052</ref>
      <ref url="http://www.openssl.org/news/secadv_20130204.txt" source="CONFIRM" adv="1">http://www.openssl.org/news/secadv_20130204.txt</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2621" source="DEBIAN">DSA-2621</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0783.html" source="REDHAT">RHSA-2013:0783</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0782.html" source="REDHAT">RHSA-2013:0782</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0587.html" source="REDHAT">RHSA-2013:0587</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136396549913849&amp;w=2" source="HP">HPSBUX02856</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136396549913849&amp;w=2" source="HP">SSRT101104</ref>
      <ref url="http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=ebc71865f0506a293242bd4aec97cdc7a8ef24b0" source="CONFIRM">http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=ebc71865f0506a293242bd4aec97cdc7a8ef24b0</ref>
      <ref url="http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=66e8211c0b1347970096e04b18aa52567c325200" source="CONFIRM">http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=66e8211c0b1347970096e04b18aa52567c325200</ref>
      <ref url="http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=62e4506a7d4cec1c8e1ff687f6b220f6a62a57c7" source="CONFIRM">http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=62e4506a7d4cec1c8e1ff687f6b220f6a62a57c7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.1c"/>
        <vers num="0.9.2b"/>
        <vers num="0.9.3"/>
        <vers num="0.9.3a"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5" edition="beta1"/>
        <vers num="0.9.5" edition="beta2"/>
        <vers num="0.9.5a" edition="beta1"/>
        <vers num="0.9.5a" edition="beta2"/>
        <vers num="0.9.6" edition="beta1"/>
        <vers num="0.9.6" edition="beta2"/>
        <vers num="0.9.6" edition="beta3"/>
        <vers num="0.9.6a" edition="beta1"/>
        <vers num="0.9.6a" edition="beta2"/>
        <vers num="0.9.6a" edition="beta3"/>
        <vers num="0.9.6b"/>
        <vers num="0.9.6c"/>
        <vers num="0.9.6d"/>
        <vers num="0.9.6e"/>
        <vers num="0.9.6f"/>
        <vers num="0.9.6g"/>
        <vers num="0.9.6h"/>
        <vers num="0.9.6i"/>
        <vers num="0.9.6j"/>
        <vers num="0.9.6k"/>
        <vers num="0.9.6l"/>
        <vers num="0.9.6m"/>
        <vers num="0.9.7" edition="beta1"/>
        <vers num="0.9.7" edition="beta2"/>
        <vers num="0.9.7" edition="beta3"/>
        <vers num="0.9.7" edition="beta4"/>
        <vers num="0.9.7" edition="beta5"/>
        <vers num="0.9.7" edition="beta6"/>
        <vers num="0.9.7a"/>
        <vers num="0.9.7b"/>
        <vers num="0.9.7c"/>
        <vers num="0.9.7d"/>
        <vers num="0.9.7e"/>
        <vers num="0.9.7f"/>
        <vers num="0.9.7g"/>
        <vers num="0.9.7h"/>
        <vers num="0.9.7i"/>
        <vers num="0.9.7j"/>
        <vers num="0.9.7k"/>
        <vers num="0.9.7l"/>
        <vers num="0.9.7m"/>
        <vers num="0.9.8"/>
        <vers num="0.9.8a"/>
        <vers num="0.9.8b"/>
        <vers num="0.9.8c"/>
        <vers num="0.9.8d"/>
        <vers num="0.9.8e"/>
        <vers num="0.9.8f"/>
        <vers num="0.9.8g"/>
        <vers num="0.9.8h"/>
        <vers num="0.9.8i"/>
        <vers num="0.9.8j"/>
        <vers num="0.9.8k"/>
        <vers num="0.9.8l"/>
        <vers num="0.9.8m" edition="beta1"/>
        <vers num="0.9.8n"/>
        <vers num="0.9.8o"/>
        <vers num="0.9.8p"/>
        <vers num="0.9.8q"/>
        <vers num="0.9.8r"/>
        <vers num="0.9.8s"/>
        <vers num="0.9.8t"/>
        <vers num="0.9.8u"/>
        <vers num="0.9.8v"/>
        <vers num="0.9.8w"/>
        <vers num="0.9.8x"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0a"/>
        <vers num="1.0.0b"/>
        <vers num="1.0.0c"/>
        <vers num="1.0.0d"/>
        <vers num="1.0.0e"/>
        <vers num="1.0.0f"/>
        <vers num="1.0.0g"/>
        <vers num="1.0.0h"/>
        <vers num="1.0.0i"/>
        <vers num="1.0.0j"/>
        <vers num="1.0.1"/>
        <vers num="1.0.1a"/>
        <vers num="1.0.1b"/>
        <vers num="1.0.1c"/>
      </prod>
      <prod vendor="redhat" name="openssl">
        <vers num="0.9.6-15"/>
        <vers num="0.9.6b-3"/>
        <vers num="0.9.7a-2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0168" published="2013-03-12" name="CVE-2013-0168" modified="2013-03-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticated storage admins to cause a denial of service (free space consumption of other storage domains) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=893355" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=893355</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/81834" source="XF">entreprise-movedisk-dos(81834)</ref>
      <ref url="http://www.securitytracker.com/id/1028076" source="SECTRACK">1028076</ref>
      <ref url="http://www.securityfocus.com/bid/57750" source="BID">57750</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0211.html" source="REDHAT" adv="1">RHSA-2013:0211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_virtualization_manager">
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.3"/>
        <vers num="3.0"/>
        <vers prev="1" num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0169" published="2013-02-08" name="CVE-2013-0169" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.</descript>
      <descript source="nvd">Per http://www.openssl.org/news/vulnerabilities.html:
Fixed in OpenSSL 1.0.1d (Affected 1.0.1c, 1.0.1b, 1.0.1a, 1.0.1) 
Fixed in OpenSSL 1.0.0k (Affected 1.0.0j, 1.0.0i, 1.0.0g, 1.0.0f, 1.0.0e, 1.0.0d, 1.0.0c, 1.0.0b, 1.0.0a, 1.0.0) 
Fixed in OpenSSL 0.9.8y (Affected 0.9.8x, 0.9.8w, 0.9.8v, 0.9.8u, 0.9.8t, 0.9.8s, 0.9.8r, 0.9.8q, 0.9.8p, 0.9.8o, 0.9.8n, 0.9.8m, 0.9.8l, 0.9.8k, 0.9.8j, 0.9.8i, 0.9.8h, 0.9.8g, 0.9.8f, 0.9.8d, 0.9.8c, 0.9.8b, 0.9.8a, 0.9.8) </descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-051A.html" source="CERT">TA13-051A</ref>
      <ref url="https://polarssl.org/tech-updates/releases/polarssl-1.2.5-released" source="CONFIRM" adv="1">https://polarssl.org/tech-updates/releases/polarssl-1.2.5-released</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1735-1" source="UBUNTU">USN-1735-1</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html</ref>
      <ref url="http://www.openssl.org/news/secadv_20130204.txt" source="CONFIRM" adv="1">http://www.openssl.org/news/secadv_20130204.txt</ref>
      <ref url="http://www.matrixssl.org/news.html" source="CONFIRM">http://www.matrixssl.org/news.html</ref>
      <ref url="http://www.isg.rhul.ac.uk/tls/TLStiming.pdf" source="MISC">http://www.isg.rhul.ac.uk/tls/TLStiming.pdf</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2622" source="DEBIAN">DSA-2622</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2621" source="DEBIAN">DSA-2621</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0783.html" source="REDHAT">RHSA-2013:0783</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0782.html" source="REDHAT">RHSA-2013:0782</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0587.html" source="REDHAT">RHSA-2013:0587</ref>
      <ref url="http://openwall.com/lists/oss-security/2013/02/05/24" source="MLIST">[oss-security] 20130205 Re: CVE request: TLS CBC padding timing flaw in various SSL / TLS implementations</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136396549913849&amp;w=2" source="HP">HPSBUX02856</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136396549913849&amp;w=2" source="HP">SSRT101104</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00002.html" source="SUSE">openSUSE-SU-2013:0378</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00000.html" source="SUSE">openSUSE-SU-2013:0375</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00020.html" source="SUSE">SUSE-SU-2013:0328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.8"/>
        <vers num="0.9.8a"/>
        <vers num="0.9.8b"/>
        <vers num="0.9.8c"/>
        <vers num="0.9.8d"/>
        <vers num="0.9.8f"/>
        <vers num="0.9.8g"/>
        <vers num="0.9.8h"/>
        <vers num="0.9.8i"/>
        <vers num="0.9.8j"/>
        <vers num="0.9.8k"/>
        <vers num="0.9.8l"/>
        <vers num="0.9.8m"/>
        <vers num="0.9.8n"/>
        <vers num="0.9.8o"/>
        <vers num="0.9.8p"/>
        <vers num="0.9.8q"/>
        <vers num="0.9.8r"/>
        <vers num="0.9.8s"/>
        <vers num="0.9.8t"/>
        <vers num="0.9.8u"/>
        <vers num="0.9.8v"/>
        <vers num="0.9.8w"/>
        <vers num="0.9.8x"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0a"/>
        <vers num="1.0.0b"/>
        <vers num="1.0.0c"/>
        <vers num="1.0.0d"/>
        <vers num="1.0.0e"/>
        <vers num="1.0.0f"/>
        <vers num="1.0.0g"/>
        <vers num="1.0.0i"/>
        <vers num="1.0.0j"/>
        <vers num="1.0.1"/>
        <vers num="1.0.1a"/>
        <vers num="1.0.1b"/>
        <vers num="1.0.1c"/>
      </prod>
      <prod vendor="oracle" name="openjdk">
        <vers num="-"/>
        <vers num="1.6.0"/>
        <vers num="1.7.0"/>
        <vers num="1.8.0"/>
      </prod>
      <prod vendor="polarssl" name="polarssl">
        <vers num="0.10.0"/>
        <vers num="0.10.1"/>
        <vers num="0.11.0"/>
        <vers num="0.11.1"/>
        <vers num="0.12.0"/>
        <vers num="0.12.1"/>
        <vers num="0.13.1"/>
        <vers num="0.14.0"/>
        <vers num="0.14.2"/>
        <vers num="0.14.3"/>
        <vers num="0.99" edition="pre1"/>
        <vers num="0.99" edition="pre3"/>
        <vers num="0.99" edition="pre4"/>
        <vers num="0.99" edition="pre5"/>
        <vers num="1.0.0"/>
        <vers num="1.1.0" edition="rc0"/>
        <vers num="1.1.0" edition="rc1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0170" published="2013-02-08" name="CVE-2013-0170" modified="2013-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=893450" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=893450</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/81552" source="XF">libvirt-virnetmessagefree-code-exec(81552)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1708-1" source="UBUNTU">USN-1708-1</ref>
      <ref url="http://www.securitytracker.com/id/1028047" source="SECTRACK">1028047</ref>
      <ref url="http://www.securityfocus.com/bid/57578" source="BID">57578</ref>
      <ref url="http://wiki.libvirt.org/page/Maintenance_Releases" source="CONFIRM">http://wiki.libvirt.org/page/Maintenance_Releases</ref>
      <ref url="http://secunia.com/advisories/52003" source="SECUNIA" adv="1">52003</ref>
      <ref url="http://secunia.com/advisories/52001" source="SECUNIA" adv="1">52001</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0199.html" source="REDHAT">RHSA-2013:0199</ref>
      <ref url="http://osvdb.org/89644" source="OSVDB">89644</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00016.html" source="SUSE">SUSE-SU-2013:0320</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00002.html" source="SUSE">openSUSE-SU-2013:0275</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00001.html" source="SUSE">openSUSE-SU-2013:0274</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098398.html" source="FEDORA">FEDORA-2013-1626</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098370.html" source="FEDORA">FEDORA-2013-1642</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098326.html" source="FEDORA">FEDORA-2013-1644</ref>
      <ref url="http://libvirt.org/news.html" source="CONFIRM">http://libvirt.org/news.html</ref>
      <ref url="http://libvirt.org/git/?p=libvirt.git;a=commit;h=46532e3e8ed5f5a736a02f67d6c805492f9ca720" source="CONFIRM">http://libvirt.org/git/?p=libvirt.git;a=commit;h=46532e3e8ed5f5a736a02f67d6c805492f9ca720</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="libvirt">
        <vers num="" edition="0.9.11"/>
        <vers num="" edition="0.9.11.1"/>
        <vers num="" edition="0.9.11.2"/>
        <vers num="" edition="0.9.11.3"/>
        <vers num="" edition="0.9.11.4"/>
        <vers num="" edition="0.9.11.5"/>
        <vers num="" edition="0.9.11.6"/>
        <vers num="" edition="0.9.11.7"/>
        <vers num="" edition="0.9.11.8"/>
        <vers num="0.10.2"/>
        <vers num="0.10.2.1"/>
        <vers num="0.10.2.2"/>
        <vers num="0.9.6"/>
        <vers num="0.9.6.1"/>
        <vers num="0.9.6.2"/>
        <vers num="0.9.6.3"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0172" published="2013-01-17" name="CVE-2013-0172" modified="2013-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifying LDAP directory objects by leveraging (1) objectClass access by a user, (2) objectClass access by a group, or (3) write access to an attribute.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.samba.org/samba/security/CVE-2013-0172" source="CONFIRM" adv="1">http://www.samba.org/samba/security/CVE-2013-0172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="4.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0175" published="2013-04-25" name="CVE-2013-0175" modified="2013-04-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://news.ycombinator.com/item?id=5040457" source="MISC">https://news.ycombinator.com/item?id=5040457</ref>
      <ref url="https://groups.google.com/forum/?fromgroups=#%21topic/ruby-grape/fthDkMgIOa0" source="CONFIRM">https://groups.google.com/forum/?fromgroups=#!topic/ruby-grape/fthDkMgIOa0</ref>
      <ref url="https://github.com/sferik/multi_xml/pull/34" source="CONFIRM">https://github.com/sferik/multi_xml/pull/34</ref>
      <ref url="https://gist.github.com/nate/d7f6d9f4925f413621aa" source="CONFIRM">https://gist.github.com/nate/d7f6d9f4925f413621aa</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/11/9" source="MLIST">[oss-security] 20130111 Re: CVE request for multi_xml ruby gem (has same problem as CVE-2013-0156)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="erik_michaels-ober" name="multi_xml">
        <vers num="0.5.2"/>
      </prod>
      <prod vendor="grape_project" name="grape">
        <vers num="0.1.0"/>
        <vers num="0.1.1"/>
        <vers num="0.1.2"/>
        <vers num="0.1.3"/>
        <vers num="0.1.4"/>
        <vers num="0.1.5"/>
        <vers num="0.2.0"/>
        <vers num="0.2.1"/>
        <vers num="0.2.2"/>
        <vers num="0.2.3"/>
        <vers num="0.2.4"/>
        <vers num="0.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0176" published="2013-02-05" name="CVE-2013-0176" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.libssh.org/2013/01/22/libssh-0-5-4-security-release/" source="CONFIRM" patch="1" adv="1">http://www.libssh.org/2013/01/22/libssh-0-5-4-security-release/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/81595" source="XF">libssh-publickeyfromprivatekey-dos(81595)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1707-1" source="UBUNTU">USN-1707-1</ref>
      <ref url="http://secunia.com/advisories/51982" source="SECUNIA" adv="1">51982</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098094.html" source="FEDORA">FEDORA-2013-1407</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098065.html" source="FEDORA">FEDORA-2013-1422</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libssh" name="libssh">
        <vers num="0.4.7"/>
        <vers num="0.4.8"/>
        <vers num="0.5.0" edition="rc1"/>
        <vers num="0.5.1"/>
        <vers num="0.5.2"/>
        <vers prev="1" num="0.5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0181" published="2013-03-27" name="CVE-2013-0181" modified="2013-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Views in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using certain backends and facets, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://drupal.org/node/1884332" source="MISC" patch="1" adv="1">https://drupal.org/node/1884332</ref>
      <ref url="https://drupal.org/node/1884076" source="CONFIRM" patch="1">https://drupal.org/node/1884076</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/15/3" source="MLIST">[oss-security] 20130114 Re: CVE request for Drupal contributed modules</ref>
      <ref url="http://drupalcode.org/project/search_api.git/commitdiff/35b5728" source="CONFIRM">http://drupalcode.org/project/search_api.git/commitdiff/35b5728</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomas_seidl" name="search_api">
        <vers num="7.x-1.0" edition="beta1"/>
        <vers num="7.x-1.0" edition="beta10"/>
        <vers num="7.x-1.0" edition="beta2"/>
        <vers num="7.x-1.0" edition="beta3"/>
        <vers num="7.x-1.0" edition="beta4"/>
        <vers num="7.x-1.0" edition="beta5"/>
        <vers num="7.x-1.0" edition="beta6"/>
        <vers num="7.x-1.0" edition="beta7"/>
        <vers num="7.x-1.0" edition="beta8"/>
        <vers num="7.x-1.0" edition="beta9"/>
        <vers num="7.x-1.0" edition="rc1"/>
        <vers num="7.x-1.1"/>
        <vers num="7.x-1.2"/>
        <vers num="7.x-1.3"/>
        <vers num="7.x-1.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0182" published="2013-03-27" name="CVE-2013-0182" modified="2013-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Payment module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to payments, which allows remote attackers to read arbitrary payments.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://drupal.org/node/1884360" source="MISC" patch="1" adv="1">https://drupal.org/node/1884360</ref>
      <ref url="http://drupal.org/node/1883830" source="CONFIRM" patch="1">http://drupal.org/node/1883830</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/15/3" source="MLIST">[oss-security] 20130114 Re: CVE request for Drupal contributed modules</ref>
      <ref url="http://drupalcode.org/project/payment.git/commitdiff/62c9186" source="CONFIRM">http://drupalcode.org/project/payment.git/commitdiff/62c9186</ref>
      <ref url="http://drupal.org/node/1871508" source="MISC">http://drupal.org/node/1871508</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bart_feenstra" name="payment">
        <vers num="" edition="7.x-1.0"/>
        <vers num="" edition="7.x-1.0:alpha2"/>
        <vers num="" edition="7.x-1.0:alpha4"/>
        <vers num="" edition="7.x-1.0:beta2"/>
        <vers num="" edition="7.x-1.0:alpha1"/>
        <vers num="" edition="7.x-1.0:alpha3"/>
        <vers num="" edition="7.x-1.0:alpha6"/>
        <vers num="" edition="7.x-1.0:beta1"/>
        <vers num="" edition="7.x-1.0:alpha5"/>
        <vers num="" edition="7.x-1.0:beta3"/>
        <vers num="" edition="7.x-1.1"/>
        <vers num="" edition="7.x-1.2"/>
        <vers num="" edition="7.x-1.x"/>
        <vers num="" edition="7.x-1.x:dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0183" published="2013-03-01" name="CVE-2013-0183" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">multipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a long string in a Multipart HTTP packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://groups.google.com/forum/#%21topic/rack-devel/7ZKPNAjgRSs" source="CONFIRM">https://groups.google.com/forum/#!topic/rack-devel/7ZKPNAjgRSs</ref>
      <ref url="https://groups.google.com/forum/#%21topic/rack-devel/-MWPHDeGWtI" source="CONFIRM">https://groups.google.com/forum/#!topic/rack-devel/-MWPHDeGWtI</ref>
      <ref url="https://github.com/rack/rack/commit/f95113402b7239f225282806673e1b6424522b18" source="CONFIRM">https://github.com/rack/rack/commit/f95113402b7239f225282806673e1b6424522b18</ref>
      <ref url="https://github.com/rack/rack/commit/548b9af2dc0059f4c0c19728624448d84de450ff" source="CONFIRM">https://github.com/rack/rack/commit/548b9af2dc0059f4c0c19728624448d84de450ff</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=895282" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=895282</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0548.html" source="REDHAT">RHSA-2013:0548</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0544.html" source="REDHAT">RHSA-2013:0544</ref>
      <ref url="http://rack.github.com/" source="CONFIRM">http://rack.github.com/</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html" source="SUSE">openSUSE-SU-2013:0462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rack_project" name="rack">
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0184" published="2013-03-01" name="CVE-2013-0184" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Rack::Auth::AbstractRequest in Rack 1.1.x before 1.1.5, 1.2.x before 1.2.7, 1.3.x before 1.3.9, and 1.4.x before 1.4.4 allows remote attackers to cause a denial of service via unknown vectors related to "symbolized arbitrary strings."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=895384" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=895384</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0548.html" source="REDHAT">RHSA-2013:0548</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0544.html" source="REDHAT">RHSA-2013:0544</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html" source="SUSE">openSUSE-SU-2013:0462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rack_project" name="rack">
        <vers num="1.1.0"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.6"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0189" published="2013-02-08" name="CVE-2013-0189" modified="2013-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a denial of service (resource consumption) via a crafted request.  NOTE: this issue is due to an incorrect fix for CVE-2012-5643, possibly involving an incorrect order of arguments or incorrect comparison.</descript>
      <descript source="nvd">Per http://www.ubuntu.com/usn/USN-1713-1/
A security issue affects these releases of Ubuntu and its derivatives:
Ubuntu 12.10
Ubuntu 12.04 LTS
Ubuntu 11.10
Ubuntu 10.04 LTS
</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.squid-cache.org/Versions/v3/3.2/changesets/SQUID-2012_1.patch" source="MISC" patch="1">http://www.squid-cache.org/Versions/v3/3.2/changesets/SQUID-2012_1.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v3/3.1/changesets/SQUID-2012_1.patch" source="MISC" patch="1">http://www.squid-cache.org/Versions/v3/3.1/changesets/SQUID-2012_1.patch</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/scm-commits/2013-January/934637.html" source="MLIST" patch="1">[scm-commits] 20130125 [squid/f17] CVE-2013-0189: Incomplete fix for the CVE-2012-5643</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=895972" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=895972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=887962#c9" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=887962#c9</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1713-1" source="UBUNTU">USN-1713-1</ref>
      <ref url="http://www.securityfocus.com/bid/57646" source="BID">57646</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2631" source="DEBIAN">DSA-2631</ref>
      <ref url="http://secunia.com/advisories/52024" source="SECUNIA" adv="1">52024</ref>
      <ref url="http://bazaar.launchpad.net/~squid/squid/3.2/revision/11744" source="CONFIRM">http://bazaar.launchpad.net/~squid/squid/3.2/revision/11744</ref>
      <ref url="http://bazaar.launchpad.net/~squid/squid/3.2/revision/11743" source="CONFIRM">http://bazaar.launchpad.net/~squid/squid/3.2/revision/11743</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid-cache" name="squid">
        <vers num="3.1"/>
        <vers num="3.1.0.1"/>
        <vers num="3.1.0.10"/>
        <vers num="3.1.0.11"/>
        <vers num="3.1.0.12"/>
        <vers num="3.1.0.13"/>
        <vers num="3.1.0.14"/>
        <vers num="3.1.0.15"/>
        <vers num="3.1.0.16"/>
        <vers num="3.1.0.17"/>
        <vers num="3.1.0.18"/>
        <vers num="3.1.0.2"/>
        <vers num="3.1.0.3"/>
        <vers num="3.1.0.4"/>
        <vers num="3.1.0.5"/>
        <vers num="3.1.0.6"/>
        <vers num="3.1.0.7"/>
        <vers num="3.1.0.8"/>
        <vers num="3.1.0.9"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.11"/>
        <vers num="3.1.12"/>
        <vers num="3.1.13"/>
        <vers num="3.1.14"/>
        <vers num="3.1.15"/>
        <vers num="3.1.2"/>
        <vers num="3.1.22"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.5.1"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2.0.1"/>
        <vers num="3.2.0.10"/>
        <vers num="3.2.0.11"/>
        <vers num="3.2.0.12"/>
        <vers num="3.2.0.13"/>
        <vers num="3.2.0.14"/>
        <vers num="3.2.0.15"/>
        <vers num="3.2.0.16"/>
        <vers num="3.2.0.17"/>
        <vers num="3.2.0.18"/>
        <vers num="3.2.0.19"/>
        <vers num="3.2.0.2"/>
        <vers num="3.2.0.3"/>
        <vers num="3.2.0.4"/>
        <vers num="3.2.0.5"/>
        <vers num="3.2.0.6"/>
        <vers num="3.2.0.7"/>
        <vers num="3.2.0.8"/>
        <vers num="3.2.0.9"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
      </prod>
      <prod vendor="canonical" name="ubuntu_linux">
        <vers num="10.04" edition="-"/>
        <vers num="10.04" edition="-:lts"/>
        <vers num="11.10"/>
        <vers num="12.04" edition="-"/>
        <vers num="12.04" edition="-:lts"/>
        <vers num="12.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0190" published="2013-02-12" name="CVE-2013-0190" modified="2013-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a denial of service (guest crash) by triggering an iret fault, leading to use of an incorrect stack pointer and stack corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=896038" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=896038</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1728-1" source="UBUNTU">USN-1728-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1725-1" source="UBUNTU">USN-1725-1</ref>
      <ref url="http://www.securityfocus.com/bid/57433" source="BID">57433</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/16/8" source="MLIST">[oss-security] 20130116 Xen Security Advisory 40 (CVE-2013-0190) - Linux stack corruption in xen_failsafe_callback for 32bit PVOPS guests.</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/16/6" source="MLIST">[oss-security] 20130116 [PATCH] xen: Fix stack corruption in xen_failsafe_callback for 32bit PVOPS guests.</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0496.html" source="REDHAT">RHSA-2013:0496</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0198" published="2013-03-05" name="CVE-2013-0198" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=22ce550e5346947a12a781ed0959a7b1165d0dc6" source="CONFIRM" patch="1">http://www.thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commitdiff;h=22ce550e5346947a12a781ed0959a7b1165d0dc6</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=894486" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=894486</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/18/7" source="MLIST">[oss-security] 20130118 Re: CVE Request -- dnsmasq: Incomplete fix for the CVE-2012-3411 issue</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/18/2" source="MLIST">[oss-security] 20130118 CVE Request -- dnsmasq: Incomplete fix for the CVE-2012-3411 issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thekelleys" name="dnsmasq">
        <vers num="-"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.95"/>
        <vers num="0.96"/>
        <vers num="0.98"/>
        <vers num="0.992"/>
        <vers num="0.996"/>
        <vers num="1.0"/>
        <vers num="1.10"/>
        <vers num="1.11"/>
        <vers num="1.12"/>
        <vers num="1.13"/>
        <vers num="1.14"/>
        <vers num="1.15"/>
        <vers num="1.16"/>
        <vers num="1.17"/>
        <vers num="1.18"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.9"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.10"/>
        <vers num="2.11"/>
        <vers num="2.12"/>
        <vers num="2.13"/>
        <vers num="2.14"/>
        <vers num="2.15"/>
        <vers num="2.16"/>
        <vers num="2.17"/>
        <vers num="2.18"/>
        <vers num="2.19"/>
        <vers num="2.2"/>
        <vers num="2.20"/>
        <vers num="2.21"/>
        <vers num="2.22"/>
        <vers num="2.23"/>
        <vers num="2.24"/>
        <vers num="2.25"/>
        <vers num="2.26"/>
        <vers num="2.27"/>
        <vers num="2.28"/>
        <vers num="2.29"/>
        <vers num="2.3"/>
        <vers num="2.30"/>
        <vers num="2.31"/>
        <vers num="2.33"/>
        <vers num="2.34"/>
        <vers num="2.35"/>
        <vers num="2.36"/>
        <vers num="2.37"/>
        <vers num="2.38"/>
        <vers num="2.39"/>
        <vers num="2.4"/>
        <vers num="2.40"/>
        <vers num="2.41"/>
        <vers num="2.42"/>
        <vers num="2.43"/>
        <vers num="2.44"/>
        <vers num="2.45"/>
        <vers num="2.46"/>
        <vers num="2.47"/>
        <vers num="2.48"/>
        <vers num="2.49"/>
        <vers num="2.5"/>
        <vers num="2.50"/>
        <vers num="2.51"/>
        <vers num="2.52"/>
        <vers num="2.53"/>
        <vers num="2.54"/>
        <vers num="2.55"/>
        <vers num="2.56"/>
        <vers num="2.57"/>
        <vers num="2.58"/>
        <vers num="2.59"/>
        <vers num="2.6"/>
        <vers num="2.60"/>
        <vers num="2.61"/>
        <vers num="2.62"/>
        <vers num="2.63"/>
        <vers num="2.64"/>
        <vers prev="1" num="2.65"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0200" published="2013-03-06" name="CVE-2013-0200" modified="2013-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per https://access.redhat.com/security/cve/CVE-2013-0200
"This issue has been addressed in Red Hat Enterprise Linux 6 via RHSA-2013:0500."</impact>
    </impacts>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="ftp://ftp.scientificlinux.org/linux/scientific/6x/SRPMS/vendor/hplip-3.12.4-4.el6.src.rpm" source="CONFIRM" patch="1">ftp://ftp.scientificlinux.org/linux/scientific/6x/SRPMS/vendor/hplip-3.12.4-4.el6.src.rpm</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=902163" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=902163</ref>
      <ref url="http://hplipopensource.com/hplip-web/release_notes.html" source="MISC">http://hplipopensource.com/hplip-web/release_notes.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="linux_imaging_and_printing_project">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="2.7.10"/>
        <vers num="3.10.2"/>
        <vers num="3.10.5"/>
        <vers num="3.10.6"/>
        <vers num="3.10.9"/>
        <vers num="3.11.1"/>
        <vers num="3.11.10"/>
        <vers num="3.11.3"/>
        <vers num="3.11.3a"/>
        <vers num="3.11.5"/>
        <vers num="3.11.7"/>
        <vers prev="1" num="3.12.4"/>
        <vers num="3.9.10"/>
        <vers num="3.9.12"/>
        <vers num="3.9.2"/>
        <vers num="3.9.4"/>
        <vers num="3.9.4b"/>
        <vers num="3.9.6"/>
        <vers num="3.9.8"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0205" published="2013-03-19" name="CVE-2013-0205" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://drupal.org/node/1890216" source="CONFIRM" patch="1">https://drupal.org/node/1890216</ref>
      <ref url="https://drupal.org/node/1890212" source="CONFIRM" patch="1">https://drupal.org/node/1890212</ref>
      <ref url="https://drupal.org/node/1890222" source="MISC" adv="1">https://drupal.org/node/1890222</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/21/5" source="MLIST">[oss-security] 20130121 Re: CVE request for Drupal contributed modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="restful_web_services_project" name="restws">
        <vers num="7.x-1.0" edition="beta1"/>
        <vers num="7.x-1.0" edition="beta2"/>
        <vers num="7.x-1.x" edition="dev"/>
        <vers num="7.x-2.0" edition="alpha1"/>
        <vers num="7.x-2.0" edition="alpha2"/>
        <vers num="7.x-2.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0206" published="2013-03-19" name="CVE-2013-0206" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "administer CSS" permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.</descript>
      <descript source="nvd">CWE-434: Unrestricted Upload of File with Dangerous Type</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://drupal.org/node/1890318" source="MISC" patch="1" adv="1">https://drupal.org/node/1890318</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/21/5" source="MLIST">[oss-security] 20130121 Re: CVE request for Drupal contributed modules</ref>
      <ref url="http://drupalcode.org/project/live_css.git/commitdiff/ef323c8" source="CONFIRM">http://drupalcode.org/project/live_css.git/commitdiff/ef323c8</ref>
      <ref url="http://drupalcode.org/project/live_css.git/commitdiff/cb7005f" source="CONFIRM">http://drupalcode.org/project/live_css.git/commitdiff/cb7005f</ref>
      <ref url="http://drupal.org/node/1883978" source="CONFIRM">http://drupal.org/node/1883978</ref>
      <ref url="http://drupal.org/node/1883976" source="CONFIRM">http://drupal.org/node/1883976</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guy_bedford" name="live_css">
        <vers num="6.x-2.0"/>
        <vers num="7.x-2.0"/>
        <vers num="7.x-2.0-beta1"/>
        <vers num="7.x-2.1"/>
        <vers num="7.x-2.2"/>
        <vers num="7.x-2.3"/>
        <vers num="7.x-2.4"/>
        <vers num="7.x-2.5"/>
        <vers num="7.x-2.6"/>
        <vers num="7.x-2.x-dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0207" published="2013-03-19" name="CVE-2013-0207" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the Mark Complete module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://drupal.org/node/1890566" source="CONFIRM">https://drupal.org/node/1890566</ref>
      <ref url="https://drupal.org/node/1890538" source="MISC" adv="1">https://drupal.org/node/1890538</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/21/5" source="MLIST">[oss-security] 20130121 Re: CVE request for Drupal contributed modules</ref>
      <ref url="http://drupalcode.org/project/mark_complete.git/commitdiff/a18c7b2" source="CONFIRM">http://drupalcode.org/project/mark_complete.git/commitdiff/a18c7b2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="leighton_whiting" name="mark_complete">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0208" published="2013-02-13" name="CVE-2013-0208" modified="2013-02-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the block_device_mapping parameter.</descript>
      <descript source="nvd">Per http://www.ubuntu.com/usn/USN-1709-1/
A security issue affects these releases of Ubuntu and its derivatives:
Ubuntu 12.10
Ubuntu 12.04 LTS
Ubuntu 11.10
</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://github.com/openstack/nova/commit/317cc0af385536dee43ef2addad50a91357fc1ad" source="CONFIRM">https://github.com/openstack/nova/commit/317cc0af385536dee43ef2addad50a91357fc1ad</ref>
      <ref url="https://github.com/openstack/nova/commit/243d516cea9d3caa5a8267b12d2f577dcb24193b" source="CONFIRM">https://github.com/openstack/nova/commit/243d516cea9d3caa5a8267b12d2f577dcb24193b</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=902629" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=902629</ref>
      <ref url="https://bugs.launchpad.net/nova/+bug/1069904" source="CONFIRM">https://bugs.launchpad.net/nova/+bug/1069904</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/81697" source="XF">nova-volume-security-bypass(81697)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1709-1" source="UBUNTU">USN-1709-1</ref>
      <ref url="http://www.securityfocus.com/bid/57613" source="BID">57613</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/29/9" source="MLIST">[oss-security] 20130129 [OSSA 2013-001] Boot from volume allows access to random volumes (CVE-2013-0208)</ref>
      <ref url="http://secunia.com/advisories/51992" source="SECUNIA" adv="1">51992</ref>
      <ref url="http://secunia.com/advisories/51963" source="SECUNIA" adv="1">51963</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0208.html" source="REDHAT">RHSA-2013:0208</ref>
      <ref url="http://osvdb.org/89661" source="OSVDB">89661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openstack" name="essex">
        <vers num="-"/>
      </prod>
      <prod vendor="openstack" name="folsom">
        <vers num="-"/>
      </prod>
      <prod vendor="canonical" name="ubuntu_linux">
        <vers num="11.10"/>
        <vers num="12.04" edition="-"/>
        <vers num="12.04" edition="-:lts"/>
        <vers num="12.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0209" published="2013-01-22" name="CVE-2013-0209" modified="2013-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.movabletype.org/2013/01/movable_type_438_patch.html" source="CONFIRM" patch="1" adv="1">http://www.movabletype.org/2013/01/movable_type_438_patch.html</ref>
      <ref url="http://www.sec-1.com/blog/wp-content/uploads/2013/01/movabletype_upgrade_exec.rb_.txt" source="MISC">http://www.sec-1.com/blog/wp-content/uploads/2013/01/movabletype_upgrade_exec.rb_.txt</ref>
      <ref url="http://www.sec-1.com/blog/?p=402" source="MISC">http://www.sec-1.com/blog/?p=402</ref>
      <ref url="http://openwall.com/lists/oss-security/2013/01/22/3" source="MLIST">[oss-security] 20130121 Re: CVE request for Movable Type</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sixapart" name="movable_type">
        <vers num="4.21"/>
        <vers num="4.22"/>
        <vers num="4.23"/>
        <vers num="4.24"/>
        <vers num="4.25"/>
        <vers num="4.26"/>
        <vers num="4.261"/>
        <vers num="4.27"/>
        <vers num="4.28" edition=""/>
        <vers num="4.28" edition=":open_source"/>
        <vers num="4.28" edition=":enterprise"/>
        <vers num="4.29" edition=""/>
        <vers num="4.29" edition=":open_source"/>
        <vers num="4.29" edition=":enterprise"/>
        <vers num="4.291" edition=""/>
        <vers num="4.291" edition=":open_source"/>
        <vers num="4.291" edition=":enterprise"/>
        <vers num="4.292" edition=""/>
        <vers num="4.292" edition=":enterprise"/>
        <vers num="4.292" edition=":open_source"/>
        <vers num="4.31"/>
        <vers num="4.32"/>
        <vers num="4.33"/>
        <vers num="4.34"/>
        <vers num="4.35"/>
        <vers num="4.36" edition=""/>
        <vers num="4.36" edition=":open_source"/>
        <vers num="4.361" edition=""/>
        <vers num="4.361" edition=":open_source"/>
        <vers num="4.37" edition=""/>
        <vers num="4.37" edition=":open_source"/>
        <vers num="4.38" edition=""/>
        <vers num="4.38" edition=":open_source"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0212" published="2013-02-24" name="CVE-2013-0212" modified="2013-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.</descript>
      <descript source="nvd">Per http://www.ubuntu.com/usn/usn-1710-1/
A security issue affects these releases of Ubuntu and its derivatives:
Ubuntu 12.10, Ubuntu 12.04 LTS, Ubuntu 11.10
</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=902964" source="MISC" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=902964</ref>
      <ref url="http://ubuntu.com/usn/usn-1710-1" source="UBUNTU" patch="1">USN-1710-1</ref>
      <ref url="https://lists.launchpad.net/openstack/msg20517.html" source="MLIST">[openstack] 20130129 [OSSA 2013-002] Backend password leak in Glance error message (CVE-2013-0212)</ref>
      <ref url="https://launchpad.net/glance/+milestone/2012.2.3" source="CONFIRM">https://launchpad.net/glance/+milestone/2012.2.3</ref>
      <ref url="https://github.com/openstack/glance/commit/e96273112b5b5da58d970796b7cfce04c5030a89" source="CONFIRM">https://github.com/openstack/glance/commit/e96273112b5b5da58d970796b7cfce04c5030a89</ref>
      <ref url="https://github.com/openstack/glance/commit/96a470be64adcef97f235ca96ed3c59ed954a4c1" source="CONFIRM">https://github.com/openstack/glance/commit/96a470be64adcef97f235ca96ed3c59ed954a4c1</ref>
      <ref url="https://github.com/openstack/glance/commit/37d4d96bf88c2bf3e7e9511b5e321cf4bed364b7" source="CONFIRM">https://github.com/openstack/glance/commit/37d4d96bf88c2bf3e7e9511b5e321cf4bed364b7</ref>
      <ref url="https://bugs.launchpad.net/glance/+bug/1098962" source="CONFIRM">https://bugs.launchpad.net/glance/+bug/1098962</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/29/10" source="MLIST">[oss-security] 20130129 [OSSA 2013-002] Backend password leak in Glance error message (CVE-2013-0212)</ref>
      <ref url="http://secunia.com/advisories/51990" source="SECUNIA" adv="1">51990</ref>
      <ref url="http://secunia.com/advisories/51957" source="SECUNIA" adv="1">51957</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0209.html" source="REDHAT" adv="1">RHSA-2013:0209</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openstack" name="essex">
        <vers num="2012.1"/>
      </prod>
      <prod vendor="openstack" name="folsom">
        <vers num="2012.2"/>
      </prod>
      <prod vendor="openstack" name="glance">
        <vers num="grizzly"/>
      </prod>
      <prod vendor="canonical" name="ubuntu_linux">
        <vers num="11.10"/>
        <vers num="12.04" edition="-"/>
        <vers num="12.04" edition="-:lts"/>
        <vers num="12.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0213" published="2013-02-02" name="CVE-2013-0213" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://capec.mitre.org/data/definitions/103.html

"CAPEC-103: Clickjacking"</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.samba.org/samba/security/CVE-2013-0213" source="CONFIRM" adv="1">http://www.samba.org/samba/security/CVE-2013-0213</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2617" source="DEBIAN">DSA-2617</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00033.html" source="SUSE">openSUSE-SU-2013:0281</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00029.html" source="SUSE">openSUSE-SU-2013:0277</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00042.html" source="SUSE">SUSE-SU-2013:0519</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00019.html" source="SUSE">SUSE-SU-2013:0326</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14" edition="a"/>
        <vers num="3.0.14a"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2" edition="a"/>
        <vers num="3.0.20" edition="a"/>
        <vers num="3.0.20" edition="b"/>
        <vers num="3.0.20a"/>
        <vers num="3.0.20b"/>
        <vers num="3.0.21" edition="a"/>
        <vers num="3.0.21" edition="b"/>
        <vers num="3.0.21" edition="c"/>
        <vers num="3.0.21a"/>
        <vers num="3.0.21b"/>
        <vers num="3.0.21c"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23" edition="a"/>
        <vers num="3.0.23" edition="b"/>
        <vers num="3.0.23" edition="c"/>
        <vers num="3.0.23" edition="d"/>
        <vers num="3.0.23a"/>
        <vers num="3.0.23b"/>
        <vers num="3.0.23c"/>
        <vers num="3.0.23d"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25" edition="a"/>
        <vers num="3.0.25" edition="b"/>
        <vers num="3.0.25" edition="c"/>
        <vers num="3.0.25" edition="pre1"/>
        <vers num="3.0.25" edition="pre2"/>
        <vers num="3.0.25" edition="rc1"/>
        <vers num="3.0.25" edition="rc2"/>
        <vers num="3.0.25" edition="rc3"/>
        <vers num="3.0.25a"/>
        <vers num="3.0.25b"/>
        <vers num="3.0.25c"/>
        <vers num="3.0.26" edition="a"/>
        <vers num="3.0.26a"/>
        <vers num="3.0.27" edition="a"/>
        <vers num="3.0.28" edition="a"/>
        <vers num="3.0.29"/>
        <vers num="3.0.2a"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.4" edition="rc1"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.10"/>
        <vers num="3.3.11"/>
        <vers num="3.3.12"/>
        <vers num="3.3.13"/>
        <vers num="3.3.14"/>
        <vers num="3.3.15"/>
        <vers num="3.3.16"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.3.9"/>
        <vers num="3.4.0"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.0"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.19"/>
        <vers num="3.5.2"/>
        <vers num="3.5.20"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0214" published="2013-02-02" name="CVE-2013-0214" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.samba.org/samba/security/CVE-2013-0214" source="CONFIRM" adv="1">http://www.samba.org/samba/security/CVE-2013-0214</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2617" source="DEBIAN">DSA-2617</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00033.html" source="SUSE">openSUSE-SU-2013:0281</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00029.html" source="SUSE">openSUSE-SU-2013:0277</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00042.html" source="SUSE">SUSE-SU-2013:0519</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00019.html" source="SUSE">SUSE-SU-2013:0326</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14" edition="a"/>
        <vers num="3.0.14a"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2" edition="a"/>
        <vers num="3.0.20" edition="a"/>
        <vers num="3.0.20" edition="b"/>
        <vers num="3.0.20a"/>
        <vers num="3.0.20b"/>
        <vers num="3.0.21" edition="a"/>
        <vers num="3.0.21" edition="b"/>
        <vers num="3.0.21" edition="c"/>
        <vers num="3.0.21a"/>
        <vers num="3.0.21b"/>
        <vers num="3.0.21c"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23" edition="a"/>
        <vers num="3.0.23" edition="b"/>
        <vers num="3.0.23" edition="c"/>
        <vers num="3.0.23" edition="d"/>
        <vers num="3.0.23a"/>
        <vers num="3.0.23b"/>
        <vers num="3.0.23c"/>
        <vers num="3.0.23d"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25" edition="a"/>
        <vers num="3.0.25" edition="b"/>
        <vers num="3.0.25" edition="c"/>
        <vers num="3.0.25" edition="pre1"/>
        <vers num="3.0.25" edition="pre2"/>
        <vers num="3.0.25" edition="rc1"/>
        <vers num="3.0.25" edition="rc2"/>
        <vers num="3.0.25" edition="rc3"/>
        <vers num="3.0.25a"/>
        <vers num="3.0.25b"/>
        <vers num="3.0.25c"/>
        <vers num="3.0.26" edition="a"/>
        <vers num="3.0.26a"/>
        <vers num="3.0.27" edition="a"/>
        <vers num="3.0.28" edition="a"/>
        <vers num="3.0.29"/>
        <vers num="3.0.2a"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.4" edition="rc1"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.10"/>
        <vers num="3.3.11"/>
        <vers num="3.3.12"/>
        <vers num="3.3.13"/>
        <vers num="3.3.14"/>
        <vers num="3.3.15"/>
        <vers num="3.3.16"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.3.9"/>
        <vers num="3.4.0"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.0"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.19"/>
        <vers num="3.5.2"/>
        <vers num="3.5.20"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0215" published="2013-03-07" name="CVE-2013-0215" modified="2013-03-07" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="5.5" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">oxenstored in Xen 4.1.x, Xen 4.2.x, and xen-unstable does not properly consider the state of the Xenstore ring during read operations, which allows guest OS users to cause a denial of service (daemon crash and host-control outage, or memory consumption) or obtain sensitive control-plane data by leveraging guest administrative access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=61401264eb00fae4ee4efc8e9a5067449283207b" source="CONFIRM">http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=61401264eb00fae4ee4efc8e9a5067449283207b</ref>
      <ref url="http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=40f9c5e0a6d15b4ca1f6d4ed3a46f0871520eab5" source="CONFIRM">http://xenbits.xen.org/gitweb/?p=xen.git;a=commit;h=40f9c5e0a6d15b4ca1f6d4ed3a46f0871520eab5</ref>
      <ref url="http://openwall.com/lists/oss-security/2013/02/05/10" source="MLIST">[oss-security] 20130205 Xen Security Advisory 38 (CVE-2013-0215) - oxenstored incorrect handling of certain Xenbus ring states</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xen" name="xen">
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0216" published="2013-02-17" name="CVE-2013-0216" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:S/C:N/I:N/A:C)" CVSS_score="5.2" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.4" CVSS_base_score="5.2">
    <desc>
      <descript source="cve">The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/48856286b64e4b66ec62b94e504d0b29c1ade664" source="CONFIRM" patch="1">https://github.com/torvalds/linux/commit/48856286b64e4b66ec62b94e504d0b29c1ade664</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=48856286b64e4b66ec62b94e504d0b29c1ade664" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=48856286b64e4b66ec62b94e504d0b29c1ade664</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=910883" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=910883</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/05/12" source="MLIST">[oss-security] 20130205 Xen Security Advisory 39 (CVE-2013-0216,CVE-2013-0217) - Linux netback DoS via malicious guest ring.</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.8" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.8</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.html" source="SUSE">SUSE-SU-2013:0674</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.html" source="SUSE">openSUSE-SU-2013:0395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers prev="1" num="3.7.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0217" published="2013-02-17" name="CVE-2013-0217" modified="2013-02-18" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:S/C:N/I:N/A:C)" CVSS_score="5.2" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.4" CVSS_base_score="5.2">
    <desc>
      <descript source="cve">Memory leak in drivers/net/xen-netback/netback.c in the Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (memory consumption) by triggering certain error conditions.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/7d5145d8eb2b9791533ffe4dc003b129b9696c48" source="CONFIRM" patch="1">https://github.com/torvalds/linux/commit/7d5145d8eb2b9791533ffe4dc003b129b9696c48</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=7d5145d8eb2b9791533ffe4dc003b129b9696c48" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=7d5145d8eb2b9791533ffe4dc003b129b9696c48</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=910883" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=910883</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/05/12" source="MLIST">[oss-security] 20130205 Xen Security Advisory 39 (CVE-2013-0216,CVE-2013-0217) - Linux netback DoS via malicious guest ring.</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.8" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers prev="1" num="3.7.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0218" published="2013-02-05" name="CVE-2013-0218" modified="2013-02-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.</descript>
      <descript source="nvd">Per http://rhn.redhat.com/errata/RHSA-2013-0206.html 
"An update for JBoss Enterprise Application Platform 5.2.0 which fixes one
security issue is now available from the Red Hat Customer Portal."

Per http://rhn.redhat.com/errata/RHSA-2013-0207.html
"An update for JBoss Enterprise Web Platform 5.2.0 which fixes one security
issue is now available from the Red Hat Customer Portal."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=903073" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=903073</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/81725" source="XF">jboss-eap-info-disc(81725)</ref>
      <ref url="http://www.securityfocus.com/bid/57652" source="BID">57652</ref>
      <ref url="http://www.osvdb.org/89698" source="OSVDB">89698</ref>
      <ref url="http://secunia.com/advisories/52041" source="SECUNIA" adv="1">52041</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0207.html" source="REDHAT" adv="1">RHSA-2013:0207</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0206.html" source="REDHAT" adv="1">RHSA-2013:0206</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="jboss_enterprise_application_platform">
        <vers num="5.1.2"/>
        <vers num="5.2.0"/>
      </prod>
      <prod vendor="redhat" name="jboss_enterprise_web_platform">
        <vers num="5.1.2"/>
        <vers num="5.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0219" published="2013-02-24" name="CVE-2013-0219" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.</descript>
      <descript source="nvd">Per https://access.redhat.com/security/cve/CVE-2013-0219

This issue affects the version of sssd shipped with Red Hat Enterprise Linux 5 and 6.
</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4" source="CONFIRM">https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4</ref>
      <ref url="https://fedorahosted.org/sssd/ticket/1782" source="CONFIRM">https://fedorahosted.org/sssd/ticket/1782</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=884254" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=884254</ref>
      <ref url="http://www.securityfocus.com/bid/57539" source="BID">57539</ref>
      <ref url="http://secunia.com/advisories/52315" source="SECUNIA" adv="1">52315</ref>
      <ref url="http://secunia.com/advisories/51928" source="SECUNIA" adv="1">51928</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0508.html" source="REDHAT">RHSA-2013:0508</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098613.html" source="FEDORA">FEDORA-2013-1826</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098434.html" source="FEDORA">FEDORA-2013-1795</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/commit/?id=e864d914a44a37016736554e9257c06b18c57d37" source="CONFIRM">http://git.fedorahosted.org/cgit/sssd.git/commit/?id=e864d914a44a37016736554e9257c06b18c57d37</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/commit/?id=94cbf1cfb0f88c967f1fb0a4cf23723148868e4a" source="CONFIRM">http://git.fedorahosted.org/cgit/sssd.git/commit/?id=94cbf1cfb0f88c967f1fb0a4cf23723148868e4a</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/commit/?id=3843b284cd3e8f88327772ebebc7249990fd87b9" source="CONFIRM">http://git.fedorahosted.org/cgit/sssd.git/commit/?id=3843b284cd3e8f88327772ebebc7249990fd87b9</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/commit/?id=020bf88fd1c5bdac8fc671b37c7118f5378c7047" source="CONFIRM">http://git.fedorahosted.org/cgit/sssd.git/commit/?id=020bf88fd1c5bdac8fc671b37c7118f5378c7047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fedoraproject" name="sssd">
        <vers num="0.2.1"/>
        <vers num="0.3.0"/>
        <vers num="0.3.1"/>
        <vers num="0.3.2"/>
        <vers num="0.3.3"/>
        <vers num="0.4.0"/>
        <vers num="0.4.1"/>
        <vers num="0.5.0"/>
        <vers num="0.6.0"/>
        <vers num="0.6.1"/>
        <vers num="0.7.0"/>
        <vers num="0.7.1"/>
        <vers num="0.99.0"/>
        <vers num="0.99.1"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.99"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.91"/>
        <vers num="1.1.92"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.91"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.5.14"/>
        <vers num="1.5.15"/>
        <vers num="1.5.16"/>
        <vers num="1.5.17"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.6.1"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.5.9"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.7.0"/>
        <vers num="1.8.0" edition="beta1"/>
        <vers num="1.8.0" edition="beta2"/>
        <vers num="1.8.0" edition="beta3"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers prev="1" num="1.9.3"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="5"/>
        <vers num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0220" published="2013-02-24" name="CVE-2013-0220" modified="2013-02-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4" source="CONFIRM">https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.4</ref>
      <ref url="https://fedorahosted.org/sssd/ticket/1781" source="CONFIRM">https://fedorahosted.org/sssd/ticket/1781</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=884601" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=884601</ref>
      <ref url="http://www.securityfocus.com/bid/57539" source="BID">57539</ref>
      <ref url="http://secunia.com/advisories/52315" source="SECUNIA" adv="1">52315</ref>
      <ref url="http://secunia.com/advisories/51928" source="SECUNIA" adv="1">51928</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0508.html" source="REDHAT">RHSA-2013:0508</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098613.html" source="FEDORA">FEDORA-2013-1826</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098434.html" source="FEDORA">FEDORA-2013-1795</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/commit/?id=30e2585dd46b62aa3a4abdf6de3f40a20e1743ab" source="CONFIRM">http://git.fedorahosted.org/cgit/sssd.git/commit/?id=30e2585dd46b62aa3a4abdf6de3f40a20e1743ab</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/commit/?id=2bd514cfde1938b1e245af11c9b548d58d49b325" source="CONFIRM">http://git.fedorahosted.org/cgit/sssd.git/commit/?id=2bd514cfde1938b1e245af11c9b548d58d49b325</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fedoraproject" name="sssd">
        <vers num="0.2.1"/>
        <vers num="0.3.0"/>
        <vers num="0.3.1"/>
        <vers num="0.3.2"/>
        <vers num="0.3.3"/>
        <vers num="0.4.0"/>
        <vers num="0.4.1"/>
        <vers num="0.5.0"/>
        <vers num="0.6.0"/>
        <vers num="0.6.1"/>
        <vers num="0.7.0"/>
        <vers num="0.7.1"/>
        <vers num="0.99.0"/>
        <vers num="0.99.1"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.99"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.91"/>
        <vers num="1.1.92"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.91"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.5.14"/>
        <vers num="1.5.15"/>
        <vers num="1.5.16"/>
        <vers num="1.5.17"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.6.1"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.5.9"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.7.0"/>
        <vers num="1.8.0" edition="beta1"/>
        <vers num="1.8.0" edition="beta2"/>
        <vers num="1.8.0" edition="beta3"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers prev="1" num="1.9.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0224" published="2013-03-19" name="CVE-2013-0224" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">The Video module 7.x-2.x before 7.x-2.9 for Drupal, when using the FFmpeg transcoder, allows local users to execute arbitrary PHP code by modifying a temporary PHP file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://drupal.org/node/1896714" source="MISC" patch="1" adv="1">https://drupal.org/node/1896714</ref>
      <ref url="https://drupal.org/node/1895234" source="CONFIRM" patch="1">https://drupal.org/node/1895234</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/25/4" source="MLIST">[oss-security] 20130124 Re: CVE request for Drupal contributed modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="video_project" name="video">
        <vers num="7.x-2.0" edition="alpha1"/>
        <vers num="7.x-2.0" edition="alpha2"/>
        <vers num="7.x-2.0" edition="alpha3"/>
        <vers num="7.x-2.0" edition="alpha4"/>
        <vers num="7.x-2.0" edition="alpha5"/>
        <vers num="7.x-2.0" edition="alpha6"/>
        <vers num="7.x-2.1" edition="alpha1"/>
        <vers num="7.x-2.1" edition="alpha2"/>
        <vers num="7.x-2.1" edition="alpha3"/>
        <vers num="7.x-2.2" edition="beta1"/>
        <vers num="7.x-2.2" edition="beta2"/>
        <vers num="7.x-2.2" edition="beta3"/>
        <vers num="7.x-2.2" edition="beta4"/>
        <vers num="7.x-2.2" edition="beta5"/>
        <vers num="7.x-2.3"/>
        <vers num="7.x-2.4"/>
        <vers num="7.x-2.5"/>
        <vers num="7.x-2.6"/>
        <vers num="7.x-2.7"/>
        <vers num="7.x-2.8"/>
        <vers num="7.x-2.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0225" published="2013-03-19" name="CVE-2013-0225" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://drupal.org/node/1896720" source="MISC" patch="1" adv="1">https://drupal.org/node/1896720</ref>
      <ref url="https://drupal.org/node/1896276" source="CONFIRM" patch="1">https://drupal.org/node/1896276</ref>
      <ref url="https://drupal.org/node/1896272" source="CONFIRM" patch="1">https://drupal.org/node/1896272</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/25/4" source="MLIST">[oss-security] 20130124 Re: CVE request for Drupal contributed modules</ref>
      <ref url="http://drupalcode.org/project/user_relationships.git/commitdiff/b9a4739" source="CONFIRM">http://drupalcode.org/project/user_relationships.git/commitdiff/b9a4739</ref>
      <ref url="http://drupalcode.org/project/user_relationships.git/commitdiff/17e94b9" source="CONFIRM">http://drupalcode.org/project/user_relationships.git/commitdiff/17e94b9</ref>
    </refs>
    <vuln_soft>
      <prod vendor="user_relationships_project" name="user_relationships">
        <vers num="6.x-1.0" edition="beta1"/>
        <vers num="6.x-1.0" edition="beta10"/>
        <vers num="6.x-1.0" edition="beta2"/>
        <vers num="6.x-1.0" edition="beta3"/>
        <vers num="6.x-1.0" edition="beta4"/>
        <vers num="6.x-1.0" edition="beta5"/>
        <vers num="6.x-1.0" edition="beta6"/>
        <vers num="6.x-1.0" edition="beta7"/>
        <vers num="6.x-1.0" edition="beta8"/>
        <vers num="6.x-1.0" edition="beta9"/>
        <vers num="6.x-1.0" edition="rc1"/>
        <vers num="6.x-1.0" edition="rc2"/>
        <vers num="6.x-1.0" edition="rc3"/>
        <vers num="6.x-1.0" edition="rc4"/>
        <vers num="6.x-1.0" edition="rc5"/>
        <vers num="6.x-1.0" edition="rc6"/>
        <vers num="6.x-1.1"/>
        <vers num="6.x-1.2"/>
        <vers num="6.x-1.3"/>
        <vers num="6.x-1.x" edition="dev"/>
        <vers num="7.x-1.0" edition="alpha1"/>
        <vers num="7.x-1.0" edition="alpha2"/>
        <vers num="7.x-1.0" edition="alpha3"/>
        <vers num="7.x-1.0" edition="alpha4"/>
        <vers num="7.x-1.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0226" published="2013-03-19" name="CVE-2013-0226" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">The Keyboard Shortcut Utility module 7.x-1.x before 7.x-1.1 for Drupal does not properly check node restrictions, which allows (1) remote authenticated users with the "view shortcuts" permission to read nodes or (2) remote authenticated users with the "admin shortcuts" permission to read, edit, or delete nodes via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://drupal.org/node/1896752" source="CONFIRM" adv="1">https://drupal.org/node/1896752</ref>
      <ref url="https://drupal.org/node/1896752" source="MISC">https://drupal.org/node/1896752</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/25/4" source="MLIST">[oss-security] 20130124 Re: CVE request for Drupal contributed modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zugec_ivan" name="keyboard_shortcut_utility">
        <vers num="7.x-1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0227" published="2013-03-19" name="CVE-2013-0227" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://drupal.org/node/1896782" source="MISC" patch="1" adv="1">https://drupal.org/node/1896782</ref>
      <ref url="https://drupal.org/node/1896756" source="CONFIRM" patch="1">https://drupal.org/node/1896756</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/25/4" source="MLIST">[oss-security] 20130124 Re: CVE request for Drupal contributed modules</ref>
      <ref url="http://drupalcode.org/project/search_api_sorts.git/commitdiff/f6cbf47" source="CONFIRM">http://drupalcode.org/project/search_api_sorts.git/commitdiff/f6cbf47</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mathijs_koenraadt" name="search_api_sorts">
        <vers num="7.x-1.0"/>
        <vers num="7.x-1.1"/>
        <vers num="7.x-1.2"/>
        <vers num="7.x-1.3"/>
        <vers num="7.x-1.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0228" published="2013-03-01" name="CVE-2013-0228" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">The xen_iret function in arch/x86/xen/xen-asm_32.S in the Linux kernel before 3.7.9 on 32-bit Xen paravirt_ops platforms does not properly handle an invalid value in the DS segment register, which allows guest OS users to gain guest OS privileges via a crafted application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/13d2b4d11d69a92574a55bfd985cfb0ca77aebdc" source="CONFIRM">https://github.com/torvalds/linux/commit/13d2b4d11d69a92574a55bfd985cfb0ca77aebdc</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=906309" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=906309</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1808-1" source="UBUNTU">USN-1808-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1805-1" source="UBUNTU">USN-1805-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1797-1" source="UBUNTU">USN-1797-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1796-1" source="UBUNTU">USN-1796-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1795-1" source="UBUNTU">USN-1795-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/13/10" source="MLIST">[oss-security] 20130213 Xen Security Advisory 42 (CVE-2013-0228) - Linux kernel hits general protection if %ds is corrupt for 32-bit PVOPS.</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.9" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.9</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=13d2b4d11d69a92574a55bfd985cfb0ca77aebdc" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=13d2b4d11d69a92574a55bfd985cfb0ca77aebdc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers prev="1" num="3.7.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0229" published="2013-01-31" name="CVE-2013-0229" modified="2013-02-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://community.rapid7.com/servlet/JiveServlet/download/2150-1-16596/SecurityFlawsUPnP.pdf" source="MISC">https://community.rapid7.com/servlet/JiveServlet/download/2150-1-16596/SecurityFlawsUPnP.pdf</ref>
      <ref url="https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-play" source="MISC">https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-play</ref>
    </refs>
    <vuln_soft>
      <prod vendor="miniupnp_project" name="miniupnpd">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers prev="1" num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0230" published="2013-01-31" name="CVE-2013-0230" modified="2013-02-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://community.rapid7.com/servlet/JiveServlet/download/2150-1-16596/SecurityFlawsUPnP.pdf" source="MISC">https://community.rapid7.com/servlet/JiveServlet/download/2150-1-16596/SecurityFlawsUPnP.pdf</ref>
      <ref url="https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-play" source="MISC">https://community.rapid7.com/community/infosec/blog/2013/01/29/security-flaws-in-universal-plug-and-play-unplug-dont-play</ref>
    </refs>
    <vuln_soft>
      <prod vendor="miniupnp_project" name="miniupnpd">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0231" published="2013-02-12" name="CVE-2013-0231" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81923" source="XF">xen-pcibackenablemsi-dos(81923)</ref>
      <ref url="http://www.securityfocus.com/bid/57740" source="BID">57740</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/05/9" source="MLIST">[oss-security] 20130205 Xen Security Advisory 43 (CVE-2013-0231) - Linux pciback DoS via not rate limited log messages.</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2632" source="DEBIAN">DSA-2632</ref>
      <ref url="http://secunia.com/advisories/52059" source="SECUNIA" adv="1">52059</ref>
      <ref url="http://osvdb.org/89903" source="OSVDB">89903</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.html" source="SUSE">SUSE-SU-2013:0674</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.html" source="SUSE">openSUSE-SU-2013:0395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.18"/>
        <vers num="3.8"/>
      </prod>
      <prod vendor="xen" name="xen">
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0232" published="2013-03-20" name="CVE-2013-0232" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.zoneminder.com/forums/viewtopic.php?f=29&amp;t=20771" source="MISC">http://www.zoneminder.com/forums/viewtopic.php?f=29&amp;t=20771</ref>
      <ref url="http://www.osvdb.org/89529" source="OSVDB">89529</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/28/2" source="MLIST">[oss-security] 20130128 Re: CVE Request: zoneminder: arbitrary command execution vulnerability</ref>
      <ref url="http://www.exploit-db.com/exploits/24310" source="EXPLOIT-DB">24310</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2640" source="DEBIAN">DSA-2640</ref>
      <ref url="http://itsecuritysolutions.org/2013-01-22-ZoneMinder-Video-Server-arbitrary-command-execution-vulnerability/" source="MISC">http://itsecuritysolutions.org/2013-01-22-ZoneMinder-Video-Server-arbitrary-command-execution-vulnerability/</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=698910" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=698910</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zoneminder" name="zoneminder">
        <vers num="1.24.0"/>
        <vers num="1.24.1"/>
        <vers num="1.24.2"/>
        <vers num="1.24.3"/>
        <vers num="1.24.4"/>
        <vers num="1.25.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0233" published="2013-04-25" name="CVE-2013-0233" modified="2013-05-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://lists.opensuse.org/opensuse-updates/2013-03/msg00000.html
"Affected Products:
openSUSE 12.2"</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://github.com/Snorby/snorby/issues/261" source="MISC">https://github.com/Snorby/snorby/issues/261</ref>
      <ref url="http://www.securityfocus.com/bid/57577" source="BID">57577</ref>
      <ref url="http://www.phenoelit.org/blog/archives/2013/02/05/mysql_madness_and_rails/index.html" source="MISC">http://www.phenoelit.org/blog/archives/2013/02/05/mysql_madness_and_rails/index.html</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/29/3" source="MLIST">[oss-security] 20130128 Re: CVE request for 'devise' ruby gem</ref>
      <ref url="http://www.metasploit.com/modules/auxiliary/admin/http/rails_devise_pass_reset" source="MISC">http://www.metasploit.com/modules/auxiliary/admin/http/rails_devise_pass_reset</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00000.html" source="SUSE">openSUSE-SU-2013:0374</ref>
      <ref url="http://blog.plataformatec.com.br/2013/01/security-announcement-devise-v2-2-3-v2-1-3-v2-0-5-and-v1-5-3-released/" source="CONFIRM" adv="1">http://blog.plataformatec.com.br/2013/01/security-announcement-devise-v2-2-3-v2-1-3-v2-0-5-and-v1-5-3-released/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plataformatec" name="devise">
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
      </prod>
      <prod vendor="novell" name="opensuse">
        <vers num="12.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0238" published="2013-02-12" name="CVE-2013-0238" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allows remote attackers to cause a denial of service (crash) via a mask that causes a negative number to be parsed.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81695" source="XF">ircdhybrid-tryparsev4netmask-dos(81695)</ref>
      <ref url="http://www.securityfocus.com/bid/57610" source="BID">57610</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/29/8" source="MLIST">[oss-security] 20130129 ircd-hybrid: Denial of service vulnerability in  hostmask.c:try_parse_v4_netmask()</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2618" source="DEBIAN">DSA-2618</ref>
      <ref url="http://svn.ircd-hybrid.org:8000/viewcvs.cgi/ircd-hybrid/trunk/src/hostmask.c?r1=1786&amp;r2=1785&amp;pathrev=1786" source="CONFIRM">http://svn.ircd-hybrid.org:8000/viewcvs.cgi/ircd-hybrid/trunk/src/hostmask.c?r1=1786&amp;r2=1785&amp;pathrev=1786</ref>
      <ref url="http://secunia.com/advisories/52106" source="SECUNIA" adv="1">52106</ref>
      <ref url="http://secunia.com/advisories/51948" source="SECUNIA" adv="1">51948</ref>
      <ref url="http://osvdb.org/89623" source="OSVDB">89623</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699267" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699267</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ircd-hybrid" name="ircd-hybrid">
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.3.0" edition="rc1"/>
        <vers num="7.3.1"/>
        <vers num="8.0.0" edition="beta1"/>
        <vers num="8.0.0" edition="beta2"/>
        <vers num="8.0.0" edition="beta3"/>
        <vers num="8.0.0" edition="rc1"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers prev="1" num="8.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0239" published="2013-03-12" name="CVE-2013-0239" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1438424" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1438424</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/81981" source="XF">apachecxf-username-tokens-sec-bypass(81981)</ref>
      <ref url="http://www.securityfocus.com/bid/57876" source="BID">57876</ref>
      <ref url="http://secunia.com/advisories/51988" source="SECUNIA" adv="1">51988</ref>
      <ref url="http://seclists.org/fulldisclosure/2013/Feb/39" source="FULLDISC">20130208 New security advisories for Apache CXF</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0749.html" source="REDHAT">RHSA-2013:0749</ref>
      <ref url="http://packetstormsecurity.com/files/120214/Apache-CXF-WS-Security-UsernameToken-Bypass.html" source="MISC">http://packetstormsecurity.com/files/120214/Apache-CXF-WS-Security-UsernameToken-Bypass.html</ref>
      <ref url="http://osvdb.org/90078" source="OSVDB">90078</ref>
      <ref url="http://cxf.apache.org/cve-2013-0239.html" source="CONFIRM" adv="1">http://cxf.apache.org/cve-2013-0239.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="cxf">
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers prev="1" num="2.5.8"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0240" published="2013-04-01" name="CVE-2013-0240" modified="2013-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://www.ubuntu.com/usn/usn-1779-1/
"A security issue affects these releases of Ubuntu and its derivatives:
    Ubuntu 12.10
    Ubuntu 12.04 LTS
    Ubuntu 11.10"</impact>
    </impacts>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://mail.gnome.org/archives/gnome-announce-list/2013-March/msg00007.html" source="MLIST">[gnome-announce-list] 20130304 GNOME Online Accounts 3.6.3 released</ref>
      <ref url="https://git.gnome.org/browse/gnome-online-accounts/commit/?id=edde7c63326242a60a075341d3fea0be0bc4d80e" source="CONFIRM">https://git.gnome.org/browse/gnome-online-accounts/commit/?id=edde7c63326242a60a075341d3fea0be0bc4d80e</ref>
      <ref url="https://git.gnome.org/browse/gnome-online-accounts/commit/?id=bc10fdb68f75f8be84eb698ada08743b9c7c248f" source="CONFIRM">https://git.gnome.org/browse/gnome-online-accounts/commit/?id=bc10fdb68f75f8be84eb698ada08743b9c7c248f</ref>
      <ref url="https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&amp;id=ecad8142e9ac519b9fc74b96dcb5531052bbffe1" source="CONFIRM">https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&amp;id=ecad8142e9ac519b9fc74b96dcb5531052bbffe1</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=894352" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=894352</ref>
      <ref url="https://bugzilla.gnome.org/show_bug.cgi?id=693214" source="CONFIRM">https://bugzilla.gnome.org/show_bug.cgi?id=693214</ref>
      <ref url="http://ubuntu.com/usn/usn-1779-1" source="UBUNTU">USN-1779-1</ref>
      <ref url="http://secunia.com/advisories/52791" source="SECUNIA" adv="1">52791</ref>
      <ref url="http://secunia.com/advisories/51976" source="SECUNIA" adv="1">51976</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00046.html" source="SUSE">openSUSE-SU-2013:0301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gnome_online_accounts">
        <vers num="3.4.0"/>
        <vers num="3.4.1"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
      </prod>
      <prod vendor="canonical" name="ubuntu_linux">
        <vers num="11.10"/>
        <vers num="12.04" edition="-"/>
        <vers num="12.04" edition="-:lts"/>
        <vers num="12.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0241" published="2013-02-12" name="CVE-2013-0241" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemu_mutex mutex.  NOTE: some of these details are obtained from third party information.</descript>
      <descript source="nvd">Per https://rhn.redhat.com/errata/RHSA-2013-0218.html
Affected Products: 	
Red Hat Enterprise Linux Desktop (v. 6)
Red Hat Enterprise Linux Server (v. 6)
Red Hat Enterprise Linux Workstation (v. 6)

Per http://www.ubuntu.com/usn/USN-1714-1/
A security issue affects these releases of Ubuntu and its derivatives:
Ubuntu 12.04 LTS
Ubuntu 11.10
</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=906032" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=906032</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/81704" source="XF">qxl-virtual-spice-dos(81704)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1714-1" source="UBUNTU">USN-1714-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/30/4" source="MLIST">[oss-security] 20130130 Re: CVE request -- qxl: synchronous io guest DoS</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/30/3" source="MLIST">[oss-security] 20130130 CVE request -- qxl: synchronous io guest DoS</ref>
      <ref url="http://secunia.com/advisories/52021" source="SECUNIA" adv="1">52021</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0218.html" source="REDHAT">RHSA-2013:0218</ref>
    </refs>
    <vuln_soft>
      <prod vendor="canonical" name="ubuntu_linux">
        <vers num="11.10"/>
        <vers num="12.04" edition="-"/>
        <vers num="12.04" edition="-:lts"/>
      </prod>
      <prod vendor="qxl_graphics_driver_project" name="xf86-video-qxl">
        <vers num="0.1.0"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="6.0"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_server">
        <vers num="6.0"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux_workstation">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0242" published="2013-02-08" name="CVE-2013-0242" modified="2013-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceware.org/bugzilla/show_bug.cgi?id=15078" source="MISC" patch="1">http://sourceware.org/bugzilla/show_bug.cgi?id=15078</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/81707" source="XF">glibc-extendbuffers-dos(81707)</ref>
      <ref url="http://www.securitytracker.com/id/1028063" source="SECTRACK">1028063</ref>
      <ref url="http://www.securityfocus.com/bid/57638" source="BID">57638</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/01/30/5" source="MLIST">[oss-security] 20130130 Re: CVE Request -- glibc: DoS due to a buffer overrun in regexp matcher by processing multibyte characters</ref>
      <ref url="http://sourceware.org/ml/libc-alpha/2013-01/msg00967.html" source="MLIST">[libc-alpha] 20130129 [PATCH] Fix buffer overrun in regexp matcher</ref>
      <ref url="http://secunia.com/advisories/51951" source="SECUNIA" adv="1">51951</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0769.html" source="REDHAT">RHSA-2013:0769</ref>
      <ref url="http://osvdb.org/89747" source="OSVDB">89747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0247" published="2013-02-24" name="CVE-2013-0247" modified="2013-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.</descript>
      <descript source="nvd">Per http://www.ubuntu.com/usn/USN-1715-1/
A security issue affects these releases of Ubuntu and its derivatives:
Ubuntu 12.10 Ubuntu 12.04 LTS
</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=906171" source="MISC" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=906171</ref>
      <ref url="https://bugs.launchpad.net/keystone/+bug/1098307" source="CONFIRM">https://bugs.launchpad.net/keystone/+bug/1098307</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1715-1" source="UBUNTU">USN-1715-1</ref>
      <ref url="http://www.securityfocus.com/bid/57747" source="BID">57747</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0253.html" source="REDHAT">RHSA-2013:0253</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098906.html" source="FEDORA">FEDORA-2013-2168</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openstack" name="essex">
        <vers num="2012.1"/>
        <vers prev="1" num="2012.1.3"/>
      </prod>
      <prod vendor="openstack" name="grizzly">
        <vers num="-" edition="rc1"/>
        <vers prev="1" num="1"/>
      </prod>
      <prod vendor="canonical" name="ubuntu_linux">
        <vers num="12.04" edition="-"/>
        <vers num="12.04" edition="-:lts"/>
        <vers num="12.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0248" published="2013-03-15" name="CVE-2013-0248" modified="2013-03-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/90906" source="OSVDB">90906</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2013-03/0035.html" source="BUGTRAQ">20130306 [SECURITY] CVE-2013-0248 Apache Commons FileUpload - Insecure examples</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="commons_fileupload">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0249" published="2013-03-08" name="CVE-2013-0249" modified="2013-05-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the realm parameter in a (1) POP3, (2) SMTP or (3) IMAP message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1721-1" source="UBUNTU" adv="1">USN-1721-1</ref>
      <ref url="http://www.securitytracker.com/id/1028093" source="SECTRACK">1028093</ref>
      <ref url="http://www.osvdb.org/89988" source="OSVDB">89988</ref>
      <ref url="http://www.exploit-db.com/exploits/24487" source="EXPLOIT-DB">24487</ref>
      <ref url="http://packetstormsecurity.com/files/120170/Slackware-Security-Advisory-curl-Updates.html" source="MISC">http://packetstormsecurity.com/files/120170/Slackware-Security-Advisory-curl-Updates.html</ref>
      <ref url="http://packetstormsecurity.com/files/120147/cURL-Buffer-Overflow.html" source="MISC">http://packetstormsecurity.com/files/120147/cURL-Buffer-Overflow.html</ref>
      <ref url="http://nakedsecurity.sophos.com/2013/02/10/anatomy-of-a-vulnerability-curl-web-download-toolkit-holed-by-authentication-bug/" source="MISC">http://nakedsecurity.sophos.com/2013/02/10/anatomy-of-a-vulnerability-curl-web-download-toolkit-holed-by-authentication-bug/</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099140.html" source="FEDORA">FEDORA-2013-2098</ref>
      <ref url="http://curl.haxx.se/docs/adv_20130206.html" source="CONFIRM" adv="1">http://curl.haxx.se/docs/adv_20130206.html</ref>
      <ref url="http://blog.volema.com/curl-rce.html" source="MISC">http://blog.volema.com/curl-rce.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="haxx" name="curl">
        <vers num="7.26.0"/>
        <vers num="7.27.0"/>
        <vers num="7.28.0"/>
        <vers num="7.28.1"/>
      </prod>
      <prod vendor="haxx" name="libcurl">
        <vers num="7.26.0"/>
        <vers num="7.27.0"/>
        <vers num="7.28.0"/>
        <vers num="7.28.1"/>
      </prod>
      <prod vendor="ubuntu" name="ubuntu">
        <vers num="12.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0251" published="2013-03-19" name="CVE-2013-0251" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in llogincircuit.cc in latd 1.25 through 1.30 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the llogin version.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/05/2" source="MLIST">[oss-security] 20130205 Re: CVE id request: latd</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/04/3" source="MLIST">[oss-security] 20130203 Re: CVE id request: latd</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699625" source="MISC" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="latd">
        <vers num="1.25"/>
        <vers num="1.26"/>
        <vers num="1.27"/>
        <vers num="1.28"/>
        <vers num="1.29"/>
        <vers num="1.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0252" published="2013-03-12" name="CVE-2013-0252" modified="2013-03-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">boost::locale::utf::utf_traits in the Boost.Locale library in Boost 1.48 through 1.52 does not properly detect certain invalid UTF-8 sequences, which might allow remote attackers to bypass input validation protection mechanisms via crafted trailing bytes.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://svn.boost.org/trac/boost/ticket/7743" source="CONFIRM">https://svn.boost.org/trac/boost/ticket/7743</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=907481" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=907481</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1727-1" source="UBUNTU">USN-1727-1</ref>
      <ref url="http://www.securityfocus.com/bid/57675" source="BID">57675</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/04/2" source="MLIST">[oss-security] 20130203 Re: CVE id request: boost</ref>
      <ref url="http://www.boost.org/users/news/boost_locale_security_notice.html" source="CONFIRM">http://www.boost.org/users/news/boost_locale_security_notice.html</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099122.html" source="FEDORA">FEDORA-2013-2448</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099103.html" source="FEDORA">FEDORA-2013-2420</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699650" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699650</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699649" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boost" name="boost">
        <vers num="1.48.0"/>
        <vers num="1.49.0"/>
        <vers num="1.50.0"/>
        <vers num="1.51.0"/>
        <vers num="1.52.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0253" published="2013-04-09" name="CVE-2013-0253" modified="2013-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://maven.apache.org/security.html" source="CONFIRM" patch="1" adv="1">https://maven.apache.org/security.html</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=917084" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=917084</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0700.html" source="REDHAT">RHSA-2013:0700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="maven">
        <vers num="3.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0254" published="2013-02-06" name="CVE-2013-0254" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://lists.qt-project.org/pipermail/announce/2013-February/000023.html" source="MLIST" patch="1" adv="1">[qt-announce] 20130205 [Announce] [CVE-2013-0254] Qt Project Security Advisory: System V shared memory segments created world-writeable</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=907425" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=907425</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0669.html" source="REDHAT">RHSA-2013:0669</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00019.html" source="SUSE">openSUSE-SU-2013:0411</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00015.html" source="SUSE">openSUSE-SU-2013:0404</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00014.html" source="SUSE">openSUSE-SU-2013:0403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digia" name="qt">
        <vers num="1.41"/>
        <vers num="1.42"/>
        <vers num="1.43"/>
        <vers num="1.44"/>
        <vers num="1.45"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.3"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="4.4.3"/>
        <vers num="4.5.0"/>
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.8.0"/>
        <vers num="4.8.1"/>
        <vers num="4.8.2"/>
        <vers num="4.8.3"/>
        <vers num="4.8.4"/>
        <vers num="4.8.5"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0255" published="2013-02-12" name="CVE-2013-0255" modified="2013-04-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PostgreSQL 9.2.x before 9.2.3, 9.1.x before 9.1.8, 9.0.x before 9.0.12, 8.4.x before 8.4.16, and 8.3.x before 8.3.23 does not properly declare the enum_recv function in backend/utils/adt/enum.c, which causes it to be invoked with incorrect arguments and allows remote authenticated users to cause a denial of service (server crash) or read sensitive process memory via a crafted SQL command, which triggers an array index error and an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=907892" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=907892</ref>
      <ref url="https://blogs.oracle.com/sunsecurity/entry/cve_2013_0255_array_index" source="CONFIRM">https://blogs.oracle.com/sunsecurity/entry/cve_2013_0255_array_index</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/81917" source="XF">postgresql-enumrecv-dos(81917)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1717-1" source="UBUNTU">USN-1717-1</ref>
      <ref url="http://www.securityfocus.com/bid/57844" source="BID">57844</ref>
      <ref url="http://www.postgresql.org/docs/9.2/static/release-9-2-3.html" source="CONFIRM">http://www.postgresql.org/docs/9.2/static/release-9-2-3.html</ref>
      <ref url="http://www.postgresql.org/docs/9.1/static/release-9-1-8.html" source="CONFIRM">http://www.postgresql.org/docs/9.1/static/release-9-1-8.html</ref>
      <ref url="http://www.postgresql.org/docs/9.0/static/release-9-0-12.html" source="CONFIRM">http://www.postgresql.org/docs/9.0/static/release-9-0-12.html</ref>
      <ref url="http://www.postgresql.org/docs/8.4/static/release-8-4-16.html" source="CONFIRM">http://www.postgresql.org/docs/8.4/static/release-8-4-16.html</ref>
      <ref url="http://www.postgresql.org/docs/8.3/static/release-8-3-23.html" source="CONFIRM">http://www.postgresql.org/docs/8.3/static/release-8-3-23.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2630" source="DEBIAN">DSA-2630</ref>
      <ref url="http://secunia.com/advisories/52819" source="SECUNIA">52819</ref>
      <ref url="http://secunia.com/advisories/51923" source="SECUNIA" adv="1">51923</ref>
      <ref url="http://osvdb.org/89935" source="OSVDB">89935</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00060.html" source="SUSE">openSUSE-SU-2013:0319</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00059.html" source="SUSE">openSUSE-SU-2013:0318</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098586.html" source="FEDORA">FEDORA-2013-2123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="8.3"/>
        <vers num="8.3.1"/>
        <vers num="8.3.10"/>
        <vers num="8.3.11"/>
        <vers num="8.3.12"/>
        <vers num="8.3.13"/>
        <vers num="8.3.14"/>
        <vers num="8.3.15"/>
        <vers num="8.3.16"/>
        <vers num="8.3.17"/>
        <vers num="8.3.18"/>
        <vers num="8.3.19"/>
        <vers num="8.3.2"/>
        <vers num="8.3.20"/>
        <vers num="8.3.21"/>
        <vers num="8.3.22"/>
        <vers num="8.3.3"/>
        <vers num="8.3.4"/>
        <vers num="8.3.5"/>
        <vers num="8.3.6"/>
        <vers num="8.3.7"/>
        <vers num="8.3.8"/>
        <vers num="8.3.9"/>
        <vers num="8.4"/>
        <vers num="8.4.1"/>
        <vers num="8.4.10"/>
        <vers num="8.4.11"/>
        <vers num="8.4.12"/>
        <vers num="8.4.13"/>
        <vers num="8.4.14"/>
        <vers num="8.4.15"/>
        <vers num="8.4.2"/>
        <vers num="8.4.3"/>
        <vers num="8.4.4"/>
        <vers num="8.4.5"/>
        <vers num="8.4.6"/>
        <vers num="8.4.7"/>
        <vers num="8.4.8"/>
        <vers num="8.4.9"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.10"/>
        <vers num="9.0.11"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.0.4"/>
        <vers num="9.0.5"/>
        <vers num="9.0.6"/>
        <vers num="9.0.7"/>
        <vers num="9.0.8"/>
        <vers num="9.0.9"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3"/>
        <vers num="9.1.4"/>
        <vers num="9.1.5"/>
        <vers num="9.1.6"/>
        <vers num="9.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0256" published="2013-03-01" name="CVE-2013-0256" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://www.ruby-lang.org/en/news/2013/02/06/rdoc-xss-cve-2013-0256/
Affected versions
All ruby 1.9 versions prior to ruby 1.9.3 patchlevel 383
All ruby 2.0 versions prior to ruby 2.0.0 rc2 or prior to trunk revision 39102
</impact>
    </impacts>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://github.com/rdoc/rdoc/commit/ffa87887ee0517793df7541629a470e331f9fe60" source="CONFIRM">https://github.com/rdoc/rdoc/commit/ffa87887ee0517793df7541629a470e331f9fe60</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=907820" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=907820</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1733-1" source="UBUNTU">USN-1733-1</ref>
      <ref url="http://www.ruby-lang.org/en/news/2013/02/06/rdoc-xss-cve-2013-0256/" source="CONFIRM" adv="1">http://www.ruby-lang.org/en/news/2013/02/06/rdoc-xss-cve-2013-0256/</ref>
      <ref url="http://secunia.com/advisories/52774" source="SECUNIA">52774</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0728.html" source="REDHAT">RHSA-2013:0728</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0701.html" source="REDHAT">RHSA-2013:0701</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0686.html" source="REDHAT">RHSA-2013:0686</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0548.html" source="REDHAT">RHSA-2013:0548</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00048.html" source="SUSE">openSUSE-SU-2013:0303</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00015.html" source="SUSE">SUSE-SU-2013:0647</ref>
      <ref url="http://blog.segment7.net/2013/02/06/rdoc-xss-vulnerability-cve-2013-0256-releases-3-9-5-3-12-1-4-0-0-rc-2" source="MISC">http://blog.segment7.net/2013/02/06/rdoc-xss-vulnerability-cve-2013-0256-releases-3-9-5-3-12-1-4-0-0-rc-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dave_thomas" name="rdoc">
        <vers num="2.3.0"/>
        <vers num="3.12"/>
        <vers num="4.0.0"/>
      </prod>
      <prod vendor="ruby-lang" name="ruby">
        <vers num="1.9"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3" edition="p0"/>
        <vers num="1.9.3" edition="p125"/>
        <vers num="1.9.3" edition="p194"/>
        <vers num="1.9.3" edition="p286"/>
        <vers num="1.9.3" edition="p383"/>
        <vers num="2.0"/>
        <vers num="2.0.0" edition="rc1"/>
        <vers num="2.0.0" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0257" published="2013-03-27" name="CVE-2013-0257" modified="2013-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of user email addresses and email fields.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://drupal.org/node/1903264" source="MISC" patch="1" adv="1">http://drupal.org/node/1903264</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/05/1" source="MLIST">[oss-security] 20130204 Re: CVE request for Drupal contributed modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="david_alkire" name="email2image">
        <vers num="6.x-1.x"/>
        <vers num="6.x-2.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0258" published="2013-03-27" name="CVE-2013-0258" modified="2013-04-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://drupalcode.org/project/ga_login.git/commitdiff/50b032d" source="CONFIRM" patch="1">http://drupalcode.org/project/ga_login.git/commitdiff/50b032d</ref>
      <ref url="http://drupal.org/node/1903282" source="MISC" patch="1" adv="1">http://drupal.org/node/1903282</ref>
      <ref url="http://drupal.org/node/1902102" source="CONFIRM" patch="1">http://drupal.org/node/1902102</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/05/1" source="MLIST">[oss-security] 20130204 Re: CVE request for Drupal contributed modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google_authenticator_login_project" name="ga_login">
        <vers num="7.x-1.0" edition="beta1"/>
        <vers num="7.x-1.0" edition="dev"/>
        <vers num="7.x-1.1"/>
        <vers num="7.x-1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0259" published="2013-03-27" name="CVE-2013-0259" modified="2013-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://drupal.org/node/1903300" source="MISC" patch="1" adv="1">http://drupal.org/node/1903300</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/05/1" source="MLIST">[oss-security] 20130204 Re: CVE request for Drupal contributed modules</ref>
      <ref url="http://drupalcode.org/project/boxes.git/commitdiff/456ff8e" source="CONFIRM">http://drupalcode.org/project/boxes.git/commitdiff/456ff8e</ref>
      <ref url="http://drupal.org/node/1897016" source="CONFIRM">http://drupal.org/node/1897016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boxes_project" name="boxes">
        <vers num="7.x-1.0" edition="beta1"/>
        <vers num="7.x-1.0" edition="beta2"/>
        <vers num="7.x-1.0" edition="beta3"/>
        <vers num="7.x-1.0" edition="beta4"/>
        <vers num="7.x-1.0" edition="beta5"/>
        <vers num="7.x-1.0" edition="beta6"/>
        <vers num="7.x-1.0" edition="beta7"/>
        <vers num="7.x-1.0" edition="beta8"/>
        <vers num="7.x-1.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0260" published="2013-03-27" name="CVE-2013-0260" modified="2013-03-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/05/1" source="MLIST">[oss-security] 20130204 Re: CVE request for Drupal contributed modules</ref>
      <ref url="http://drupal.org/node/1903324" source="MISC" adv="1">http://drupal.org/node/1903324</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elliot_pahl" name="drush_debian_packaging">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0261" published="2013-03-08" name="CVE-2013-0261" modified="2013-03-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">(1) installer/basedefs.py and (2) modules/ospluginutils.py in PackStack allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://rhn.redhat.com/errata/RHSA-2013-0595.html these are the affected products:

Red Hat OpenStack Essex
Red Hat OpenStack Folsom</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=908101" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=908101</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0595.html" source="REDHAT" adv="1">RHSA-2013:0595</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openstack" name="essex">
        <vers num="-"/>
      </prod>
      <prod vendor="openstack" name="folsom">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0262" published="2013-02-08" name="CVE-2013-0262" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ" source="CONFIRM">https://groups.google.com/forum/#!msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ</ref>
      <ref url="https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ" source="CONFIRM">https://groups.google.com/forum/#!msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ</ref>
      <ref url="https://github.com/rack/rack/commit/6f237e4c9fab649d3750482514f0fde76c56ab30" source="CONFIRM">https://github.com/rack/rack/commit/6f237e4c9fab649d3750482514f0fde76c56ab30</ref>
      <ref url="https://github.com/rack/rack/blob/master/lib/rack/file.rb#L56" source="MISC">https://github.com/rack/rack/blob/master/lib/rack/file.rb#L56</ref>
      <ref url="https://gist.github.com/rentzsch/4736940" source="MISC">https://gist.github.com/rentzsch/4736940</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=909072" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=909072</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=909071" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=909071</ref>
      <ref url="http://secunia.com/advisories/52033" source="SECUNIA" adv="1">52033</ref>
      <ref url="http://rack.github.com/" source="CONFIRM">http://rack.github.com/</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html" source="SUSE">openSUSE-SU-2013:0462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rack_project" name="rack">
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0263" published="2013-02-08" name="CVE-2013-0263" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving am HMAC comparison function that does not run in constant time.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://twitter.com/coda/statuses/299732877745197056" source="MISC">https://twitter.com/coda/statuses/299732877745197056</ref>
      <ref url="https://groups.google.com/forum/#%21msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ" source="CONFIRM">https://groups.google.com/forum/#!msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ</ref>
      <ref url="https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ" source="CONFIRM">https://groups.google.com/forum/#!msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ</ref>
      <ref url="https://groups.google.com/forum/#%21msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ" source="CONFIRM">https://groups.google.com/forum/#!msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ</ref>
      <ref url="https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ" source="CONFIRM">https://groups.google.com/forum/#!msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ</ref>
      <ref url="https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J" source="CONFIRM">https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J</ref>
      <ref url="https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11" source="CONFIRM">https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11</ref>
      <ref url="https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07" source="CONFIRM">https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07</ref>
      <ref url="https://gist.github.com/codahale/f9f3781f7b54985bee94" source="MISC">https://gist.github.com/codahale/f9f3781f7b54985bee94</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=909071" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=909071</ref>
      <ref url="http://www.osvdb.org/89939" source="OSVDB">89939</ref>
      <ref url="http://secunia.com/advisories/52774" source="SECUNIA">52774</ref>
      <ref url="http://secunia.com/advisories/52134" source="SECUNIA" adv="1">52134</ref>
      <ref url="http://secunia.com/advisories/52033" source="SECUNIA" adv="1">52033</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0686.html" source="REDHAT">RHSA-2013:0686</ref>
      <ref url="http://rack.github.com/" source="CONFIRM" adv="1">http://rack.github.com/</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html" source="SUSE">openSUSE-SU-2013:0462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rack_project" name="rack">
        <vers num="1.1.0"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0265" published="2013-02-12" name="CVE-2013-0265" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The redirect_stderr function in xnbd_common.c in xnbd-server and xndb-wrapper in xNBD 0.1.0 allow local users to overwrite arbitrary files via a symlink attack on /tmp/xnbd.log.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/06/2" source="MLIST" patch="1">[oss-security] 20130206 CVE request: Insecure default log file path in xNBD</ref>
      <ref url="http://www.osvdb.org/90008" source="OSVDB">90008</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/07/5" source="MLIST">[oss-security] 20130206 Re: CVE request: Insecure default log file path in  xNBD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitbucket" name="xnbd">
        <vers num="0.1.0" edition="pre"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0266" published="2013-03-08" name="CVE-2013-0266" modified="2013-03-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading the files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/puppetlabs/puppetlabs-cinder/commit/7da792fbd40c0e6eae1ee093aa00e0b177bd2ebc" source="CONFIRM">https://github.com/puppetlabs/puppetlabs-cinder/commit/7da792fbd40c0e6eae1ee093aa00e0b177bd2ebc</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=908581" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=908581</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0595.html" source="REDHAT" adv="1">RHSA-2013:0595</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openstack" name="essex">
        <vers num="-"/>
      </prod>
      <prod vendor="openstack" name="folsom">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0268" published="2013-02-17" name="CVE-2013-0268" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c903f0456bc69176912dee6dd25c6a66ee1aed00" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c903f0456bc69176912dee6dd25c6a66ee1aed00</ref>
      <ref url="https://github.com/torvalds/linux/commit/c903f0456bc69176912dee6dd25c6a66ee1aed00" source="CONFIRM">https://github.com/torvalds/linux/commit/c903f0456bc69176912dee6dd25c6a66ee1aed00</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=908693" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=908693</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/07/12" source="MLIST">[oss-security] 20130207 Re: CVE request -- Linux kernel: x86/msr: /dev/cpu/*/msr local privilege escalation</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.6" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.6</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00018.html" source="SUSE">SUSE-SU-2013:0674</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers prev="1" num="3.7.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0269" published="2013-02-12" name="CVE-2013-0269" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://groups.google.com/group/rubyonrails-security/msg/d8e0db6e08c81428?dmode=source&amp;output=gplain" source="MLIST">[rubyonrails-security] 20130211 Denial of Service and Unsafe Object Creation Vulnerability in JSON [CVE-2013-0269]</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/82010" source="XF">json-ruby-security-bypass(82010)</ref>
      <ref url="http://www.zweitag.de/en/blog/ruby-on-rails-vulnerable-to-mass-assignment-and-sql-injection" source="MISC">http://www.zweitag.de/en/blog/ruby-on-rails-vulnerable-to-mass-assignment-and-sql-injection</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1733-1" source="UBUNTU">USN-1733-1</ref>
      <ref url="http://www.securityfocus.com/bid/57899" source="BID">57899</ref>
      <ref url="http://www.osvdb.org/90074" source="OSVDB">90074</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/11/8" source="MLIST">[oss-security] 20130211 Patch update for [CVE-2013-0269]</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/11/7" source="MLIST">[oss-security] 20130211 Denial of Service and Unsafe Object Creation Vulnerability in JSON [CVE-2013-0269]</ref>
      <ref url="http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/" source="CONFIRM" adv="1">http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/</ref>
      <ref url="http://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed" source="CONFIRM">http://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed</ref>
      <ref url="http://secunia.com/advisories/52902" source="SECUNIA">52902</ref>
      <ref url="http://secunia.com/advisories/52774" source="SECUNIA">52774</ref>
      <ref url="http://secunia.com/advisories/52075" source="SECUNIA" adv="1">52075</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0701.html" source="REDHAT">RHSA-2013:0701</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0686.html" source="REDHAT">RHSA-2013:0686</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-04/msg00034.html" source="SUSE">openSUSE-SU-2013:0603</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00015.html" source="SUSE">SUSE-SU-2013:0647</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00001.html" source="SUSE">SUSE-SU-2013:0609</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2013-03/0104.html" source="SLACKWARE">SSA:2013-075-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rubygems" name="json_gem">
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6.6"/>
        <vers num="1.6.7"/>
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.4"/>
        <vers num="1.7.5"/>
        <vers num="1.7.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0270" published="2013-04-12" name="CVE-2013-0270" modified="2013-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenStack Keystone Grizzly before 2013.1, Folsom, and possibly earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a large HTTP request, as demonstrated by a long tenant_name when requesting a token.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://launchpad.net/keystone/grizzly/2013.1" source="CONFIRM" patch="1">https://launchpad.net/keystone/grizzly/2013.1</ref>
      <ref url="https://github.com/openstack/keystone/commit/82c87e5638ebaf9f166a9b07a0155291276d6fdc" source="CONFIRM">https://github.com/openstack/keystone/commit/82c87e5638ebaf9f166a9b07a0155291276d6fdc</ref>
      <ref url="https://github.com/openstack/keystone/commit/7691276b869a86c2b75631d5bede9f61e030d9d8" source="CONFIRM">https://github.com/openstack/keystone/commit/7691276b869a86c2b75631d5bede9f61e030d9d8</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=909012" source="MISC" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=909012</ref>
      <ref url="https://bugs.launchpad.net/keystone/+bug/1099025" source="CONFIRM">https://bugs.launchpad.net/keystone/+bug/1099025</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0708.html" source="REDHAT">RHSA-2013:0708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openstack" name="folsom">
        <vers prev="1" num="2012.1.3"/>
        <vers num="2012.2"/>
      </prod>
      <prod vendor="openstack" name="grizzly">
        <vers prev="1" num="2012.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0271" published="2013-02-16" name="CVE-2013-0271" modified="2013-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The MXit protocol plugin in libpurple in Pidgin before 2.10.7 might allow remote attackers to create or overwrite files via a crafted (1) mxit or (2) mxit/imagestrips pathname.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1746-1" source="UBUNTU">USN-1746-1</ref>
      <ref url="http://www.pidgin.im/news/security/?id=65" source="CONFIRM" adv="1">http://www.pidgin.im/news/security/?id=65</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00006.html" source="SUSE">openSUSE-SU-2013:0405</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00003.html" source="SUSE">SUSE-SU-2013:0388</ref>
      <ref url="http://hg.pidgin.im/pidgin/main/rev/a8aef1d340f2" source="CONFIRM">http://hg.pidgin.im/pidgin/main/rev/a8aef1d340f2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pidgin" name="pidgin">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.2"/>
        <vers num="2.10.3"/>
        <vers num="2.10.4"/>
        <vers num="2.10.5"/>
        <vers prev="1" num="2.10.6"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.10"/>
        <vers num="2.7.11"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
        <vers num="2.7.9"/>
        <vers num="2.8.0"/>
        <vers num="2.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0272" published="2013-02-16" name="CVE-2013-0272" modified="2013-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in http.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.7 allows remote servers to execute arbitrary code via a long HTTP header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1746-1" source="UBUNTU">USN-1746-1</ref>
      <ref url="http://www.pidgin.im/news/security/?id=66" source="CONFIRM" adv="1">http://www.pidgin.im/news/security/?id=66</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00007.html" source="SUSE">openSUSE-SU-2013:0407</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00006.html" source="SUSE">openSUSE-SU-2013:0405</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00003.html" source="SUSE">SUSE-SU-2013:0388</ref>
      <ref url="http://hg.pidgin.im/pidgin/main/rev/879db2a9a59c" source="CONFIRM">http://hg.pidgin.im/pidgin/main/rev/879db2a9a59c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pidgin" name="pidgin">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.2"/>
        <vers num="2.10.3"/>
        <vers num="2.10.4"/>
        <vers num="2.10.5"/>
        <vers prev="1" num="2.10.6"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.10"/>
        <vers num="2.7.11"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
        <vers num="2.7.9"/>
        <vers num="2.8.0"/>
        <vers num="2.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0273" published="2013-02-16" name="CVE-2013-0273" modified="2013-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">sametime.c in the Sametime protocol plugin in libpurple in Pidgin before 2.10.7 does not properly terminate long user IDs, which allows remote servers to cause a denial of service (application crash) via a crafted packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1746-1" source="UBUNTU">USN-1746-1</ref>
      <ref url="http://www.pidgin.im/news/security/?id=67" source="CONFIRM" adv="1">http://www.pidgin.im/news/security/?id=67</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00007.html" source="SUSE">openSUSE-SU-2013:0407</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00006.html" source="SUSE">openSUSE-SU-2013:0405</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00003.html" source="SUSE">SUSE-SU-2013:0388</ref>
      <ref url="http://hg.pidgin.im/pidgin/main/rev/c31cf8de31cd" source="CONFIRM">http://hg.pidgin.im/pidgin/main/rev/c31cf8de31cd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pidgin" name="pidgin">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.2"/>
        <vers num="2.10.3"/>
        <vers num="2.10.4"/>
        <vers num="2.10.5"/>
        <vers prev="1" num="2.10.6"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.10"/>
        <vers num="2.7.11"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
        <vers num="2.7.9"/>
        <vers num="2.8.0"/>
        <vers num="2.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0274" published="2013-02-16" name="CVE-2013-0274" modified="2013-03-22" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="2.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="5.5" CVSS_base_score="2.9">
    <desc>
      <descript source="cve">upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1746-1" source="UBUNTU">USN-1746-1</ref>
      <ref url="http://www.pidgin.im/news/security/?id=68" source="CONFIRM" adv="1">http://www.pidgin.im/news/security/?id=68</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00007.html" source="SUSE">openSUSE-SU-2013:0407</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00006.html" source="SUSE">openSUSE-SU-2013:0405</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00003.html" source="SUSE">SUSE-SU-2013:0388</ref>
      <ref url="http://hg.pidgin.im/pidgin/main/rev/ad7e7fb98db3" source="CONFIRM">http://hg.pidgin.im/pidgin/main/rev/ad7e7fb98db3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pidgin" name="pidgin">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.10.0"/>
        <vers num="2.10.1"/>
        <vers num="2.10.2"/>
        <vers num="2.10.3"/>
        <vers num="2.10.4"/>
        <vers num="2.10.5"/>
        <vers prev="1" num="2.10.6"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.5.0"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.5.3"/>
        <vers num="2.5.4"/>
        <vers num="2.5.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.5.9"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.10"/>
        <vers num="2.7.11"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
        <vers num="2.7.9"/>
        <vers num="2.8.0"/>
        <vers num="2.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0275" published="2013-03-13" name="CVE-2013-0275" modified="2013-03-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ganglia Web before 3.5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://github.com/ganglia/ganglia-web/commit/31d348947419058c43b8dfcd062e2988abd5058e" source="CONFIRM" patch="1">https://github.com/ganglia/ganglia-web/commit/31d348947419058c43b8dfcd062e2988abd5058e</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=892823" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=892823</ref>
      <ref url="http://www.securityfocus.com/bid/58204" source="BID">58204</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/08/6" source="MLIST">[oss-security] 20130208 Re: CVE request: XSS flaws fixed in ganglia</ref>
      <ref url="http://ganglia.info/?p=566" source="CONFIRM" adv="1">http://ganglia.info/?p=566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ganglia" name="ganglia-web">
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.2.0"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.5.0"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers prev="1" num="3.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0276" published="2013-02-12" name="CVE-2013-0276" modified="2013-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/11/5" source="MLIST" patch="1">[oss-security] 20130211 Circumvention of attr_protected [CVE-2013-0276]</ref>
      <ref url="https://groups.google.com/group/rubyonrails-security/msg/bb44b98a73ef1a06?dmode=source&amp;output=gplain" source="MLIST">[rubyonrails-security] 20130211 Circumvention of attr_protected [CVE-2013-0276]</ref>
      <ref url="http://www.securityfocus.com/bid/57896" source="BID">57896</ref>
      <ref url="http://www.osvdb.org/90072" source="OSVDB">90072</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2620" source="DEBIAN">DSA-2620</ref>
      <ref url="http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/" source="CONFIRM" adv="1">http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/</ref>
      <ref url="http://support.apple.com/kb/HT5784" source="CONFIRM">http://support.apple.com/kb/HT5784</ref>
      <ref url="http://secunia.com/advisories/52774" source="SECUNIA">52774</ref>
      <ref url="http://secunia.com/advisories/52112" source="SECUNIA">52112</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0686.html" source="REDHAT">RHSA-2013:0686</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html" source="SUSE">openSUSE-SU-2013:0462</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html" source="APPLE">APPLE-SA-2013-06-04-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rubyonrails" name="ruby_on_rails">
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.3.15"/>
        <vers num="2.3.16"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.9"/>
        <vers num="3.1.0" edition="beta1"/>
        <vers num="3.1.0" edition="rc1"/>
        <vers num="3.1.0" edition="rc2"/>
        <vers num="3.1.0" edition="rc3"/>
        <vers num="3.1.0" edition="rc4"/>
        <vers num="3.1.0" edition="rc5"/>
        <vers num="3.1.0" edition="rc6"/>
        <vers num="3.1.0" edition="rc7"/>
        <vers num="3.1.0" edition="rc8"/>
        <vers num="3.1.1" edition="rc1"/>
        <vers num="3.1.1" edition="rc2"/>
        <vers num="3.1.1" edition="rc3"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2" edition="rc1"/>
        <vers num="3.1.2" edition="rc2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4" edition="rc1"/>
        <vers num="3.1.5" edition="rc1"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2.0" edition="rc1"/>
        <vers num="3.2.0" edition="rc2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.2" edition="rc1"/>
        <vers num="3.2.3" edition="rc1"/>
        <vers num="3.2.3" edition="rc2"/>
        <vers num="3.2.4" edition="rc1"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0277" published="2013-02-12" name="CVE-2013-0277" modified="2013-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/11/6" source="MLIST" patch="1">[oss-security] 20130211 Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]</ref>
      <ref url="https://groups.google.com/group/rubyonrails-security/msg/302ec7ce90f13837?dmode=source&amp;output=gplain" source="MLIST">[rubyonrails-security] 20130211 Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]</ref>
      <ref url="http://www.osvdb.org/90073" source="OSVDB">90073</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2620" source="DEBIAN">DSA-2620</ref>
      <ref url="http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/" source="CONFIRM">http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/</ref>
      <ref url="http://support.apple.com/kb/HT5784" source="CONFIRM">http://support.apple.com/kb/HT5784</ref>
      <ref url="http://securitytracker.com/id?1028109" source="SECTRACK">1028109</ref>
      <ref url="http://secunia.com/advisories/52112" source="SECUNIA">52112</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html" source="SUSE">openSUSE-SU-2013:0462</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html" source="APPLE">APPLE-SA-2013-06-04-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rubyonrails" name="ruby_on_rails">
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.3.15"/>
        <vers num="2.3.16"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.9"/>
        <vers num="3.0.0" edition="beta"/>
        <vers num="3.0.0" edition="beta2"/>
        <vers num="3.0.0" edition="beta3"/>
        <vers num="3.0.0" edition="beta4"/>
        <vers num="3.0.0" edition="rc"/>
        <vers num="3.0.0" edition="rc2"/>
        <vers num="3.0.1" edition="pre"/>
        <vers num="3.0.10" edition="rc1"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12" edition="rc1"/>
        <vers num="3.0.13" edition="rc1"/>
        <vers num="3.0.14"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2" edition="pre"/>
        <vers num="3.0.20"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4" edition="rc"/>
        <vers num="3.0.4" edition="rc1"/>
        <vers num="3.0.5" edition="rc1"/>
        <vers num="3.0.6" edition="rc1"/>
        <vers num="3.0.6" edition="rc2"/>
        <vers num="3.0.7" edition="rc1"/>
        <vers num="3.0.7" edition="rc2"/>
        <vers num="3.0.8" edition="rc1"/>
        <vers num="3.0.8" edition="rc2"/>
        <vers num="3.0.8" edition="rc3"/>
        <vers num="3.0.8" edition="rc4"/>
        <vers num="3.0.9" edition="rc1"/>
        <vers num="3.0.9" edition="rc2"/>
        <vers num="3.0.9" edition="rc3"/>
        <vers num="3.0.9" edition="rc4"/>
        <vers num="3.0.9" edition="rc5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2013-0278" reject="1" published="2013-04-02" name="CVE-2013-0278" modified="2013-04-02">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-1664, CVE-2013-1665. Reason: This candidate is a duplicate of CVE-2013-1664 and/or CVE-2013-1665. Notes: All CVE users should reference CVE-2013-1664 and/or CVE-2013-1665 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" seq="2013-0279" reject="1" published="2013-04-02" name="CVE-2013-0279" modified="2013-04-02">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-1664, CVE-2013-1665. Reason: This candidate is a duplicate of CVE-2013-1664 and/or CVE-2013-1665. Notes: All CVE users should reference CVE-2013-1664 and/or CVE-2013-1665 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" seq="2013-0280" reject="1" published="2013-04-02" name="CVE-2013-0280" modified="2013-04-02">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-1664, CVE-2013-1665. Reason: This candidate is a duplicate of CVE-2013-1664 and/or CVE-2013-1665. Notes: All CVE users should reference CVE-2013-1664 and/or CVE-2013-1665 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0282" published="2013-04-12" name="CVE-2013-0282" modified="2013-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://review.openstack.org/#/c/22321/" source="CONFIRM">https://review.openstack.org/#/c/22321/</ref>
      <ref url="https://review.openstack.org/#/c/22320/" source="CONFIRM">https://review.openstack.org/#/c/22320/</ref>
      <ref url="https://review.openstack.org/#/c/22319/" source="CONFIRM">https://review.openstack.org/#/c/22319/</ref>
      <ref url="https://launchpad.net/keystone/grizzly/2013.1" source="CONFIRM">https://launchpad.net/keystone/grizzly/2013.1</ref>
      <ref url="https://launchpad.net/keystone/+milestone/2012.2.4" source="CONFIRM">https://launchpad.net/keystone/+milestone/2012.2.4</ref>
      <ref url="https://bugs.launchpad.net/keystone/+bug/1121494" source="CONFIRM">https://bugs.launchpad.net/keystone/+bug/1121494</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/19/3" source="MLIST">[oss-security] 20130219 [OSSA 2013-005] Keystone EC2-style authentication accepts disabled user/tenants (CVE-2013-0282)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openstack" name="essex">
        <vers num="-"/>
      </prod>
      <prod vendor="openstack" name="folsom">
        <vers prev="1" num="2012.1.3"/>
        <vers num="2012.2"/>
      </prod>
      <prod vendor="openstack" name="grizzly">
        <vers prev="1" num="2012.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0284" published="2013-04-09" name="CVE-2013-0284" modified="2013-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ruby agent 3.2.0 through 3.5.2 serializes sensitive data when communicating with servers operated by New Relic, which allows remote attackers to obtain sensitive information (database credentials and SQL statements) by sniffing the network and deserializing the data.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://newrelic.com/docs/ruby/ruby-agent-security-notification" source="CONFIRM" adv="1">https://newrelic.com/docs/ruby/ruby-agent-security-notification</ref>
      <ref url="http://seclists.org/oss-sec/2013/q1/304" source="MLIST">[oss-security] 20130213 Some rubygems related CVEs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newrelic" name="ruby_agent">
        <vers num="3.2.0"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.2.1"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.4.1"/>
        <vers num="3.3.5"/>
        <vers num="3.4.0"/>
        <vers num="3.4.0.1"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.2.1"/>
        <vers num="3.5.0"/>
        <vers num="3.5.0.1"/>
        <vers num="3.5.1"/>
        <vers num="3.5.1.14"/>
        <vers num="3.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0285" published="2013-04-09" name="CVE-2013-0285" modified="2013-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://support.cloud.engineyard.com/entries/22915701-january-14-2013-security-vulnerabilities-httparty-extlib-crack-nori-update-these-gems-immediately" source="MISC">https://support.cloud.engineyard.com/entries/22915701-january-14-2013-security-vulnerabilities-httparty-extlib-crack-nori-update-these-gems-immediately</ref>
      <ref url="http://seclists.org/oss-sec/2013/q1/304" source="MLIST">[oss-security] 20130213 Some rubygems related CVEs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nori_gem_project" name="nori_gem">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0287" published="2013-03-21" name="CVE-2013-0287" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)" CVSS_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/patch/?id=c0bca1722d6f9dfb654ad78397be70f79ff39af1" source="CONFIRM" patch="1">http://git.fedorahosted.org/cgit/sssd.git/patch/?id=c0bca1722d6f9dfb654ad78397be70f79ff39af1</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/patch/?id=b63830b142053f99bfe954d4be5a2b0f68ce3a93" source="CONFIRM" patch="1">http://git.fedorahosted.org/cgit/sssd.git/patch/?id=b63830b142053f99bfe954d4be5a2b0f68ce3a93</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/patch/?id=8b8019fe3dd1564fba657e219ec20ff816c7ffdb" source="CONFIRM" patch="1">http://git.fedorahosted.org/cgit/sssd.git/patch/?id=8b8019fe3dd1564fba657e219ec20ff816c7ffdb</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/patch/?id=7619be9f6bf649665fcbeee9e6b120f9f9cba2a5" source="CONFIRM" patch="1">http://git.fedorahosted.org/cgit/sssd.git/patch/?id=7619be9f6bf649665fcbeee9e6b120f9f9cba2a5</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/patch/?id=754b09b5444e6da88ed58d6deaed8b815e268b6b" source="CONFIRM" patch="1">http://git.fedorahosted.org/cgit/sssd.git/patch/?id=754b09b5444e6da88ed58d6deaed8b815e268b6b</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/patch/?id=6837eee3f7f81c0ee454d3718d67d7f3cc6b48ef" source="CONFIRM" patch="1">http://git.fedorahosted.org/cgit/sssd.git/patch/?id=6837eee3f7f81c0ee454d3718d67d7f3cc6b48ef</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/patch/?id=6569d57e3bc168e6e83d70333b48c5cb43aa04c4" source="CONFIRM" patch="1">http://git.fedorahosted.org/cgit/sssd.git/patch/?id=6569d57e3bc168e6e83d70333b48c5cb43aa04c4</ref>
      <ref url="http://git.fedorahosted.org/cgit/sssd.git/patch/?id=26590d31f492dbbd36be6d0bde46a4bd3b221edb" source="CONFIRM" patch="1">http://git.fedorahosted.org/cgit/sssd.git/patch/?id=26590d31f492dbbd36be6d0bde46a4bd3b221edb</ref>
      <ref url="https://lists.fedorahosted.org/pipermail/sssd-devel/2013-March/014066.html" source="MLIST">[sssd-devel] 20130319 [SSSD] A security bug in SSSD 1.9 (CVE-2013-0287)</ref>
      <ref url="http://www.securityfocus.com/bid/58593" source="BID">58593</ref>
      <ref url="http://securitytracker.com/id?1028317" source="SECTRACK">1028317</ref>
      <ref url="http://secunia.com/advisories/52722" source="SECUNIA" adv="1">52722</ref>
      <ref url="http://secunia.com/advisories/52704" source="SECUNIA" adv="1">52704</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0663.html" source="REDHAT">RHSA-2013:0663</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00115.html" source="SUSE">openSUSE-SU-2013:0559</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=910938" source="MISC">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=910938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fedoraproject" name="sssd">
        <vers num="1.9.0"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0288" published="2013-03-05" name="CVE-2013-0288" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0288" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0288</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/82175" source="XF">nsspamldapd-fdsetsize-bo(82175)</ref>
      <ref url="http://www.securityfocus.com/bid/58007" source="BID">58007</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/18/2" source="MLIST">[oss-security] 20130218 CVE-2013-0288 nss-pam-ldapd: FD_SET array index error, leading to stack-based buffer overflow</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2628" source="DEBIAN">DSA-2628</ref>
      <ref url="http://secunia.com/advisories/52242" source="SECUNIA" adv="1">52242</ref>
      <ref url="http://secunia.com/advisories/52212" source="SECUNIA">52212</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0590.html" source="REDHAT">RHSA-2013:0590</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00091.html" source="SUSE">openSUSE-SU-2013:0524</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00087.html" source="SUSE">openSUSE-SU-2013:0522</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2013-February/099438.html" source="FEDORA">FEDORA-2013-2754</ref>
      <ref url="http://lists.arthurdejong.org/nss-pam-ldapd-announce/2013/msg00001.html" source="MLIST">[nss-pam-ldapd-announce] 20130218 nss-pam-ldapd security advisory (CVE-2013-0288)</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=690319" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=690319</ref>
      <ref url="http://arthurdejong.org/git/nss-pam-ldapd/commit/?id=f266f05f20afe73e89c3946a7bd60bd7c5948e1b" source="CONFIRM">http://arthurdejong.org/git/nss-pam-ldapd/commit/?id=f266f05f20afe73e89c3946a7bd60bd7c5948e1b</ref>
      <ref url="http://arthurdejong.org/git/nss-pam-ldapd/commit/?id=abf03bc54032beeff95b1b8634cc005137e11f32" source="CONFIRM">http://arthurdejong.org/git/nss-pam-ldapd/commit/?id=abf03bc54032beeff95b1b8634cc005137e11f32</ref>
      <ref url="http://arthurdejong.org/git/nss-pam-ldapd/commit/?id=7867b93f9a7c76b96f1571cddc1de0811134bb81" source="CONFIRM">http://arthurdejong.org/git/nss-pam-ldapd/commit/?id=7867b93f9a7c76b96f1571cddc1de0811134bb81</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arthurdejong" name="nss-pam-ldapd">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.2.1"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.4.1"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.0"/>
        <vers num="0.6.1"/>
        <vers num="0.6.10"/>
        <vers num="0.6.11"/>
        <vers num="0.6.12"/>
        <vers num="0.6.2"/>
        <vers num="0.6.3"/>
        <vers num="0.6.4"/>
        <vers num="0.6.5"/>
        <vers num="0.6.6"/>
        <vers num="0.6.7"/>
        <vers num="0.6.7.1"/>
        <vers num="0.6.7.2"/>
        <vers num="0.6.8"/>
        <vers num="0.6.9"/>
        <vers num="0.7.0"/>
        <vers num="0.7.1"/>
        <vers num="0.7.10"/>
        <vers num="0.7.11"/>
        <vers num="0.7.12"/>
        <vers num="0.7.13"/>
        <vers num="0.7.14"/>
        <vers num="0.7.15"/>
        <vers num="0.7.16"/>
        <vers prev="1" num="0.7.17"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.7.4"/>
        <vers num="0.7.5"/>
        <vers num="0.7.6"/>
        <vers num="0.7.7"/>
        <vers num="0.7.8"/>
        <vers num="0.7.9"/>
        <vers num="0.8.0"/>
        <vers num="0.8.1"/>
        <vers num="0.8.10"/>
        <vers num="0.8.2"/>
        <vers num="0.8.3"/>
        <vers num="0.8.4"/>
        <vers num="0.8.5"/>
        <vers num="0.8.6"/>
        <vers num="0.8.7"/>
        <vers num="0.8.8"/>
        <vers num="0.8.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0290" published="2013-02-19" name="CVE-2013-0290" modified="2013-02-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The __skb_recv_datagram function in net/core/datagram.c in the Linux kernel before 3.8 does not properly handle the MSG_PEEK flag with zero-length data, which allows local users to cause a denial of service (infinite loop and system hang) via a crafted application.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/77c1090f94d1b0b5186fb13a1b71b47b1343f87f" source="CONFIRM" patch="1">https://github.com/torvalds/linux/commit/77c1090f94d1b0b5186fb13a1b71b47b1343f87f</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/patch-3.8.bz2" source="CONFIRM" patch="1">http://www.kernel.org/pub/linux/kernel/v3.x/patch-3.8.bz2</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=911473" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=911473</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/15/2" source="MLIST">[oss-security] 20130214 Re: CVE Request: kernel -- local DOS (endless loop with interrupts disabled)</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=77c1090f94d1b0b5186fb13a1b71b47b1343f87f" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=77c1090f94d1b0b5186fb13a1b71b47b1343f87f</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers prev="1" num="3.7.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0292" published="2013-03-05" name="CVE-2013-0292" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://cgit.freedesktop.org/dbus/dbus-glib/commit/?id=166978a09cf5edff4028e670b6074215a4c75eca" source="CONFIRM" patch="1">http://cgit.freedesktop.org/dbus/dbus-glib/commit/?id=166978a09cf5edff4028e670b6074215a4c75eca</ref>
      <ref url="https://bugs.freedesktop.org/show_bug.cgi?id=60916" source="CONFIRM">https://bugs.freedesktop.org/show_bug.cgi?id=60916</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/82135" source="XF">dbus-message-sender-priv-esc(82135)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1753-1" source="UBUNTU">USN-1753-1</ref>
      <ref url="http://www.securityfocus.com/bid/57985" source="BID">57985</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/15/10" source="MLIST">[oss-security] 20130215 CVE-2013-0292: authentication bypass due to insufficient checks in  dbus-glib &lt; 0.100.1</ref>
      <ref url="http://secunia.com/advisories/52404" source="SECUNIA" adv="1">52404</ref>
      <ref url="http://secunia.com/advisories/52375" source="SECUNIA">52375</ref>
      <ref url="http://secunia.com/advisories/52225" source="SECUNIA" adv="1">52225</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0568.html" source="REDHAT">RHSA-2013:0568</ref>
      <ref url="http://osvdb.org/90302" source="OSVDB">90302</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=911658" source="MISC">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=911658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freedesktop" name="dbus-glib">
        <vers prev="1" num="0.100"/>
        <vers num="0.72"/>
        <vers num="0.73"/>
        <vers num="0.74"/>
        <vers num="0.76"/>
        <vers num="0.78"/>
        <vers num="0.80"/>
        <vers num="0.82"/>
        <vers num="0.84"/>
        <vers num="0.86"/>
        <vers num="0.88"/>
        <vers num="0.90"/>
        <vers num="0.92"/>
        <vers num="0.94"/>
        <vers num="0.96"/>
        <vers num="0.98"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0305" published="2013-05-02" name="CVE-2013-0305" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://www.ubuntu.com/usn/usn-1757-1/
"A security issue affects these releases of Ubuntu and its derivatives:

    Ubuntu 12.10
    Ubuntu 12.04 LTS
    Ubuntu 11.10
    Ubuntu 10.04 LTS"</impact>
    </impacts>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.djangoproject.com/weblog/2013/feb/19/security/" source="CONFIRM" patch="1" adv="1">https://www.djangoproject.com/weblog/2013/feb/19/security/</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2634" source="DEBIAN">DSA-2634</ref>
      <ref url="http://ubuntu.com/usn/usn-1757-1" source="UBUNTU">USN-1757-1</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0670.html" source="REDHAT">RHSA-2013:0670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="djangoproject" name="django">
        <vers num="1.3" edition="alpha1"/>
        <vers num="1.3" edition="beta1"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.4" edition="alpha"/>
        <vers num="1.4" edition="beta"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.5" edition="alpha"/>
        <vers num="1.5" edition="beta"/>
      </prod>
      <prod vendor="canonical" name="ubuntu_linux">
        <vers num="10.04" edition="-"/>
        <vers num="10.04" edition="-:lts"/>
        <vers num="11.10"/>
        <vers num="12.04" edition="-"/>
        <vers num="12.04" edition="-:lts"/>
        <vers num="12.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0306" published="2013-05-02" name="CVE-2013-0306" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.djangoproject.com/weblog/2013/feb/19/security/" source="CONFIRM" adv="1">https://www.djangoproject.com/weblog/2013/feb/19/security/</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2634" source="DEBIAN">DSA-2634</ref>
      <ref url="http://ubuntu.com/usn/usn-1757-1" source="UBUNTU">USN-1757-1</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0670.html" source="REDHAT">RHSA-2013:0670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="djangoproject" name="django">
        <vers num="1.3" edition="alpha1"/>
        <vers num="1.3" edition="beta1"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.4" edition="alpha"/>
        <vers num="1.4" edition="beta"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.5" edition="alpha"/>
        <vers num="1.5" edition="beta"/>
      </prod>
      <prod vendor="canonical" name="ubuntu_linux">
        <vers num="10.04" edition="-"/>
        <vers num="10.04" edition="-:lts"/>
        <vers num="11.10"/>
        <vers num="12.04" edition="-"/>
        <vers num="12.04" edition="-:lts"/>
        <vers num="12.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0308" published="2013-03-08" name="CVE-2013-0308" modified="2013-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://raw.github.com/git/git/master/Documentation/RelNotes/1.8.1.4.txt" source="CONFIRM">https://raw.github.com/git/git/master/Documentation/RelNotes/1.8.1.4.txt</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=909977" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=909977</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=804730" source="MISC">https://bugzilla.novell.com/show_bug.cgi?id=804730</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/82329" source="XF">git-gitimapsend-spoofing(82329)</ref>
      <ref url="http://www.securitytracker.com/id/1028205" source="SECTRACK">1028205</ref>
      <ref url="http://www.securityfocus.com/bid/58148" source="BID">58148</ref>
      <ref url="http://secunia.com/advisories/52467" source="SECUNIA" adv="1">52467</ref>
      <ref url="http://secunia.com/advisories/52443" source="SECUNIA" adv="1">52443</ref>
      <ref url="http://secunia.com/advisories/52361" source="SECUNIA" adv="1">52361</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0589.html" source="REDHAT">RHSA-2013:0589</ref>
      <ref url="http://marc.info/?l=git&amp;m=136134619013145&amp;w=2" source="MLIST">[ANNOUNCE] 20130220 Git v1.8.1.4</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00007.html" source="SUSE">openSUSE-SU-2013:0382</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00005.html" source="SUSE">openSUSE-SU-2013:0380</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=701586" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=701586</ref>
    </refs>
    <vuln_soft>
      <prod vendor="git" name="git">
        <vers prev="1" num="1.8.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0309" published="2013-02-21" name="CVE-2013-0309" modified="2013-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">arch/x86/include/asm/pgtable.h in the Linux kernel before 3.6.2, when transparent huge pages are used, does not properly support PROT_NONE memory regions, which allows local users to cause a denial of service (system crash) via a crafted application.</descript>
      <descript source="nvd">Per https://access.redhat.com/security/cve/CVE-2013-0309 "This issue did affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 6."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/027ef6c87853b0a9df53175063028edb4950d476" source="CONFIRM">https://github.com/torvalds/linux/commit/027ef6c87853b0a9df53175063028edb4950d476</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=912898" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=912898</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/20/4" source="MLIST">[oss-security] 20130219 Re: CVE request -- Linux kernel: mm: thp: pmd_present and PROT_NONE local DoS</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.6.2" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.6.2</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0496.html" source="REDHAT">RHSA-2013:0496</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=027ef6c87853b0a9df53175063028edb4950d476" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=027ef6c87853b0a9df53175063028edb4950d476</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition=""/>
        <vers num="3.2" edition=":~~~~x86~"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1" edition=""/>
        <vers num="3.2.1" edition=":~~~~x86~"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition=""/>
        <vers num="3.4" edition=":~~~~x86~"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc1:~~~~x86~"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc2:~~~~x86~"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc3:~~~~x86~"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc4:~~~~x86~"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc5:~~~~x86~"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc6:~~~~x86~"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4" edition="rc7:~~~~x86~"/>
        <vers num="3.4.1" edition=""/>
        <vers num="3.4.1" edition=":~~~~x86~"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2" edition=""/>
        <vers num="3.4.2" edition=":~~~~x86~"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3" edition=""/>
        <vers num="3.4.3" edition=":~~~~x86~"/>
        <vers num="3.4.4" edition=""/>
        <vers num="3.4.4" edition=":~~~~x86~"/>
        <vers num="3.4.5" edition=""/>
        <vers num="3.4.5" edition=":~~~~x86~"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6"/>
        <vers prev="1" num="3.6.1"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0310" published="2013-02-21" name="CVE-2013-0310" modified="2013-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call.</descript>
      <descript source="nvd">Per https://access.redhat.com/security/cve/CVE-2013-0310
"This issue did affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 6."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/89d7ae34cdda4195809a5a987f697a517a2a3177" source="CONFIRM">https://github.com/torvalds/linux/commit/89d7ae34cdda4195809a5a987f697a517a2a3177</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=912900" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=912900</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/20/5" source="MLIST">[oss-security] 20130219 Re: CVE request -- Linux kernel: net: CIPSO_V4_TAG_LOCAL tag NULL pointer dereference</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.8" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.8</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0496.html" source="REDHAT">RHSA-2013:0496</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=89d7ae34cdda4195809a5a987f697a517a2a3177" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=89d7ae34cdda4195809a5a987f697a517a2a3177</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers prev="1" num="3.4.7"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0311" published="2013-02-21" name="CVE-2013-0311" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:A/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="6.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.5" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The translate_desc function in drivers/vhost/vhost.c in the Linux kernel before 3.7 does not properly handle cross-region descriptors, which allows guest OS users to obtain host OS privileges by leveraging KVM guest OS privileges.</descript>
      <descript source="nvd">Per https://access.redhat.com/security/cve/CVE-2013-0311
"This issue did affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 6."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/patch-3.7.bz2" source="CONFIRM" patch="1">http://www.kernel.org/pub/linux/kernel/v3.x/patch-3.7.bz2</ref>
      <ref url="https://github.com/torvalds/linux/commit/bd97120fc3d1a11f3124c7c9ba1d91f51829eb85" source="CONFIRM">https://github.com/torvalds/linux/commit/bd97120fc3d1a11f3124c7c9ba1d91f51829eb85</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=912905" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=912905</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/20/6" source="MLIST">[oss-security] 20130219 Re: CVE request -- Linux kernel: vhost: fix length for cross region descriptor</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0882.html" source="REDHAT">RHSA-2013:0882</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0579.html" source="REDHAT">RHSA-2013:0579</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0496.html" source="REDHAT">RHSA-2013:0496</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=bd97120fc3d1a11f3124c7c9ba1d91f51829eb85" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=bd97120fc3d1a11f3124c7c9ba1d91f51829eb85</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6.10"/>
        <vers prev="1" num="3.6.11"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0312" published="2013-03-13" name="CVE-2013-0312" modified="2013-03-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://fedorahosted.org/389/ticket/571" source="MISC">https://fedorahosted.org/389/ticket/571</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=912964" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=912964</ref>
      <ref url="http://www.securityfocus.com/bid/58428" source="BID">58428</ref>
      <ref url="http://secunia.com/advisories/52568" source="SECUNIA" adv="1">52568</ref>
      <ref url="http://secunia.com/advisories/52279" source="SECUNIA" adv="1">52279</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0628.html" source="REDHAT">RHSA-2013:0628</ref>
      <ref url="http://directory.fedoraproject.org/wiki/Releases/1.3.0.4" source="CONFIRM">http://directory.fedoraproject.org/wiki/Releases/1.3.0.4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fedoraproject" name="389_directory_server">
        <vers prev="1" num="1.3.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0313" published="2013-02-21" name="CVE-2013-0313" modified="2013-02-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">The evm_update_evmxattr function in security/integrity/evm/evm_crypto.c in the Linux kernel before 3.7.5, when the Extended Verification Module (EVM) is enabled, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an attempted removexattr operation on an inode of a sockfs filesystem.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/a67adb997419fb53540d4a4f79c6471c60bc69b6" source="CONFIRM">https://github.com/torvalds/linux/commit/a67adb997419fb53540d4a4f79c6471c60bc69b6</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=913266" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=913266</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/20/16" source="MLIST">[oss-security] 20130220 Re: CVE request - Linux kernel: evm: NULL pointer de-reference flaw</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.5" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.5</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a67adb997419fb53540d4a4f79c6471c60bc69b6" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a67adb997419fb53540d4a4f79c6471c60bc69b6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers prev="1" num="3.7.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0314" published="2013-04-12" name="CVE-2013-0314" modified="2013-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, which allows remote attackers to modify site contents, remove the site, or alter the access controls for portlets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=913327" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=913327</ref>
      <ref url="http://www.osvdb.org/91120" source="OSVDB">91120</ref>
      <ref url="http://secunia.com/advisories/52552" source="SECUNIA" adv="1">52552</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0613.html" source="REDHAT" adv="1">RHSA-2013:0613</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="jboss_enterprise_portal_platform">
        <vers num="5.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0315" published="2013-04-12" name="CVE-2013-0315" modified="2013-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted external XML entity in an XML document, aka an XML Entity Expansion (XEE) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=913340" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=913340</ref>
      <ref url="http://www.osvdb.org/91121" source="OSVDB">91121</ref>
      <ref url="http://secunia.com/advisories/52552" source="SECUNIA" adv="1">52552</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0613.html" source="REDHAT" adv="1">RHSA-2013:0613</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="jboss_enterprise_portal_platform">
        <vers num="5.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0316" published="2013-03-27" name="CVE-2013-0316" modified="2013-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Image module in Drupal 7.x before 7.20 allows remote attackers to cause a denial of service (CPU and disk space consumption) via a large number of new derivative requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://drupal.org/SA-CORE-2013-002" source="CONFIRM" patch="1" adv="1">http://drupal.org/SA-CORE-2013-002</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/5" source="MLIST">[oss-security] 20130220 Re: CVE request for Drupal Core and contributed modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="7.0" edition="alpha1"/>
        <vers num="7.0" edition="alpha2"/>
        <vers num="7.0" edition="alpha3"/>
        <vers num="7.0" edition="alpha4"/>
        <vers num="7.0" edition="alpha5"/>
        <vers num="7.0" edition="alpha6"/>
        <vers num="7.0" edition="alpha7"/>
        <vers num="7.0" edition="beta1"/>
        <vers num="7.0" edition="beta2"/>
        <vers num="7.0" edition="beta3"/>
        <vers num="7.0" edition="dev"/>
        <vers num="7.0" edition="rc1"/>
        <vers num="7.0" edition="rc2"/>
        <vers num="7.0" edition="rc3"/>
        <vers num="7.0" edition="rc4"/>
        <vers num="7.1"/>
        <vers num="7.10"/>
        <vers num="7.11"/>
        <vers num="7.12"/>
        <vers num="7.13"/>
        <vers num="7.14"/>
        <vers num="7.15"/>
        <vers num="7.16"/>
        <vers num="7.17"/>
        <vers num="7.18"/>
        <vers num="7.19"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="7.4"/>
        <vers num="7.5"/>
        <vers num="7.6"/>
        <vers num="7.7"/>
        <vers num="7.8"/>
        <vers num="7.9"/>
        <vers num="7.x-dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0317" published="2013-03-27" name="CVE-2013-0317" modified="2013-04-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Manager Change for Organic Groups (og_manager_change) module 7.x-2.x before 7.x-2.1 for Drupal might allow remote attackers to inject arbitrary web script or HTML via the username in the new manager autocomplete field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://drupalcode.org/project/og_manager_change.git/commitdiff/ab7152b" source="CONFIRM" patch="1">http://drupalcode.org/project/og_manager_change.git/commitdiff/ab7152b</ref>
      <ref url="http://drupal.org/node/1916312" source="MISC" patch="1" adv="1">http://drupal.org/node/1916312</ref>
      <ref url="http://drupal.org/node/1915408" source="CONFIRM" patch="1">http://drupal.org/node/1915408</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/5" source="MLIST">[oss-security] 20130220 Re: CVE request for Drupal Core and contributed modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joe_haskins" name="og_manager_change">
        <vers num="7.x-2.0" edition="beta1"/>
        <vers num="7.x-2.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0318" published="2013-03-27" name="CVE-2013-0318" modified="2013-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended restrictions via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/5" source="MLIST">[oss-security] 20130220 Re: CVE request for Drupal Core and contributed modules</ref>
      <ref url="http://drupal.org/node/1916370" source="MISC" adv="1">http://drupal.org/node/1916370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="banckle_chat_project" name="banckle_chat">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0319" published="2013-03-27" name="CVE-2013-0319" modified="2013-04-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Yandex.Metrics module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the Yandex.Metrica service data.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://drupalcode.org/project/yandex_metrics.git/commitdiff/80bb901" source="CONFIRM" patch="1">http://drupalcode.org/project/yandex_metrics.git/commitdiff/80bb901</ref>
      <ref url="http://drupalcode.org/project/yandex_metrics.git/commitdiff/290b718" source="CONFIRM" patch="1">http://drupalcode.org/project/yandex_metrics.git/commitdiff/290b718</ref>
      <ref url="http://drupal.org/node/1922400" source="MISC" patch="1" adv="1">http://drupal.org/node/1922400</ref>
      <ref url="http://drupal.org/node/1921342" source="CONFIRM" patch="1">http://drupal.org/node/1921342</ref>
      <ref url="http://drupal.org/node/1921340" source="CONFIRM" patch="1">http://drupal.org/node/1921340</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/5" source="MLIST">[oss-security] 20130220 Re: CVE request for Drupal Core and contributed modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yandex.metrics_project" name="yandex_metrics">
        <vers num="6.x-1.0"/>
        <vers num="6.x-1.1"/>
        <vers num="6.x-1.2"/>
        <vers num="6.x-1.3"/>
        <vers num="6.x-1.4"/>
        <vers num="6.x-1.5"/>
        <vers num="6.x-1.x" edition="dev"/>
        <vers num="7.x-1.0"/>
        <vers num="7.x-1.1"/>
        <vers num="7.x-1.2"/>
        <vers num="7.x-1.3"/>
        <vers num="7.x-1.4"/>
        <vers num="7.x-1.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0320" published="2013-03-27" name="CVE-2013-0320" modified="2013-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the authentication of users with 'administer taxonomy' permissions via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://drupal.org/node/1922410" source="MISC" patch="1" adv="1">http://drupal.org/node/1922410</ref>
      <ref url="http://drupal.org/node/1922170" source="CONFIRM" patch="1">http://drupal.org/node/1922170</ref>
      <ref url="http://drupal.org/node/1922168" source="CONFIRM" patch="1">http://drupal.org/node/1922168</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/5" source="MLIST">[oss-security] 20130220 Re: CVE request for Drupal Core and contributed modules</ref>
      <ref url="http://drupalcode.org/project/taxonomy_manager.git/commitdiff/595f1b3" source="CONFIRM">http://drupalcode.org/project/taxonomy_manager.git/commitdiff/595f1b3</ref>
      <ref url="http://drupalcode.org/project/taxonomy_manager.git/commitdiff/2d05801" source="CONFIRM">http://drupalcode.org/project/taxonomy_manager.git/commitdiff/2d05801</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mattias_hutterer" name="taxonomy_manager">
        <vers num="6.x-2.0"/>
        <vers num="6.x-2.1"/>
        <vers num="6.x-2.x" edition="dev"/>
        <vers num="7.x-1.0" edition="alpha1"/>
        <vers num="7.x-1.0" edition="alpha2"/>
        <vers num="7.x-1.0" edition="alpha3"/>
        <vers num="7.x-1.0" edition="alpha4"/>
        <vers num="7.x-1.0" edition="beta1"/>
        <vers num="7.x-1.0" edition="beta2"/>
        <vers num="7.x-1.0" edition="beta3"/>
        <vers num="7.x-1.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0321" published="2013-03-27" name="CVE-2013-0321" modified="2013-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Views in the Ubercart Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://drupal.org/node/1922416" source="MISC" patch="1" adv="1">http://drupal.org/node/1922416</ref>
      <ref url="http://drupal.org/node/1922128" source="CONFIRM" patch="1">http://drupal.org/node/1922128</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/5" source="MLIST">[oss-security] 20130220 Re: CVE request for Drupal Core and contributed modules</ref>
      <ref url="http://drupalcode.org/project/uc_views.git/commitdiff/157d5d3" source="CONFIRM">http://drupalcode.org/project/uc_views.git/commitdiff/157d5d3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubercart_views_project" name="uc_views">
        <vers num="6.x-1.0"/>
        <vers num="6.x-1.1"/>
        <vers num="6.x-1.x" edition="dev"/>
        <vers num="6.x-2.0"/>
        <vers num="6.x-3.0"/>
        <vers num="6.x-3.1"/>
        <vers num="6.x-3.2"/>
        <vers num="6.x-3.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0322" published="2013-03-27" name="CVE-2013-0322" modified="2013-04-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Views in the Ubercart module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://drupal.org/node/1922418" source="MISC" patch="1" adv="1">http://drupal.org/node/1922418</ref>
      <ref url="http://drupal.org/node/1922136" source="CONFIRM" patch="1">http://drupal.org/node/1922136</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/5" source="MLIST">[oss-security] 20130220 Re: CVE request for Drupal Core and contributed modules</ref>
      <ref url="http://drupalcode.org/project/ubercart.git/commitdiff/f9d69b5" source="CONFIRM">http://drupalcode.org/project/ubercart.git/commitdiff/f9d69b5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubercart" name="ubercart">
        <vers num="7.x-3.0" edition="alpha1"/>
        <vers num="7.x-3.0" edition="alpha2"/>
        <vers num="7.x-3.0" edition="alpha3"/>
        <vers num="7.x-3.0" edition="beta1"/>
        <vers num="7.x-3.0" edition="beta2"/>
        <vers num="7.x-3.0" edition="beta3"/>
        <vers num="7.x-3.0" edition="beta4"/>
        <vers num="7.x-3.0" edition="dev"/>
        <vers num="7.x-3.0" edition="rc1"/>
        <vers num="7.x-3.0" edition="rc2"/>
        <vers num="7.x-3.0" edition="rc3"/>
        <vers num="7.x-3.0" edition="rc4"/>
        <vers num="7.x-3.1"/>
        <vers num="7.x-3.2"/>
        <vers num="7.x-3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0323" published="2013-03-27" name="CVE-2013-0323" modified="2013-04-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the author field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://drupalcode.org/project/ds.git/commitdiff/90bcd8f" source="CONFIRM" patch="1">http://drupalcode.org/project/ds.git/commitdiff/90bcd8f</ref>
      <ref url="http://drupalcode.org/project/ds.git/commitdiff/665c791" source="CONFIRM" patch="1">http://drupalcode.org/project/ds.git/commitdiff/665c791</ref>
      <ref url="http://drupalcode.org/project/ds.git/commitdiff/45d490e" source="CONFIRM" patch="1">http://drupalcode.org/project/ds.git/commitdiff/45d490e</ref>
      <ref url="http://drupal.org/node/1922438" source="MISC" patch="1" adv="1">http://drupal.org/node/1922438</ref>
      <ref url="http://drupal.org/node/1922430" source="CONFIRM" patch="1">http://drupal.org/node/1922430</ref>
      <ref url="http://drupal.org/node/1922424" source="CONFIRM" patch="1">http://drupal.org/node/1922424</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/5" source="MLIST">[oss-security] 20130220 Re: CVE request for Drupal Core and contributed modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="display_suite_project" name="ds">
        <vers num="7.x-1.0" edition="alpha1"/>
        <vers num="7.x-1.0" edition="alpha2"/>
        <vers num="7.x-1.0" edition="rc2"/>
        <vers num="7.x-1.0" edition="rc3"/>
        <vers num="7.x-1.1"/>
        <vers num="7.x-1.2"/>
        <vers num="7.x-1.3"/>
        <vers num="7.x-1.4"/>
        <vers num="7.x-1.5"/>
        <vers num="7.x-1.6"/>
        <vers num="7.x-1.x" edition="dev"/>
        <vers num="7.x-2.0" edition="beta1"/>
        <vers num="7.x-2.0" edition="beta2"/>
        <vers num="7.x-2.0" edition="beta3"/>
        <vers num="7.x-2.0" edition="rc1"/>
        <vers num="7.x-2.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0324" published="2013-03-27" name="CVE-2013-0324" modified="2013-04-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Rendered links formatter in the Menu Reference module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the "Administer menus and menu items" permission to inject arbitrary web script or HTML via the menu link title.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://drupalcode.org/project/menu_reference.git/commitdiff/7e7367d" source="CONFIRM" patch="1">http://drupalcode.org/project/menu_reference.git/commitdiff/7e7367d</ref>
      <ref url="http://drupal.org/node/1922446" source="MISC" patch="1" adv="1">http://drupal.org/node/1922446</ref>
      <ref url="http://drupal.org/node/1922434" source="CONFIRM" patch="1">http://drupal.org/node/1922434</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/5" source="MLIST">[oss-security] 20130220 Re: CVE request for Drupal Core and contributed modules</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tomasbarej" name="menu_reference">
        <vers num="7.x-1.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0325" published="2013-03-27" name="CVE-2013-0325" modified="2013-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin setting.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://drupal.org/node/1922756" source="MISC" patch="1" adv="1">http://drupal.org/node/1922756</ref>
      <ref url="http://drupal.org/node/1922730" source="CONFIRM" patch="1">http://drupal.org/node/1922730</ref>
      <ref url="http://drupal.org/node/1922726" source="CONFIRM" patch="1">http://drupal.org/node/1922726</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/5" source="MLIST">[oss-security] 20130220 Re: CVE request for Drupal Core and contributed modules</ref>
      <ref url="http://drupalcode.org/project/varnish.git/commitdiff/f69a62c" source="CONFIRM">http://drupalcode.org/project/varnish.git/commitdiff/f69a62c</ref>
      <ref url="http://drupalcode.org/project/varnish.git/commitdiff/e6726b4" source="CONFIRM">http://drupalcode.org/project/varnish.git/commitdiff/e6726b4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="varnish_http_accelerator_integration_project" name="varnish">
        <vers num="6.x-1.0"/>
        <vers num="6.x-1.1"/>
        <vers num="6.x-1.x" edition="dev"/>
        <vers num="7.x-1.0" edition="beta1"/>
        <vers num="7.x-1.x" edition="dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0327" published="2013-03-19" name="CVE-2013-0327" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Jenkins master in CloudBees Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to hijack the authentication of users via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16" source="CONFIRM">https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=914875" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=914875</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/7" source="MLIST">[oss-security] 20130220 Re: Jenkins CVE request for Jenkins Security Advisory 2013-02-16</ref>
      <ref url="http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-02-16.cb" source="CONFIRM">http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-02-16.cb</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0638.html" source="REDHAT">RHSA-2013:0638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cloudbees" name="jenkins">
        <vers num="1.301"/>
        <vers num="1.302"/>
        <vers num="1.303"/>
        <vers num="1.304"/>
        <vers num="1.305"/>
        <vers num="1.306"/>
        <vers num="1.307"/>
        <vers num="1.308"/>
        <vers num="1.309"/>
        <vers num="1.310"/>
        <vers num="1.311"/>
        <vers num="1.312"/>
        <vers num="1.313"/>
        <vers num="1.314"/>
        <vers num="1.315"/>
        <vers num="1.316"/>
        <vers num="1.317"/>
        <vers num="1.318"/>
        <vers num="1.319"/>
        <vers num="1.320"/>
        <vers num="1.321"/>
        <vers num="1.322"/>
        <vers num="1.323"/>
        <vers num="1.324"/>
        <vers num="1.325"/>
        <vers num="1.326"/>
        <vers num="1.327"/>
        <vers num="1.328"/>
        <vers num="1.329"/>
        <vers num="1.330"/>
        <vers num="1.331"/>
        <vers num="1.332"/>
        <vers num="1.333"/>
        <vers num="1.334"/>
        <vers num="1.335"/>
        <vers num="1.336"/>
        <vers num="1.337"/>
        <vers num="1.338"/>
        <vers num="1.339"/>
        <vers num="1.340"/>
        <vers num="1.341"/>
        <vers num="1.342"/>
        <vers num="1.343"/>
        <vers num="1.344"/>
        <vers num="1.345"/>
        <vers num="1.346"/>
        <vers num="1.347"/>
        <vers num="1.348"/>
        <vers num="1.349"/>
        <vers num="1.350"/>
        <vers num="1.351"/>
        <vers num="1.352"/>
        <vers num="1.353"/>
        <vers num="1.354"/>
        <vers num="1.355"/>
        <vers num="1.356"/>
        <vers num="1.357"/>
        <vers num="1.358"/>
        <vers num="1.359"/>
        <vers num="1.360"/>
        <vers num="1.361"/>
        <vers num="1.362"/>
        <vers num="1.363"/>
        <vers num="1.364"/>
        <vers num="1.365"/>
        <vers num="1.366"/>
        <vers num="1.367"/>
        <vers num="1.368"/>
        <vers num="1.369"/>
        <vers num="1.370"/>
        <vers num="1.371"/>
        <vers num="1.372"/>
        <vers num="1.373"/>
        <vers num="1.374"/>
        <vers num="1.375"/>
        <vers num="1.376"/>
        <vers num="1.377"/>
        <vers num="1.378"/>
        <vers num="1.379"/>
        <vers num="1.380"/>
        <vers num="1.382"/>
        <vers num="1.383"/>
        <vers num="1.384"/>
        <vers num="1.386"/>
        <vers num="1.387"/>
        <vers num="1.388"/>
        <vers num="1.389"/>
        <vers num="1.390"/>
        <vers num="1.391"/>
        <vers num="1.392"/>
        <vers num="1.393"/>
        <vers num="1.394"/>
        <vers num="1.395"/>
        <vers num="1.396"/>
        <vers num="1.397"/>
        <vers num="1.398"/>
        <vers num="1.399"/>
        <vers num="1.400" edition="-"/>
        <vers num="1.400" edition="-:lts"/>
        <vers num="1.401"/>
        <vers num="1.402"/>
        <vers num="1.403"/>
        <vers num="1.404"/>
        <vers num="1.405"/>
        <vers num="1.406"/>
        <vers num="1.407"/>
        <vers num="1.408"/>
        <vers num="1.409"/>
        <vers num="1.409.1" edition=""/>
        <vers num="1.409.1" edition=":lts"/>
        <vers num="1.409.1" edition="-"/>
        <vers num="1.409.1" edition="-:lts"/>
        <vers num="1.409.2" edition=""/>
        <vers num="1.409.2" edition=":lts"/>
        <vers num="1.409.2" edition="-"/>
        <vers num="1.409.2" edition="-:lts"/>
        <vers num="1.409.3" edition="-"/>
        <vers num="1.409.3" edition="-:lts"/>
        <vers num="1.410"/>
        <vers num="1.411"/>
        <vers num="1.412"/>
        <vers num="1.413"/>
        <vers num="1.414"/>
        <vers num="1.415"/>
        <vers num="1.416"/>
        <vers num="1.417"/>
        <vers num="1.418"/>
        <vers num="1.419"/>
        <vers num="1.420"/>
        <vers num="1.421"/>
        <vers num="1.422"/>
        <vers num="1.423"/>
        <vers num="1.424" edition="-"/>
        <vers num="1.424" edition="-:lts"/>
        <vers num="1.424.0.2" edition="-"/>
        <vers num="1.424.0.2" edition="-:enterprise"/>
        <vers num="1.424.0.4" edition="-"/>
        <vers num="1.424.0.4" edition="-:enterprise"/>
        <vers num="1.424.1" edition="-"/>
        <vers num="1.424.1" edition="-:lts"/>
        <vers num="1.424.1.1" edition="-"/>
        <vers num="1.424.1.1" edition="-:enterprise"/>
        <vers num="1.424.2" edition="-"/>
        <vers num="1.424.2" edition="-:lts"/>
        <vers num="1.424.2.1" edition="-"/>
        <vers num="1.424.2.1" edition="-:enterprise"/>
        <vers num="1.424.3" edition="-"/>
        <vers num="1.424.3" edition="-:lts"/>
        <vers num="1.424.4" edition="-"/>
        <vers num="1.424.4" edition="-:lts"/>
        <vers num="1.424.4.1" edition="-"/>
        <vers num="1.424.4.1" edition="-:enterprise"/>
        <vers num="1.424.5" edition="-"/>
        <vers num="1.424.5" edition="-:lts"/>
        <vers num="1.424.5.1" edition="-"/>
        <vers num="1.424.5.1" edition="-:enterprise"/>
        <vers num="1.424.6" edition="-"/>
        <vers num="1.424.6" edition="-:lts"/>
        <vers num="1.424.6.1" edition="-"/>
        <vers num="1.424.6.1" edition="-:enterprise"/>
        <vers num="1.424.6.11" edition="-"/>
        <vers num="1.424.6.11" edition="-:enterprise"/>
        <vers num="1.425"/>
        <vers num="1.426"/>
        <vers num="1.427"/>
        <vers num="1.428"/>
        <vers num="1.429"/>
        <vers num="1.430"/>
        <vers num="1.431"/>
        <vers num="1.432"/>
        <vers num="1.433"/>
        <vers num="1.434"/>
        <vers num="1.435"/>
        <vers num="1.436"/>
        <vers num="1.437"/>
        <vers num="1.447" edition="-"/>
        <vers num="1.447" edition="-:lts"/>
        <vers num="1.447.1" edition="-"/>
        <vers num="1.447.1" edition="-:lts"/>
        <vers num="1.447.1.1" edition="-"/>
        <vers num="1.447.1.1" edition="-:enterprise"/>
        <vers num="1.447.2" edition="-"/>
        <vers num="1.447.2" edition="-:lts"/>
        <vers num="1.447.2.2" edition="-"/>
        <vers num="1.447.2.2" edition="-:enterprise"/>
        <vers num="1.447.3.1" edition="-"/>
        <vers num="1.447.3.1" edition="-:enterprise"/>
        <vers num="1.466.1" edition="-"/>
        <vers num="1.466.1" edition="-:lts"/>
        <vers num="1.466.1.2" edition="-"/>
        <vers num="1.466.1.2" edition="-:enterprise"/>
        <vers num="1.466.2" edition="-"/>
        <vers num="1.466.2" edition="-:lts"/>
        <vers num="1.466.2.1" edition="-"/>
        <vers num="1.466.2.1" edition="-:enterprise"/>
        <vers prev="1" num="1.480.2"/>
        <vers num="1.480.3.1"/>
      </prod>
      <prod vendor="cloudbees" name="jenkins1.381">
        <vers num=""/>
      </prod>
      <prod vendor="cloudbees" name="jenkins1.500">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0328" published="2013-03-19" name="CVE-2013-0328" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CloudBees Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16" source="CONFIRM">https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=914876" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=914876</ref>
      <ref url="http://www.securityfocus.com/bid/57994" source="BID">57994</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/7" source="MLIST">[oss-security] 20130220 Re: Jenkins CVE request for Jenkins Security Advisory 2013-02-16</ref>
      <ref url="http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-02-16.cb" source="CONFIRM" adv="1">http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-02-16.cb</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0638.html" source="REDHAT">RHSA-2013:0638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cloudbees" name="jenkins">
        <vers num="1.301"/>
        <vers num="1.302"/>
        <vers num="1.303"/>
        <vers num="1.304"/>
        <vers num="1.305"/>
        <vers num="1.306"/>
        <vers num="1.307"/>
        <vers num="1.308"/>
        <vers num="1.309"/>
        <vers num="1.310"/>
        <vers num="1.311"/>
        <vers num="1.312"/>
        <vers num="1.313"/>
        <vers num="1.314"/>
        <vers num="1.315"/>
        <vers num="1.316"/>
        <vers num="1.317"/>
        <vers num="1.318"/>
        <vers num="1.319"/>
        <vers num="1.320"/>
        <vers num="1.321"/>
        <vers num="1.322"/>
        <vers num="1.323"/>
        <vers num="1.324"/>
        <vers num="1.325"/>
        <vers num="1.326"/>
        <vers num="1.327"/>
        <vers num="1.328"/>
        <vers num="1.329"/>
        <vers num="1.330"/>
        <vers num="1.331"/>
        <vers num="1.332"/>
        <vers num="1.333"/>
        <vers num="1.334"/>
        <vers num="1.335"/>
        <vers num="1.336"/>
        <vers num="1.337"/>
        <vers num="1.338"/>
        <vers num="1.339"/>
        <vers num="1.340"/>
        <vers num="1.341"/>
        <vers num="1.342"/>
        <vers num="1.343"/>
        <vers num="1.344"/>
        <vers num="1.345"/>
        <vers num="1.346"/>
        <vers num="1.347"/>
        <vers num="1.348"/>
        <vers num="1.349"/>
        <vers num="1.350"/>
        <vers num="1.351"/>
        <vers num="1.352"/>
        <vers num="1.353"/>
        <vers num="1.354"/>
        <vers num="1.355"/>
        <vers num="1.356"/>
        <vers num="1.357"/>
        <vers num="1.358"/>
        <vers num="1.359"/>
        <vers num="1.360"/>
        <vers num="1.361"/>
        <vers num="1.362"/>
        <vers num="1.363"/>
        <vers num="1.364"/>
        <vers num="1.365"/>
        <vers num="1.366"/>
        <vers num="1.367"/>
        <vers num="1.368"/>
        <vers num="1.369"/>
        <vers num="1.370"/>
        <vers num="1.371"/>
        <vers num="1.372"/>
        <vers num="1.373"/>
        <vers num="1.374"/>
        <vers num="1.375"/>
        <vers num="1.376"/>
        <vers num="1.377"/>
        <vers num="1.378"/>
        <vers num="1.379"/>
        <vers num="1.380"/>
        <vers num="1.382"/>
        <vers num="1.383"/>
        <vers num="1.384"/>
        <vers num="1.386"/>
        <vers num="1.387"/>
        <vers num="1.388"/>
        <vers num="1.389"/>
        <vers num="1.390"/>
        <vers num="1.391"/>
        <vers num="1.392"/>
        <vers num="1.393"/>
        <vers num="1.394"/>
        <vers num="1.395"/>
        <vers num="1.396"/>
        <vers num="1.397"/>
        <vers num="1.398"/>
        <vers num="1.399"/>
        <vers num="1.400" edition="-"/>
        <vers num="1.400" edition="-:lts"/>
        <vers num="1.401"/>
        <vers num="1.402"/>
        <vers num="1.403"/>
        <vers num="1.404"/>
        <vers num="1.405"/>
        <vers num="1.406"/>
        <vers num="1.407"/>
        <vers num="1.408"/>
        <vers num="1.409"/>
        <vers num="1.409.1" edition=""/>
        <vers num="1.409.1" edition=":lts"/>
        <vers num="1.409.1" edition="-"/>
        <vers num="1.409.1" edition="-:lts"/>
        <vers num="1.409.2" edition=""/>
        <vers num="1.409.2" edition=":lts"/>
        <vers num="1.409.2" edition="-"/>
        <vers num="1.409.2" edition="-:lts"/>
        <vers num="1.409.3" edition="-"/>
        <vers num="1.409.3" edition="-:lts"/>
        <vers num="1.410"/>
        <vers num="1.411"/>
        <vers num="1.412"/>
        <vers num="1.413"/>
        <vers num="1.414"/>
        <vers num="1.415"/>
        <vers num="1.416"/>
        <vers num="1.417"/>
        <vers num="1.418"/>
        <vers num="1.419"/>
        <vers num="1.420"/>
        <vers num="1.421"/>
        <vers num="1.422"/>
        <vers num="1.423"/>
        <vers num="1.424" edition="-"/>
        <vers num="1.424" edition="-:lts"/>
        <vers num="1.424.0.2" edition="-"/>
        <vers num="1.424.0.2" edition="-:enterprise"/>
        <vers num="1.424.0.4" edition="-"/>
        <vers num="1.424.0.4" edition="-:enterprise"/>
        <vers num="1.424.1" edition="-"/>
        <vers num="1.424.1" edition="-:lts"/>
        <vers num="1.424.1.1" edition="-"/>
        <vers num="1.424.1.1" edition="-:enterprise"/>
        <vers num="1.424.2" edition="-"/>
        <vers num="1.424.2" edition="-:lts"/>
        <vers num="1.424.2.1" edition="-"/>
        <vers num="1.424.2.1" edition="-:enterprise"/>
        <vers num="1.424.3" edition="-"/>
        <vers num="1.424.3" edition="-:lts"/>
        <vers num="1.424.4" edition="-"/>
        <vers num="1.424.4" edition="-:lts"/>
        <vers num="1.424.4.1" edition="-"/>
        <vers num="1.424.4.1" edition="-:enterprise"/>
        <vers num="1.424.5" edition="-"/>
        <vers num="1.424.5" edition="-:lts"/>
        <vers num="1.424.5.1" edition="-"/>
        <vers num="1.424.5.1" edition="-:enterprise"/>
        <vers num="1.424.6" edition="-"/>
        <vers num="1.424.6" edition="-:lts"/>
        <vers num="1.424.6.1" edition="-"/>
        <vers num="1.424.6.1" edition="-:enterprise"/>
        <vers num="1.424.6.11" edition="-"/>
        <vers num="1.424.6.11" edition="-:enterprise"/>
        <vers num="1.425"/>
        <vers num="1.426"/>
        <vers num="1.427"/>
        <vers num="1.428"/>
        <vers num="1.429"/>
        <vers num="1.430"/>
        <vers num="1.431"/>
        <vers num="1.432"/>
        <vers num="1.433"/>
        <vers num="1.434"/>
        <vers num="1.435"/>
        <vers num="1.436"/>
        <vers num="1.437"/>
        <vers num="1.447" edition="-"/>
        <vers num="1.447" edition="-:lts"/>
        <vers num="1.447.1" edition="-"/>
        <vers num="1.447.1" edition="-:lts"/>
        <vers num="1.447.1.1" edition="-"/>
        <vers num="1.447.1.1" edition="-:enterprise"/>
        <vers num="1.447.2" edition="-"/>
        <vers num="1.447.2" edition="-:lts"/>
        <vers num="1.447.2.2" edition="-"/>
        <vers num="1.447.2.2" edition="-:enterprise"/>
        <vers num="1.447.3.1" edition="-"/>
        <vers num="1.447.3.1" edition="-:enterprise"/>
        <vers num="1.466.1" edition="-"/>
        <vers num="1.466.1" edition="-:lts"/>
        <vers num="1.466.1.2" edition="-"/>
        <vers num="1.466.1.2" edition="-:enterprise"/>
        <vers num="1.466.2" edition="-"/>
        <vers num="1.466.2" edition="-:lts"/>
        <vers num="1.466.2.1" edition="-"/>
        <vers num="1.466.2.1" edition="-:enterprise"/>
        <vers prev="1" num="1.480.2"/>
        <vers num="1.480.3.1"/>
      </prod>
      <prod vendor="cloudbees" name="jenkins1.381">
        <vers num=""/>
      </prod>
      <prod vendor="cloudbees" name="jenkins1.500">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0329" published="2013-03-19" name="CVE-2013-0329" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in CloudBees Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to bypass the CSRF protection mechanism via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16" source="CONFIRM">https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=914877" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=914877</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/7" source="MLIST">[oss-security] 20130220 Re: Jenkins CVE request for Jenkins Security Advisory 2013-02-16</ref>
      <ref url="http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-02-16.cb" source="CONFIRM" adv="1">http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-02-16.cb</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0638.html" source="REDHAT">RHSA-2013:0638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cloudbees" name="jenkins">
        <vers num="1.301"/>
        <vers num="1.302"/>
        <vers num="1.303"/>
        <vers num="1.304"/>
        <vers num="1.305"/>
        <vers num="1.306"/>
        <vers num="1.307"/>
        <vers num="1.308"/>
        <vers num="1.309"/>
        <vers num="1.310"/>
        <vers num="1.311"/>
        <vers num="1.312"/>
        <vers num="1.313"/>
        <vers num="1.314"/>
        <vers num="1.315"/>
        <vers num="1.316"/>
        <vers num="1.317"/>
        <vers num="1.318"/>
        <vers num="1.319"/>
        <vers num="1.320"/>
        <vers num="1.321"/>
        <vers num="1.322"/>
        <vers num="1.323"/>
        <vers num="1.324"/>
        <vers num="1.325"/>
        <vers num="1.326"/>
        <vers num="1.327"/>
        <vers num="1.328"/>
        <vers num="1.329"/>
        <vers num="1.330"/>
        <vers num="1.331"/>
        <vers num="1.332"/>
        <vers num="1.333"/>
        <vers num="1.334"/>
        <vers num="1.335"/>
        <vers num="1.336"/>
        <vers num="1.337"/>
        <vers num="1.338"/>
        <vers num="1.339"/>
        <vers num="1.340"/>
        <vers num="1.341"/>
        <vers num="1.342"/>
        <vers num="1.343"/>
        <vers num="1.344"/>
        <vers num="1.345"/>
        <vers num="1.346"/>
        <vers num="1.347"/>
        <vers num="1.348"/>
        <vers num="1.349"/>
        <vers num="1.350"/>
        <vers num="1.351"/>
        <vers num="1.352"/>
        <vers num="1.353"/>
        <vers num="1.354"/>
        <vers num="1.355"/>
        <vers num="1.356"/>
        <vers num="1.357"/>
        <vers num="1.358"/>
        <vers num="1.359"/>
        <vers num="1.360"/>
        <vers num="1.361"/>
        <vers num="1.362"/>
        <vers num="1.363"/>
        <vers num="1.364"/>
        <vers num="1.365"/>
        <vers num="1.366"/>
        <vers num="1.367"/>
        <vers num="1.368"/>
        <vers num="1.369"/>
        <vers num="1.370"/>
        <vers num="1.371"/>
        <vers num="1.372"/>
        <vers num="1.373"/>
        <vers num="1.374"/>
        <vers num="1.375"/>
        <vers num="1.376"/>
        <vers num="1.377"/>
        <vers num="1.378"/>
        <vers num="1.379"/>
        <vers num="1.380"/>
        <vers num="1.382"/>
        <vers num="1.383"/>
        <vers num="1.384"/>
        <vers num="1.386"/>
        <vers num="1.387"/>
        <vers num="1.388"/>
        <vers num="1.389"/>
        <vers num="1.390"/>
        <vers num="1.391"/>
        <vers num="1.392"/>
        <vers num="1.393"/>
        <vers num="1.394"/>
        <vers num="1.395"/>
        <vers num="1.396"/>
        <vers num="1.397"/>
        <vers num="1.398"/>
        <vers num="1.399"/>
        <vers num="1.400" edition="-"/>
        <vers num="1.400" edition="-:lts"/>
        <vers num="1.401"/>
        <vers num="1.402"/>
        <vers num="1.403"/>
        <vers num="1.404"/>
        <vers num="1.405"/>
        <vers num="1.406"/>
        <vers num="1.407"/>
        <vers num="1.408"/>
        <vers num="1.409"/>
        <vers num="1.409.1" edition=""/>
        <vers num="1.409.1" edition=":lts"/>
        <vers num="1.409.1" edition="-"/>
        <vers num="1.409.1" edition="-:lts"/>
        <vers num="1.409.2" edition=""/>
        <vers num="1.409.2" edition=":lts"/>
        <vers num="1.409.2" edition="-"/>
        <vers num="1.409.2" edition="-:lts"/>
        <vers num="1.409.3" edition="-"/>
        <vers num="1.409.3" edition="-:lts"/>
        <vers num="1.410"/>
        <vers num="1.411"/>
        <vers num="1.412"/>
        <vers num="1.413"/>
        <vers num="1.414"/>
        <vers num="1.415"/>
        <vers num="1.416"/>
        <vers num="1.417"/>
        <vers num="1.418"/>
        <vers num="1.419"/>
        <vers num="1.420"/>
        <vers num="1.421"/>
        <vers num="1.422"/>
        <vers num="1.423"/>
        <vers num="1.424" edition="-"/>
        <vers num="1.424" edition="-:lts"/>
        <vers num="1.424.0.2" edition="-"/>
        <vers num="1.424.0.2" edition="-:enterprise"/>
        <vers num="1.424.0.4" edition="-"/>
        <vers num="1.424.0.4" edition="-:enterprise"/>
        <vers num="1.424.1" edition="-"/>
        <vers num="1.424.1" edition="-:lts"/>
        <vers num="1.424.1.1" edition="-"/>
        <vers num="1.424.1.1" edition="-:enterprise"/>
        <vers num="1.424.2" edition="-"/>
        <vers num="1.424.2" edition="-:lts"/>
        <vers num="1.424.2.1" edition="-"/>
        <vers num="1.424.2.1" edition="-:enterprise"/>
        <vers num="1.424.3" edition="-"/>
        <vers num="1.424.3" edition="-:lts"/>
        <vers num="1.424.4" edition="-"/>
        <vers num="1.424.4" edition="-:lts"/>
        <vers num="1.424.4.1" edition="-"/>
        <vers num="1.424.4.1" edition="-:enterprise"/>
        <vers num="1.424.5" edition="-"/>
        <vers num="1.424.5" edition="-:lts"/>
        <vers num="1.424.5.1" edition="-"/>
        <vers num="1.424.5.1" edition="-:enterprise"/>
        <vers num="1.424.6" edition="-"/>
        <vers num="1.424.6" edition="-:lts"/>
        <vers num="1.424.6.1" edition="-"/>
        <vers num="1.424.6.1" edition="-:enterprise"/>
        <vers num="1.424.6.11" edition="-"/>
        <vers num="1.424.6.11" edition="-:enterprise"/>
        <vers num="1.425"/>
        <vers num="1.426"/>
        <vers num="1.427"/>
        <vers num="1.428"/>
        <vers num="1.429"/>
        <vers num="1.430"/>
        <vers num="1.431"/>
        <vers num="1.432"/>
        <vers num="1.433"/>
        <vers num="1.434"/>
        <vers num="1.435"/>
        <vers num="1.436"/>
        <vers num="1.437"/>
        <vers num="1.447" edition="-"/>
        <vers num="1.447" edition="-:lts"/>
        <vers num="1.447.1" edition="-"/>
        <vers num="1.447.1" edition="-:lts"/>
        <vers num="1.447.1.1" edition="-"/>
        <vers num="1.447.1.1" edition="-:enterprise"/>
        <vers num="1.447.2" edition="-"/>
        <vers num="1.447.2" edition="-:lts"/>
        <vers num="1.447.2.2" edition="-"/>
        <vers num="1.447.2.2" edition="-:enterprise"/>
        <vers num="1.447.3.1" edition="-"/>
        <vers num="1.447.3.1" edition="-:enterprise"/>
        <vers num="1.466.1" edition="-"/>
        <vers num="1.466.1" edition="-:lts"/>
        <vers num="1.466.1.2" edition="-"/>
        <vers num="1.466.1.2" edition="-:enterprise"/>
        <vers num="1.466.2" edition="-"/>
        <vers num="1.466.2" edition="-:lts"/>
        <vers num="1.466.2.1" edition="-"/>
        <vers num="1.466.2.1" edition="-:enterprise"/>
        <vers prev="1" num="1.480.2"/>
        <vers num="1.480.3.1"/>
      </prod>
      <prod vendor="cloudbees" name="jenkins1.381">
        <vers num=""/>
      </prod>
      <prod vendor="cloudbees" name="jenkins1.500">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0330" published="2013-03-19" name="CVE-2013-0330" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in CloudBees Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to build arbitrary jobs via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16" source="CONFIRM">https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=914878" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=914878</ref>
      <ref url="http://www.securityfocus.com/bid/57994" source="BID">57994</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/7" source="MLIST">[oss-security] 20130220 Re: Jenkins CVE request for Jenkins Security Advisory 2013-02-16</ref>
      <ref url="http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-02-16.cb" source="CONFIRM" adv="1">http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-02-16.cb</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0638.html" source="REDHAT">RHSA-2013:0638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cloudbees" name="jenkins">
        <vers num="1.301"/>
        <vers num="1.302"/>
        <vers num="1.303"/>
        <vers num="1.304"/>
        <vers num="1.305"/>
        <vers num="1.306"/>
        <vers num="1.307"/>
        <vers num="1.308"/>
        <vers num="1.309"/>
        <vers num="1.310"/>
        <vers num="1.311"/>
        <vers num="1.312"/>
        <vers num="1.313"/>
        <vers num="1.314"/>
        <vers num="1.315"/>
        <vers num="1.316"/>
        <vers num="1.317"/>
        <vers num="1.318"/>
        <vers num="1.319"/>
        <vers num="1.320"/>
        <vers num="1.321"/>
        <vers num="1.322"/>
        <vers num="1.323"/>
        <vers num="1.324"/>
        <vers num="1.325"/>
        <vers num="1.326"/>
        <vers num="1.327"/>
        <vers num="1.328"/>
        <vers num="1.329"/>
        <vers num="1.330"/>
        <vers num="1.331"/>
        <vers num="1.332"/>
        <vers num="1.333"/>
        <vers num="1.334"/>
        <vers num="1.335"/>
        <vers num="1.336"/>
        <vers num="1.337"/>
        <vers num="1.338"/>
        <vers num="1.339"/>
        <vers num="1.340"/>
        <vers num="1.341"/>
        <vers num="1.342"/>
        <vers num="1.343"/>
        <vers num="1.344"/>
        <vers num="1.345"/>
        <vers num="1.346"/>
        <vers num="1.347"/>
        <vers num="1.348"/>
        <vers num="1.349"/>
        <vers num="1.350"/>
        <vers num="1.351"/>
        <vers num="1.352"/>
        <vers num="1.353"/>
        <vers num="1.354"/>
        <vers num="1.355"/>
        <vers num="1.356"/>
        <vers num="1.357"/>
        <vers num="1.358"/>
        <vers num="1.359"/>
        <vers num="1.360"/>
        <vers num="1.361"/>
        <vers num="1.362"/>
        <vers num="1.363"/>
        <vers num="1.364"/>
        <vers num="1.365"/>
        <vers num="1.366"/>
        <vers num="1.367"/>
        <vers num="1.368"/>
        <vers num="1.369"/>
        <vers num="1.370"/>
        <vers num="1.371"/>
        <vers num="1.372"/>
        <vers num="1.373"/>
        <vers num="1.374"/>
        <vers num="1.375"/>
        <vers num="1.376"/>
        <vers num="1.377"/>
        <vers num="1.378"/>
        <vers num="1.379"/>
        <vers num="1.380"/>
        <vers num="1.382"/>
        <vers num="1.383"/>
        <vers num="1.384"/>
        <vers num="1.386"/>
        <vers num="1.387"/>
        <vers num="1.388"/>
        <vers num="1.389"/>
        <vers num="1.390"/>
        <vers num="1.391"/>
        <vers num="1.392"/>
        <vers num="1.393"/>
        <vers num="1.394"/>
        <vers num="1.395"/>
        <vers num="1.396"/>
        <vers num="1.397"/>
        <vers num="1.398"/>
        <vers num="1.399"/>
        <vers num="1.400" edition="-"/>
        <vers num="1.400" edition="-:lts"/>
        <vers num="1.401"/>
        <vers num="1.402"/>
        <vers num="1.403"/>
        <vers num="1.404"/>
        <vers num="1.405"/>
        <vers num="1.406"/>
        <vers num="1.407"/>
        <vers num="1.408"/>
        <vers num="1.409"/>
        <vers num="1.409.1" edition=""/>
        <vers num="1.409.1" edition=":lts"/>
        <vers num="1.409.1" edition="-"/>
        <vers num="1.409.1" edition="-:lts"/>
        <vers num="1.409.2" edition=""/>
        <vers num="1.409.2" edition=":lts"/>
        <vers num="1.409.2" edition="-"/>
        <vers num="1.409.2" edition="-:lts"/>
        <vers num="1.409.3" edition="-"/>
        <vers num="1.409.3" edition="-:lts"/>
        <vers num="1.410"/>
        <vers num="1.411"/>
        <vers num="1.412"/>
        <vers num="1.413"/>
        <vers num="1.414"/>
        <vers num="1.415"/>
        <vers num="1.416"/>
        <vers num="1.417"/>
        <vers num="1.418"/>
        <vers num="1.419"/>
        <vers num="1.420"/>
        <vers num="1.421"/>
        <vers num="1.422"/>
        <vers num="1.423"/>
        <vers num="1.424" edition="-"/>
        <vers num="1.424" edition="-:lts"/>
        <vers num="1.424.0.2" edition="-"/>
        <vers num="1.424.0.2" edition="-:enterprise"/>
        <vers num="1.424.0.4" edition="-"/>
        <vers num="1.424.0.4" edition="-:enterprise"/>
        <vers num="1.424.1" edition="-"/>
        <vers num="1.424.1" edition="-:lts"/>
        <vers num="1.424.1.1" edition="-"/>
        <vers num="1.424.1.1" edition="-:enterprise"/>
        <vers num="1.424.2" edition="-"/>
        <vers num="1.424.2" edition="-:lts"/>
        <vers num="1.424.2.1" edition="-"/>
        <vers num="1.424.2.1" edition="-:enterprise"/>
        <vers num="1.424.3" edition="-"/>
        <vers num="1.424.3" edition="-:lts"/>
        <vers num="1.424.4" edition="-"/>
        <vers num="1.424.4" edition="-:lts"/>
        <vers num="1.424.4.1" edition="-"/>
        <vers num="1.424.4.1" edition="-:enterprise"/>
        <vers num="1.424.5" edition="-"/>
        <vers num="1.424.5" edition="-:lts"/>
        <vers num="1.424.5.1" edition="-"/>
        <vers num="1.424.5.1" edition="-:enterprise"/>
        <vers num="1.424.6" edition="-"/>
        <vers num="1.424.6" edition="-:lts"/>
        <vers num="1.424.6.1" edition="-"/>
        <vers num="1.424.6.1" edition="-:enterprise"/>
        <vers num="1.424.6.11" edition="-"/>
        <vers num="1.424.6.11" edition="-:enterprise"/>
        <vers num="1.425"/>
        <vers num="1.426"/>
        <vers num="1.427"/>
        <vers num="1.428"/>
        <vers num="1.429"/>
        <vers num="1.430"/>
        <vers num="1.431"/>
        <vers num="1.432"/>
        <vers num="1.433"/>
        <vers num="1.434"/>
        <vers num="1.435"/>
        <vers num="1.436"/>
        <vers num="1.437"/>
        <vers num="1.447" edition="-"/>
        <vers num="1.447" edition="-:lts"/>
        <vers num="1.447.1" edition="-"/>
        <vers num="1.447.1" edition="-:lts"/>
        <vers num="1.447.1.1" edition="-"/>
        <vers num="1.447.1.1" edition="-:enterprise"/>
        <vers num="1.447.2" edition="-"/>
        <vers num="1.447.2" edition="-:lts"/>
        <vers num="1.447.2.2" edition="-"/>
        <vers num="1.447.2.2" edition="-:enterprise"/>
        <vers num="1.447.3.1" edition="-"/>
        <vers num="1.447.3.1" edition="-:enterprise"/>
        <vers num="1.466.1" edition="-"/>
        <vers num="1.466.1" edition="-:lts"/>
        <vers num="1.466.1.2" edition="-"/>
        <vers num="1.466.1.2" edition="-:enterprise"/>
        <vers num="1.466.2" edition="-"/>
        <vers num="1.466.2" edition="-:lts"/>
        <vers num="1.466.2.1" edition="-"/>
        <vers num="1.466.2.1" edition="-:enterprise"/>
        <vers prev="1" num="1.480.2"/>
        <vers num="1.480.3.1"/>
      </prod>
      <prod vendor="cloudbees" name="jenkins1.381">
        <vers num=""/>
      </prod>
      <prod vendor="cloudbees" name="jenkins1.500">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0331" published="2013-03-19" name="CVE-2013-0331" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">CloudBees Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to cause a denial of service via a crafted payload.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16" source="CONFIRM">https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=914879" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=914879</ref>
      <ref url="http://www.securityfocus.com/bid/57994" source="BID">57994</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/7" source="MLIST">[oss-security] 20130220 Re: Jenkins CVE request for Jenkins Security Advisory 2013-02-16</ref>
      <ref url="http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-02-16.cb" source="CONFIRM" adv="1">http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2013-02-16.cb</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0638.html" source="REDHAT">RHSA-2013:0638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cloudbees" name="jenkins">
        <vers num="1.301"/>
        <vers num="1.302"/>
        <vers num="1.303"/>
        <vers num="1.304"/>
        <vers num="1.305"/>
        <vers num="1.306"/>
        <vers num="1.307"/>
        <vers num="1.308"/>
        <vers num="1.309"/>
        <vers num="1.310"/>
        <vers num="1.311"/>
        <vers num="1.312"/>
        <vers num="1.313"/>
        <vers num="1.314"/>
        <vers num="1.315"/>
        <vers num="1.316"/>
        <vers num="1.317"/>
        <vers num="1.318"/>
        <vers num="1.319"/>
        <vers num="1.320"/>
        <vers num="1.321"/>
        <vers num="1.322"/>
        <vers num="1.323"/>
        <vers num="1.324"/>
        <vers num="1.325"/>
        <vers num="1.326"/>
        <vers num="1.327"/>
        <vers num="1.328"/>
        <vers num="1.329"/>
        <vers num="1.330"/>
        <vers num="1.331"/>
        <vers num="1.332"/>
        <vers num="1.333"/>
        <vers num="1.334"/>
        <vers num="1.335"/>
        <vers num="1.336"/>
        <vers num="1.337"/>
        <vers num="1.338"/>
        <vers num="1.339"/>
        <vers num="1.340"/>
        <vers num="1.341"/>
        <vers num="1.342"/>
        <vers num="1.343"/>
        <vers num="1.344"/>
        <vers num="1.345"/>
        <vers num="1.346"/>
        <vers num="1.347"/>
        <vers num="1.348"/>
        <vers num="1.349"/>
        <vers num="1.350"/>
        <vers num="1.351"/>
        <vers num="1.352"/>
        <vers num="1.353"/>
        <vers num="1.354"/>
        <vers num="1.355"/>
        <vers num="1.356"/>
        <vers num="1.357"/>
        <vers num="1.358"/>
        <vers num="1.359"/>
        <vers num="1.360"/>
        <vers num="1.361"/>
        <vers num="1.362"/>
        <vers num="1.363"/>
        <vers num="1.364"/>
        <vers num="1.365"/>
        <vers num="1.366"/>
        <vers num="1.367"/>
        <vers num="1.368"/>
        <vers num="1.369"/>
        <vers num="1.370"/>
        <vers num="1.371"/>
        <vers num="1.372"/>
        <vers num="1.373"/>
        <vers num="1.374"/>
        <vers num="1.375"/>
        <vers num="1.376"/>
        <vers num="1.377"/>
        <vers num="1.378"/>
        <vers num="1.379"/>
        <vers num="1.380"/>
        <vers num="1.382"/>
        <vers num="1.383"/>
        <vers num="1.384"/>
        <vers num="1.386"/>
        <vers num="1.387"/>
        <vers num="1.388"/>
        <vers num="1.389"/>
        <vers num="1.390"/>
        <vers num="1.391"/>
        <vers num="1.392"/>
        <vers num="1.393"/>
        <vers num="1.394"/>
        <vers num="1.395"/>
        <vers num="1.396"/>
        <vers num="1.397"/>
        <vers num="1.398"/>
        <vers num="1.399"/>
        <vers num="1.400" edition="-"/>
        <vers num="1.400" edition="-:lts"/>
        <vers num="1.401"/>
        <vers num="1.402"/>
        <vers num="1.403"/>
        <vers num="1.404"/>
        <vers num="1.405"/>
        <vers num="1.406"/>
        <vers num="1.407"/>
        <vers num="1.408"/>
        <vers num="1.409"/>
        <vers num="1.409.1" edition=""/>
        <vers num="1.409.1" edition=":lts"/>
        <vers num="1.409.1" edition="-"/>
        <vers num="1.409.1" edition="-:lts"/>
        <vers num="1.409.2" edition=""/>
        <vers num="1.409.2" edition=":lts"/>
        <vers num="1.409.2" edition="-"/>
        <vers num="1.409.2" edition="-:lts"/>
        <vers num="1.409.3" edition="-"/>
        <vers num="1.409.3" edition="-:lts"/>
        <vers num="1.410"/>
        <vers num="1.411"/>
        <vers num="1.412"/>
        <vers num="1.413"/>
        <vers num="1.414"/>
        <vers num="1.415"/>
        <vers num="1.416"/>
        <vers num="1.417"/>
        <vers num="1.418"/>
        <vers num="1.419"/>
        <vers num="1.420"/>
        <vers num="1.421"/>
        <vers num="1.422"/>
        <vers num="1.423"/>
        <vers num="1.424" edition="-"/>
        <vers num="1.424" edition="-:lts"/>
        <vers num="1.424.0.2" edition="-"/>
        <vers num="1.424.0.2" edition="-:enterprise"/>
        <vers num="1.424.0.4" edition="-"/>
        <vers num="1.424.0.4" edition="-:enterprise"/>
        <vers num="1.424.1" edition="-"/>
        <vers num="1.424.1" edition="-:lts"/>
        <vers num="1.424.1.1" edition="-"/>
        <vers num="1.424.1.1" edition="-:enterprise"/>
        <vers num="1.424.2" edition="-"/>
        <vers num="1.424.2" edition="-:lts"/>
        <vers num="1.424.2.1" edition="-"/>
        <vers num="1.424.2.1" edition="-:enterprise"/>
        <vers num="1.424.3" edition="-"/>
        <vers num="1.424.3" edition="-:lts"/>
        <vers num="1.424.4" edition="-"/>
        <vers num="1.424.4" edition="-:lts"/>
        <vers num="1.424.4.1" edition="-"/>
        <vers num="1.424.4.1" edition="-:enterprise"/>
        <vers num="1.424.5" edition="-"/>
        <vers num="1.424.5" edition="-:lts"/>
        <vers num="1.424.5.1" edition="-"/>
        <vers num="1.424.5.1" edition="-:enterprise"/>
        <vers num="1.424.6" edition="-"/>
        <vers num="1.424.6" edition="-:lts"/>
        <vers num="1.424.6.1" edition="-"/>
        <vers num="1.424.6.1" edition="-:enterprise"/>
        <vers num="1.424.6.11" edition="-"/>
        <vers num="1.424.6.11" edition="-:enterprise"/>
        <vers num="1.425"/>
        <vers num="1.426"/>
        <vers num="1.427"/>
        <vers num="1.428"/>
        <vers num="1.429"/>
        <vers num="1.430"/>
        <vers num="1.431"/>
        <vers num="1.432"/>
        <vers num="1.433"/>
        <vers num="1.434"/>
        <vers num="1.435"/>
        <vers num="1.436"/>
        <vers num="1.437"/>
        <vers num="1.447" edition="-"/>
        <vers num="1.447" edition="-:lts"/>
        <vers num="1.447.1" edition="-"/>
        <vers num="1.447.1" edition="-:lts"/>
        <vers num="1.447.1.1" edition="-"/>
        <vers num="1.447.1.1" edition="-:enterprise"/>
        <vers num="1.447.2" edition="-"/>
        <vers num="1.447.2" edition="-:lts"/>
        <vers num="1.447.2.2" edition="-"/>
        <vers num="1.447.2.2" edition="-:enterprise"/>
        <vers num="1.447.3.1" edition="-"/>
        <vers num="1.447.3.1" edition="-:enterprise"/>
        <vers num="1.466.1" edition="-"/>
        <vers num="1.466.1" edition="-:lts"/>
        <vers num="1.466.1.2" edition="-"/>
        <vers num="1.466.1.2" edition="-:enterprise"/>
        <vers num="1.466.2" edition="-"/>
        <vers num="1.466.2" edition="-:lts"/>
        <vers num="1.466.2.1" edition="-"/>
        <vers num="1.466.2.1" edition="-:enterprise"/>
        <vers prev="1" num="1.480.2"/>
        <vers num="1.480.3.1"/>
      </prod>
      <prod vendor="cloudbees" name="jenkins1.381">
        <vers num=""/>
      </prod>
      <prod vendor="cloudbees" name="jenkins1.500">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0332" published="2013-03-20" name="CVE-2013-0332" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) view, (2) request, or (3) action parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.zoneminder.com/wiki/index.php/Change_History" source="CONFIRM">http://www.zoneminder.com/wiki/index.php/Change_History</ref>
      <ref url="http://www.zoneminder.com/forums/viewtopic.php?f=1&amp;t=17979" source="CONFIRM">http://www.zoneminder.com/forums/viewtopic.php?f=1&amp;t=17979</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/9" source="MLIST">[oss-security] 20130221 Re: CVE request: zoneminder: local file inclusion vulnerability</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/21/8" source="MLIST">[oss-security] 20130220 Re: CVE request: zoneminder: local file inclusion vulnerability</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2640" source="DEBIAN">DSA-2640</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=700912" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=700912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zoneminder" name="zoneminder">
        <vers num="1.24.0"/>
        <vers num="1.24.1"/>
        <vers num="1.24.2"/>
        <vers num="1.24.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0333" published="2013-01-30" name="CVE-2013-0333" modified="2013-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct SQL injection attacks, or bypass authentication via crafted data that triggers unsafe decoding, a different vulnerability than CVE-2013-0156.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/628463" source="CERT-VN">VU#628463</ref>
      <ref url="https://groups.google.com/group/rubyonrails-security/msg/52179af76915e518?dmode=source&amp;output=gplain" source="MLIST" adv="1">[rubyonrails-security] 20130129 Vulnerability in JSON Parser in Ruby on Rails 3.0 and 2.3</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2613" source="DEBIAN">DSA-2613</ref>
      <ref url="http://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/" source="CONFIRM">http://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/</ref>
      <ref url="http://support.apple.com/kb/HT5784" source="CONFIRM">http://support.apple.com/kb/HT5784</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0203.html" source="REDHAT">RHSA-2013:0203</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0202.html" source="REDHAT">RHSA-2013:0202</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0201.html" source="REDHAT">RHSA-2013:0201</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html" source="APPLE">APPLE-SA-2013-03-14-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html" source="APPLE">APPLE-SA-2013-06-04-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rubyonrails" name="ruby_on_rails">
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.3.15"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.9"/>
        <vers num="3.0.0" edition="beta"/>
        <vers num="3.0.0" edition="beta2"/>
        <vers num="3.0.0" edition="beta3"/>
        <vers num="3.0.0" edition="beta4"/>
        <vers num="3.0.0" edition="rc"/>
        <vers num="3.0.0" edition="rc2"/>
        <vers num="3.0.1" edition="pre"/>
        <vers num="3.0.10" edition="rc1"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12" edition="rc1"/>
        <vers num="3.0.13" edition="rc1"/>
        <vers num="3.0.14"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2" edition="pre"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4" edition="rc"/>
        <vers num="3.0.4" edition="rc1"/>
        <vers num="3.0.5" edition="rc1"/>
        <vers num="3.0.6" edition="rc1"/>
        <vers num="3.0.6" edition="rc2"/>
        <vers num="3.0.7" edition="rc1"/>
        <vers num="3.0.7" edition="rc2"/>
        <vers num="3.0.8" edition="rc1"/>
        <vers num="3.0.8" edition="rc2"/>
        <vers num="3.0.8" edition="rc3"/>
        <vers num="3.0.8" edition="rc4"/>
        <vers num="3.0.9" edition="rc1"/>
        <vers num="3.0.9" edition="rc2"/>
        <vers num="3.0.9" edition="rc3"/>
        <vers num="3.0.9" edition="rc4"/>
        <vers num="3.0.9" edition="rc5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0335" published="2013-03-22" name="CVE-2013-0335" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://www.ubuntu.com/usn/USN-1771-1/
"A security issue affects these releases of Ubuntu and its derivatives:

Ubuntu 12.10
Ubuntu 12.04 LTS
Ubuntu 11.10"</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://review.openstack.org/#/c/22872/" source="CONFIRM">https://review.openstack.org/#/c/22872/</ref>
      <ref url="https://review.openstack.org/#/c/22758" source="CONFIRM">https://review.openstack.org/#/c/22758</ref>
      <ref url="https://review.openstack.org/#/c/22086/" source="CONFIRM">https://review.openstack.org/#/c/22086/</ref>
      <ref url="https://bugs.launchpad.net/nova/+bug/1125378" source="CONFIRM">https://bugs.launchpad.net/nova/+bug/1125378</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1771-1" source="UBUNTU">USN-1771-1</ref>
      <ref url="http://www.osvdb.org/90657" source="OSVDB">90657</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/26/7" source="MLIST">[oss-security] 20130226 [OSSA-2013-006] VNC proxy can connect to the wrong VM (CVE-2013-0335)</ref>
      <ref url="http://secunia.com/advisories/52728" source="SECUNIA" adv="1">52728</ref>
      <ref url="http://secunia.com/advisories/52337" source="SECUNIA" adv="1">52337</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0709.html" source="REDHAT">RHSA-2013:0709</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openstack" name="essex">
        <vers num="2012.1"/>
      </prod>
      <prod vendor="openstack" name="folsom">
        <vers num="2012.2"/>
      </prod>
      <prod vendor="openstack" name="grizzly">
        <vers num="2012.2"/>
      </prod>
      <prod vendor="canonical" name="ubuntu_linux">
        <vers num="11.10"/>
        <vers num="12.04" edition="-"/>
        <vers num="12.04" edition="-:lts"/>
        <vers num="12.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0338" published="2013-04-25" name="CVE-2013-0338" modified="2013-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://www.ubuntu.com/usn/USN-1782-1/ "A security issue affects these releases of Ubuntu and its derivatives:

    Ubuntu 12.10
    Ubuntu 12.04 LTS
    Ubuntu 11.10
    Ubuntu 10.04 LTS
    Ubuntu 8.04 LTS"

Per http://lists.opensuse.org/opensuse-updates/2013-03/msg00112.html "http://lists.opensuse.org/opensuse-updates/2013-03/msg00112.html"
</impact>
    </impacts>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://git.gnome.org/browse/libxml2/commit/?id=23f05e0c33987d6605387b300c4be5da2120a7ab" source="CONFIRM">https://git.gnome.org/browse/libxml2/commit/?id=23f05e0c33987d6605387b300c4be5da2120a7ab</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=912400" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=912400</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1782-1" source="UBUNTU">USN-1782-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2013:056" source="MANDRIVA">MDVSA-2013:056</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00114.html" source="SUSE">openSUSE-SU-2013:0555</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-03/msg00112.html" source="SUSE">openSUSE-SU-2013:0552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmlsoft" name="libxml2">
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.4"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.10"/>
        <vers num="1.8.13"/>
        <vers num="1.8.14"/>
        <vers num="1.8.16"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.8.7"/>
        <vers num="1.8.9"/>
        <vers num="2.0.0"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.2.0" edition="beta"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18"/>
        <vers num="2.4.19"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23"/>
        <vers num="2.4.24"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27"/>
        <vers num="2.4.28"/>
        <vers num="2.4.29"/>
        <vers num="2.4.3"/>
        <vers num="2.4.30"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.5.0"/>
        <vers num="2.5.10"/>
        <vers num="2.5.11"/>
        <vers num="2.5.4"/>
        <vers num="2.5.7"/>
        <vers num="2.5.8"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.11"/>
        <vers num="2.6.12"/>
        <vers num="2.6.13"/>
        <vers num="2.6.14"/>
        <vers num="2.6.16"/>
        <vers num="2.6.17"/>
        <vers num="2.6.18"/>
        <vers num="2.6.2"/>
        <vers num="2.6.20"/>
        <vers num="2.6.21"/>
        <vers num="2.6.22"/>
        <vers num="2.6.23"/>
        <vers num="2.6.24"/>
        <vers num="2.6.25"/>
        <vers num="2.6.26"/>
        <vers num="2.6.27"/>
        <vers num="2.6.28"/>
        <vers num="2.6.29"/>
        <vers num="2.6.3"/>
        <vers num="2.6.30"/>
        <vers num="2.6.31"/>
        <vers num="2.6.32"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.6.7"/>
        <vers num="2.6.8"/>
        <vers num="2.6.9"/>
        <vers num="2.7.0"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.7.3"/>
        <vers num="2.7.4"/>
        <vers num="2.7.5"/>
        <vers num="2.7.6"/>
        <vers num="2.7.7"/>
        <vers num="2.7.8"/>
        <vers prev="1" num="2.9.0" edition="rc1"/>
      </prod>
      <prod vendor="canonical" name="ubuntu_linux">
        <vers num="10.04" edition="-"/>
        <vers num="10.04" edition="-:lts"/>
        <vers num="11.10"/>
        <vers num="12.04" edition="-"/>
        <vers num="12.04" edition="-:lts"/>
        <vers num="12.10"/>
        <vers num="8.04" edition="-"/>
        <vers num="8.04" edition="-:lts"/>
      </prod>
      <prod vendor="novell" name="opensuse">
        <vers num="12.1"/>
        <vers num="12.2"/>
        <vers num="12.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0343" published="2013-02-28" name="CVE-2013-0343" modified="2013-02-28" CVSS_version="2.0" CVSS_vector="(AV:A/AC:H/Au:N/C:P/I:N/A:P)" CVSS_score="3.2" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.2" CVSS_base_score="3.2">
    <desc>
      <descript source="cve">The ipv6_create_tempaddr function in net/ipv6/addrconf.c in the Linux kernel through 3.8 does not properly handle problems with the generation of IPv6 temporary addresses, which allows remote attackers to cause a denial of service (excessive retries and address-generation outage), and consequently obtain sensitive information, via ICMPv6 Router Advertisement (RA) messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=914664" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=914664</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/22/6" source="MLIST">[oss-security] 20130222 Re: Linux kernel handling of IPv6 temporary addresses</ref>
      <ref url="http://openwall.com/lists/oss-security/2013/01/21/11" source="MLIST">[oss-security] 20130121 Re: Linux kernel handling of IPv6 temporary addresses</ref>
      <ref url="http://openwall.com/lists/oss-security/2013/01/16/7" source="MLIST">[oss-security] 20130116 Re: Linux kernel handling of IPv6 temporary addresses</ref>
      <ref url="http://openwall.com/lists/oss-security/2012/12/05/4" source="MLIST">[oss-security] 20121205 Re: Linux kernel handling of IPv6 temporary addresses</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.10"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers num="3.7.9"/>
        <vers prev="1" num="3.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0349" published="2013-02-28" name="CVE-2013-0349" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The hidp_setup_hid function in net/bluetooth/hidp/core.c in the Linux kernel before 3.7.6 does not properly copy a certain name field, which allows local users to obtain sensitive information from kernel memory by setting a long name and making an HIDPCONNADD ioctl call.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/0a9ab9bdb3e891762553f667066190c1d22ad62b" source="CONFIRM">https://github.com/torvalds/linux/commit/0a9ab9bdb3e891762553f667066190c1d22ad62b</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=914298" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=914298</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1808-1" source="UBUNTU">USN-1808-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1805-1" source="UBUNTU">USN-1805-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/23/3" source="MLIST">[oss-security] 20130222 Re: CVE request: Linux kernel: Bluetooth HIDP information disclosure</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.6" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.6</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0744.html" source="REDHAT">RHSA-2013:0744</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0a9ab9bdb3e891762553f667066190c1d22ad62b" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0a9ab9bdb3e891762553f667066190c1d22ad62b</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers prev="1" num="3.7.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0351" published="2013-02-01" name="CVE-2013-0351" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0352" published="2013-01-16" name="CVE-2013-0352" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1 and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Content Management.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.2.0.3"/>
        <vers num="10.2.0.4"/>
        <vers num="10.2.0.5"/>
        <vers num="11.1.0.7"/>
        <vers num="11.2.0.2"/>
        <vers num="11.2.0.3"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.2.0.5"/>
        <vers num="11.1.0.1"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_plugin_for_database_control">
        <vers num="12.1.0.1"/>
        <vers num="12.1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0353" published="2013-01-16" name="CVE-2013-0353" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1 allows remote attackers to affect integrity via unknown vectors related to Enterprise Configuration Management.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="11.1.0.7"/>
        <vers num="11.2.0.2"/>
        <vers num="11.2.0.3"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.2.0.5"/>
        <vers num="11.1.0.1"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_plugin_for_database_control">
        <vers num="12.1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0354" published="2013-01-16" name="CVE-2013-0354" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5, and EM DB Control 11.1.0.7, 11.2.0.2, and 11.2.0.3, allows remote attackers to affect integrity via unknown vectors related to Policy Framework.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="11.1.0.7"/>
        <vers num="11.2.0.2"/>
        <vers num="11.2.0.3"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0355" published="2013-01-16" name="CVE-2013-0355" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1, and EM DB Control 11.1.0.7, 11.2.0.2, and 11.2.0.3, allows remote attackers to affect integrity via unknown vectors related to Distributed/Cross DB Features.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="11.1.0.7"/>
        <vers num="11.2.0.2"/>
        <vers num="11.2.0.3"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.2.0.5"/>
        <vers num="11.1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0356" published="2013-01-16" name="CVE-2013-0356" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote attackers to affect integrity, related to PIA Core Technology.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="8.51"/>
        <vers num="8.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0357" published="2013-01-16" name="CVE-2013-0357" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.52 allows remote attackers to affect integrity, related to PIA Core Technology.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="8.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0358" published="2013-01-16" name="CVE-2013-0358" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1 and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Resource Manager.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.2.0.3"/>
        <vers num="10.2.0.4"/>
        <vers num="10.2.0.5"/>
        <vers num="11.1.0.7"/>
        <vers num="11.2.0.2"/>
        <vers num="11.2.0.3"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.2.0.5"/>
        <vers num="11.1.0.1"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_plugin_for_database_control">
        <vers num="12.1.0.1"/>
        <vers num="12.1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0359" published="2013-01-16" name="CVE-2013-0359" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the APM - Application Performance Management component in Oracle Enterprise Manager Grid Control 6.5, 11.1, and 12.1.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Business Transaction Management.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="11.1"/>
        <vers num="12.1.0.2"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0360" published="2013-01-16" name="CVE-2013-0360" modified="2013-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Application Performance Management (APM) component in Oracle Enterprise Manager Grid Control 6.5, 11.1, and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Business Transaction Management, a different vulnerability than CVE-2013-0396.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="11.1"/>
        <vers num="12.1.0.2"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0361" published="2013-01-16" name="CVE-2013-0361" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-0366.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html

'Oracle Database Mobile Server was formerly known as Oracle Database Lite for 10g.'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_lite">
        <vers num="10.3.0.3"/>
      </prod>
      <prod vendor="oracle" name="database_mobile/lite_server">
        <vers num="10.3.0.3"/>
        <vers num="11.1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0362" published="2013-01-16" name="CVE-2013-0362" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0363 and CVE-2013-0364.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_mobile/lite_server">
        <vers num="10.3.0.3"/>
        <vers num="11.1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0363" published="2013-01-16" name="CVE-2013-0363" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0362 and CVE-2013-0364.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_mobile/lite_server">
        <vers num="10.3.0.3"/>
        <vers num="11.1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0364" published="2013-01-16" name="CVE-2013-0364" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0362 and CVE-2013-0363.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_lite">
        <vers num="10.3.0.3"/>
      </prod>
      <prod vendor="oracle" name="database_mobile/lite_server">
        <vers num="10.3.0.3"/>
        <vers num="11.1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0365" published="2013-01-16" name="CVE-2013-0365" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="siebel_crm">
        <vers num="8.1.1"/>
        <vers num="8.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0366" published="2013-01-16" name="CVE-2013-0366" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-0361.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_mobile/lite_server">
        <vers num="10.3.0.3"/>
        <vers num="11.1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0367" published="2013-01-16" name="CVE-2013-0367" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Partition.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1703-1" source="UBUNTU">USN-1703-1</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25" edition="a"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers prev="1" num="5.5.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0368" published="2013-01-16" name="CVE-2013-0368" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1703-1" source="UBUNTU">USN-1703-1</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25" edition="a"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers prev="1" num="5.5.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0369" published="2013-01-16" name="CVE-2013-0369" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Query.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="8.51"/>
        <vers num="8.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0370" published="2013-01-16" name="CVE-2013-0370" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="supply_chain_products_suite">
        <vers num="9.3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0371" published="2013-01-16" name="CVE-2013-0371" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability, related to MyISAM.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1703-1" source="UBUNTU">USN-1703-1</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25" edition="a"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers prev="1" num="5.5.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0372" published="2013-01-16" name="CVE-2013-0372" modified="2013-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1 and 12.1.0.1; EM DB Control 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Distributed/Cross DB Features.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="11.1.0.7"/>
        <vers num="11.2.0.2"/>
        <vers num="11.2.0.3"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="11.1.0.1"/>
        <vers num="12.1.0.1"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_plugin_for_database_control">
        <vers num="12.1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0373" published="2013-01-16" name="CVE-2013-0373" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1, and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Distributed/Cross DB Features.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.2.0.3"/>
        <vers num="10.2.0.4"/>
        <vers num="10.2.0.5"/>
        <vers num="11.1.0.7"/>
        <vers num="11.2.0.2"/>
        <vers num="11.2.0.3"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.2.0.5"/>
        <vers num="11.1.0.1"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_plugin_for_database_control">
        <vers num="12.1.0.1"/>
        <vers num="12.1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0374" published="2013-01-16" name="CVE-2013-0374" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1, and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Database Cloning.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager_database_control">
        <vers num="10.2.0.3"/>
        <vers num="10.2.0.4"/>
        <vers num="10.2.0.5"/>
        <vers num="11.1.0.7"/>
        <vers num="11.2.0.2"/>
        <vers num="11.2.0.3"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="10.2.0.5"/>
        <vers num="11.1.0.1"/>
      </prod>
      <prod vendor="oracle" name="enterprise_manager_plugin_for_database_control">
        <vers num="12.1.0.1"/>
        <vers num="12.1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0375" published="2013-01-16" name="CVE-2013-0375" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.1.28 and earlier, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Server Replication.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1703-1" source="UBUNTU">USN-1703-1</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0219.html" source="REDHAT">RHSA-2013:0219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers prev="1" num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.1.62"/>
        <vers num="5.1.63"/>
        <vers num="5.1.64"/>
        <vers num="5.1.65"/>
        <vers prev="1" num="5.1.66"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0376" published="2013-01-16" name="CVE-2013-0376" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Diagnostics.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2"/>
        <vers num="12.0.6"/>
        <vers num="12.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0377" published="2013-01-16" name="CVE-2013-0377" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Client System Analyzer.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2"/>
        <vers num="12.0.6"/>
        <vers num="12.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0378" published="2013-01-16" name="CVE-2013-0378" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to Siebel Calendar, a different vulnerability than CVE-2013-0379.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="siebel_crm">
        <vers num="8.1.1"/>
        <vers num="8.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0379" published="2013-01-16" name="CVE-2013-0379" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to Siebel Calendar, a different vulnerability than CVE-2013-0378.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="siebel_crm">
        <vers num="8.1.1"/>
        <vers num="8.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0380" published="2013-01-16" name="CVE-2013-0380" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Payroll component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to View Payslip.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2"/>
        <vers num="12.0.6"/>
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0381" published="2013-01-16" name="CVE-2013-0381" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Application Framework.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2"/>
        <vers num="12.0.6"/>
        <vers num="12.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0382" published="2013-01-16" name="CVE-2013-0382" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Campaign Management.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2"/>
        <vers num="12.0.6"/>
        <vers num="12.1.1"/>
        <vers num="12.1.2"/>
        <vers num="12.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0383" published="2013-01-16" name="CVE-2013-0383" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote attackers to affect availability via unknown vectors related to Server Locking.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1703-1" source="UBUNTU">USN-1703-1</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0219.html" source="REDHAT">RHSA-2013:0219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.1.62"/>
        <vers num="5.1.63"/>
        <vers num="5.1.64"/>
        <vers num="5.1.65"/>
        <vers prev="1" num="5.1.66"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25" edition="a"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers prev="1" num="5.5.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0384" published="2013-01-16" name="CVE-2013-0384" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Information Schema.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1703-1" source="UBUNTU">USN-1703-1</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0219.html" source="REDHAT">RHSA-2013:0219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.1.62"/>
        <vers num="5.1.63"/>
        <vers num="5.1.64"/>
        <vers num="5.1.65"/>
        <vers prev="1" num="5.1.66"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25" edition="a"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers prev="1" num="5.5.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0385" published="2013-01-16" name="CVE-2013-0385" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:N)" CVSS_score="6.6" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.9" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows local users to affect confidentiality and integrity via unknown vectors related to Server Replication.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1703-1" source="UBUNTU">USN-1703-1</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0219.html" source="REDHAT">RHSA-2013:0219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.1.62"/>
        <vers num="5.1.63"/>
        <vers num="5.1.64"/>
        <vers num="5.1.65"/>
        <vers prev="1" num="5.1.66"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25" edition="a"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers prev="1" num="5.5.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0386" published="2013-01-16" name="CVE-2013-0386" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1703-1" source="UBUNTU">USN-1703-1</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25" edition="a"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers prev="1" num="5.5.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0387" published="2013-01-16" name="CVE-2013-0387" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:M/C:P/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="5.5" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to PeopleCode.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="8.51"/>
        <vers num="8.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0388" published="2013-01-16" name="CVE-2013-0388" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft HRMS component in Oracle PeopleSoft Products 9.1 allows remote attackers to affect integrity via unknown vectors related to Mobile Company Directory.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0389" published="2013-01-16" name="CVE-2013-0389" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-1703-1" source="UBUNTU">USN-1703-1</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0219.html" source="REDHAT">RHSA-2013:0219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.11"/>
        <vers num="5.1.12"/>
        <vers num="5.1.13"/>
        <vers num="5.1.14"/>
        <vers num="5.1.15"/>
        <vers num="5.1.16"/>
        <vers num="5.1.17"/>
        <vers num="5.1.18"/>
        <vers num="5.1.19"/>
        <vers num="5.1.2"/>
        <vers num="5.1.20"/>
        <vers num="5.1.21"/>
        <vers num="5.1.22"/>
        <vers num="5.1.23" edition="a"/>
        <vers num="5.1.23_bk"/>
        <vers num="5.1.23a"/>
        <vers num="5.1.24"/>
        <vers num="5.1.25"/>
        <vers num="5.1.26"/>
        <vers num="5.1.27"/>
        <vers num="5.1.28"/>
        <vers num="5.1.29"/>
        <vers num="5.1.3"/>
        <vers num="5.1.30"/>
        <vers num="5.1.31" edition="sp1"/>
        <vers num="5.1.32"/>
        <vers num="5.1.32-bzr"/>
        <vers num="5.1.33"/>
        <vers num="5.1.34" edition="sp1"/>
        <vers num="5.1.35"/>
        <vers num="5.1.36"/>
        <vers num="5.1.37" edition="sp1"/>
        <vers num="5.1.38"/>
        <vers num="5.1.39"/>
        <vers num="5.1.4"/>
        <vers num="5.1.40" edition="sp1"/>
        <vers num="5.1.41"/>
        <vers num="5.1.42"/>
        <vers num="5.1.43" edition="sp1"/>
        <vers num="5.1.44"/>
        <vers num="5.1.45"/>
        <vers num="5.1.46" edition="sp1"/>
        <vers num="5.1.47"/>
        <vers num="5.1.48"/>
        <vers num="5.1.49" edition="sp1"/>
        <vers num="5.1.5"/>
        <vers num="5.1.50"/>
        <vers num="5.1.5a"/>
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
      </prod>
      <prod vendor="oracle" name="mysql">
        <vers num="5.1.51"/>
        <vers num="5.1.52" edition="sp1"/>
        <vers num="5.1.53"/>
        <vers num="5.1.54"/>
        <vers num="5.1.55"/>
        <vers num="5.1.56"/>
        <vers num="5.1.57"/>
        <vers num="5.1.58"/>
        <vers num="5.1.59"/>
        <vers num="5.1.60"/>
        <vers num="5.1.61"/>
        <vers num="5.1.62"/>
        <vers num="5.1.63"/>
        <vers num="5.1.64"/>
        <vers num="5.1.65"/>
        <vers prev="1" num="5.1.66"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25" edition="a"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers prev="1" num="5.5.28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0390" published="2013-01-16" name="CVE-2013-0390" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Bookmarkable Pages.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2"/>
        <vers num="12.0.6"/>
        <vers num="12.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0391" published="2013-01-16" name="CVE-2013-0391" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.52 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Security.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="8.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0392" published="2013-01-16" name="CVE-2013-0392" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote attackers to affect integrity via unknown vectors related to Portal, a different vulnerability than CVE-2012-5059.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="8.51"/>
        <vers num="8.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0393" published="2013-01-16" name="CVE-2013-0393" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0418.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html

'2. Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8."</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-012" source="MS">MS13-012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="8.3.7.0"/>
        <vers num="8.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0394" published="2013-01-16" name="CVE-2013-0394" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft HRMS component in Oracle PeopleSoft Products 9.0 and 9.1 allows remote attackers to affect confidentiality via unknown vectors related to Candidate Gateway.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0395" published="2013-01-16" name="CVE-2013-0395" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect integrity via unknown vectors related to Security.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_products">
        <vers num="8.51"/>
        <vers num="8.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0396" published="2013-01-16" name="CVE-2013-0396" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Application Performance Management (APM) component in Oracle Enterprise Manager Grid Control 6.5, 11.1, and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Business Transaction Management, a different vulnerability than CVE-2013-0360.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager_grid_control">
        <vers num="11.1"/>
        <vers num="12.1.0.2"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0397" published="2013-01-16" name="CVE-2013-0397" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Diagnostics.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2"/>
        <vers num="12.0.6"/>
        <vers num="12.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0399" published="2013-01-16" name="CVE-2013-0399" modified="2013-05-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Utility/Umount.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf" source="CONFIRM">http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0400" published="2013-01-16" name="CVE-2013-0400" modified="2013-05-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Filesystem/cachefs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf" source="CONFIRM">http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0401" published="2013-03-08" name="CVE-2013-0401" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to execute arbitrary code via vectors related to AWT, as demonstrated by Ben Murphy during a Pwn2Own competition at CanSecWest 2013.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to invocation of the system class loader by the sun.awt.datatransfer.ClassLoaderObjectInputStream class, which allows remote attackers to bypass Java sandbox restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://twitter.com/thezdi/status/309784608508100608" source="MISC">https://twitter.com/thezdi/status/309784608508100608</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=920245" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=920245</ref>
      <ref url="http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/" source="MISC">http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1806-1" source="UBUNTU">USN-1806-1</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0758.html" source="REDHAT">RHSA-2013:0758</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0757.html" source="REDHAT">RHSA-2013:0757</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0752.html" source="REDHAT">RHSA-2013:0752</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-05/msg00017.html" source="SUSE">openSUSE-SU-2013:0777</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00013.html" source="SUSE">SUSE-SU-2013:0835</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00007.html" source="SUSE">SUSE-SU-2013:0814</ref>
      <ref url="http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/31c782610044" source="MISC">http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/31c782610044</ref>
      <ref url="http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157" source="MISC">http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157</ref>
      <ref url="http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/" source="CONFIRM">http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/</ref>
      <ref url="http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/" source="CONFIRM">http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.7.0" edition="update17"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.7.0" edition="update17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0402" published="2013-03-08" name="CVE-2013-0402" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier allows remote attackers to execute arbitrary code via unspecified vectors related to JavaFX, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://twitter.com/thezdi/status/309484730506698752" source="MISC">https://twitter.com/thezdi/status/309484730506698752</ref>
      <ref url="http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/" source="MISC">http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0757.html" source="REDHAT">RHSA-2013:0757</ref>
      <ref url="http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157" source="MISC">http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.7.0" edition="update17"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.7.0" edition="update17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0403" published="2013-04-17" name="CVE-2013-0403" modified="2013-04-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect availability via unknown vectors related to Utility.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.11"/>
        <vers num="5.8"/>
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0404" published="2013-04-17" name="CVE-2013-0404" modified="2013-04-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/Boot.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0405" published="2013-04-17" name="CVE-2013-0405" modified="2013-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows remote attackers to affect confidentiality and integrity via vectors related to NFS client mounts and IPv6.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.11"/>
        <vers num="5.8"/>
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0406" published="2013-04-17" name="CVE-2013-0406" modified="2013-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect integrity via unknown vectors via vectors related to Kernel/IPsec.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0407" published="2013-01-16" name="CVE-2013-0407" modified="2013-05-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="4.6" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.1" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Kernel/DTrace Framework.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf" source="CONFIRM">http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0408" published="2013-04-17" name="CVE-2013-0408" modified="2013-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via vectors related to CPU performance counters drivers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0409" published="2013-02-01" name="CVE-2013-0409" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38 allows remote attackers to affect confidentiality via vectors related to JMX.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)
Applies to installation process on client deployment of Java."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0410" published="2013-04-17" name="CVE-2013-0410" modified="2013-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Agile EDM component in Oracle Supply Chain Products Suite 6.1.1.0, 6.1.2.0, and 6.1.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Base Component - Common Objects.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="supply_chain_products_suite">
        <vers num="6.1.1.0"/>
        <vers num="6.1.2.0"/>
        <vers num="6.1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0411" published="2013-04-17" name="CVE-2013-0411" modified="2013-04-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:M/C:C/I:C/A:C)" CVSS_score="5.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.2" CVSS_base_score="5.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via vectors related to RBAC Configuration.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.8"/>
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0412" published="2013-04-17" name="CVE-2013-0412" modified="2013-04-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect integrity and availability via unknown vectors related to Utility/pax.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.11"/>
        <vers num="5.8"/>
        <vers num="5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0413" published="2013-04-17" name="CVE-2013-0413" modified="2013-04-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Remote Execution Service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
        <vers num="5.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0414" published="2013-01-16" name="CVE-2013-0414" modified="2013-01-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect integrity and availability via unknown vectors related to Utility/ksh93.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0415" published="2013-01-16" name="CVE-2013-0415" modified="2013-05-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="6.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.5" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Bind/Postinstall script for Bind package.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf" source="CONFIRM">http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sunos">
        <vers num="5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0416" published="2013-04-17" name="CVE-2013-0416" modified="2013-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Siebel Enterprise Application Integration component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Web Services, a different vulnerability than CVE-2013-2403.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="siebel_crm">
        <vers num="8.1.1"/>
        <vers num="8.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0417" published="2013-01-16" name="CVE-2013-0417" modified="2013-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sun Storage Common Array Manager (CAM) component in Oracle Sun Products Suite 6.9.0 allows remote attackers to affect confidentiality, related to Fault Management System (FMS).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_products_suite">
        <vers num="6.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0418" published="2013-01-16" name="CVE-2013-0418" modified="2013-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0393.  NOTE: the previous information was obtained from the January 2013 CPU.  Oracle has not commented on claims from an independent researcher that this is a heap-based buffer overflow in the Paradox database stream filter (vspdx.dll) that can be triggered using a table header with a crafted "number of fields" value.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html#AppendixFMW

'2. Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS score would increase to 6.8.'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-012" source="MS">MS13-012</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2013-01/0073.html" source="BUGTRAQ">20130117 Secunia Research: Oracle Outside In Technology Paradox Database Handling Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="8.3.7.0"/>
        <vers num="8.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0419" published="2013-02-01" name="CVE-2013-0419" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0420" published="2013-01-16" name="CVE-2013-0420" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:S/C:N/I:P/A:P)" CVSS_score="2.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.5" CVSS_base_score="2.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0, 4.1, and 4.2 allows local users to affect integrity and availability via unknown vectors related to Core.  NOTE: The previous information was obtained from the January 2013 Oracle CPU. Oracle has not commented on claims from another vendor that this issue is related to an incorrect comparison in the vga_draw_text function in Devices/Graphics/DevVGA.cpp, which can cause VirtualBox to "draw more lines than necessary."</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://www.virtualbox.org/changeset/44055/vbox" source="MISC">https://www.virtualbox.org/changeset/44055/vbox</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=798776" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=798776</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00000.html" source="SUSE">openSUSE-SU-2013:0231</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="virtualization">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod vendor="oracle" name="vm_virtualbox">
        <vers num="4.0"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0422" published="2013-01-10" name="CVE-2013-0422" modified="2013-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114.  CVE-2013-0422 covers both the JMX/MBean and Reflection API issues.  NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks.  NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11.  If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.oracle.com/technetwork/java/javase/downloads/jdk7-downloads-1880260.html

'Note: JDK and JRE 6, 5.0 and 1.4.2, and Java SE Embedded JRE releases are not affected.'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-010A.html" source="CERT">TA13-010A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/625617" source="CERT-VN">VU#625617</ref>
      <ref url="https://www-304.ibm.com/connections/blogs/PSIRT/entry/oracle_java_7_security_manager_bypass_vulnerability_cve_2013_04224?lang=en_us" source="MISC">https://www-304.ibm.com/connections/blogs/PSIRT/entry/oracle_java_7_security_manager_bypass_vulnerability_cve_2013_04224?lang=en_us</ref>
      <ref url="https://threatpost.com/en_us/blogs/nasty-new-java-zero-day-found-exploit-kits-already-have-it-011013" source="MISC">https://threatpost.com/en_us/blogs/nasty-new-java-zero-day-found-exploit-kits-already-have-it-011013</ref>
      <ref url="https://partners.immunityinc.com/idocs/Java%20MBeanInstantiator.findClass%200day%20Analysis.pdf" source="MISC">https://partners.immunityinc.com/idocs/Java%20MBeanInstantiator.findClass%200day%20Analysis.pdf</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1693-1" source="UBUNTU">USN-1693-1</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/alert-cve-2013-0422-1896849.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/alert-cve-2013-0422-1896849.html</ref>
      <ref url="http://seclists.org/bugtraq/2013/Jan/48" source="BUGTRAQ">20130110 [SE-2012-01] 'Fix' for Issue 32 exploited by new Java 0-day code</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0165.html" source="REDHAT">RHSA-2013:0165</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0156.html" source="REDHAT">RHSA-2013:0156</ref>
      <ref url="http://malware.dontneedcoffee.com/2013/01/0-day-17u10-spotted-in-while-disable.html" source="MISC">http://malware.dontneedcoffee.com/2013/01/0-day-17u10-spotted-in-while-disable.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00025.html" source="SUSE">openSUSE-SU-2013:0199</ref>
      <ref url="http://labs.alienvault.com/labs/index.php/2013/new-year-new-java-zeroday/" source="MISC">http://labs.alienvault.com/labs/index.php/2013/new-year-new-java-zeroday/</ref>
      <ref url="http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/" source="MISC">http://krebsonsecurity.com/2013/01/zero-day-java-exploit-debuts-in-crimeware/</ref>
      <ref url="http://immunityproducts.blogspot.ca/2013/01/confirmed-java-only-fixed-one-of-two.html" source="MISC">http://immunityproducts.blogspot.ca/2013/01/confirmed-java-only-fixed-one-of-two.html</ref>
      <ref url="http://blog.fireeye.com/research/2013/01/happy-new-year-from-new-java-zero-day.html" source="MISC">http://blog.fireeye.com/research/2013/01/happy-new-year-from-new-java-zero-day.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0423" published="2013-02-01" name="CVE-2013-0423" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0424" published="2013-02-01" name="CVE-2013-0424" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to RMI. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to cross-site scripting (XSS) in the sun.rmi.transport.proxy CGIHandler class that does not properly handle error messages in a (1) command or (2) port number.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=906813" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=906813</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html" source="SUSE">SUSE-SU-2013:0478</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/6e173569e1e7" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/6e173569e1e7</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_20"/>
        <vers num="1.4.2_21"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_24"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0425" published="2013-02-01" name="CVE-2013-0425" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0428 and CVE-2013-0426.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html" source="SUSE">SUSE-SU-2013:0478</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce105dd2e4de" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce105dd2e4de</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907344" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_20"/>
        <vers num="1.4.2_21"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_24"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0426" published="2013-02-01" name="CVE-2013-0426" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0425 and CVE-2013-0428.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html  


"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html" source="SUSE">SUSE-SU-2013:0478</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce105dd2e4de" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce105dd2e4de</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907346" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_20"/>
        <vers num="1.4.2_21"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_24"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0427" published="2013-02-01" name="CVE-2013-0427" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect integrity via unknown vectors related to Libraries.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to interrupt certain threads that should not be interrupted.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/87d135824bdf" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/87d135824bdf</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907455" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907455</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0428" published="2013-02-01" name="CVE-2013-0428" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0425 and CVE-2013-0426.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "incorrect checks for proxy classes" in the Reflection API.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=907207" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=907207</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html" source="SUSE">SUSE-SU-2013:0478</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/c9534e095b37" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/c9534e095b37</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_20"/>
        <vers num="1.4.2_21"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_24"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0429" published="2013-02-01" name="CVE-2013-0429" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue involves the creation of a single PresentationManager that is shared across multiple thread groups, which allows remote attackers to bypass Java sandbox restrictions.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/corba/rev/c1ed8145c1b8" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/corba/rev/c1ed8145c1b8</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907460" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0430" published="2013-02-01" name="CVE-2013-0430" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the installation process of the client.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html  

"Applies to installation process on client deployment of Java."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0431" published="2013-01-31" name="CVE-2013-0431" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.securityfocus.com/archive/1/525387/30/0/threaded" source="BUGTRAQ">20130122 Re: [SE-2012-01] Java 7 Update 11 confirmed to be vulnerable</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://www.informationweek.com/security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717" source="MISC">http://www.informationweek.com/security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717</ref>
      <ref url="http://seclists.org/fulldisclosure/2013/Jan/195" source="FULLDISC">20130122 Re: [SE-2012-01] Java 7 Update 11 confirmed to be vulnerable</ref>
      <ref url="http://seclists.org/fulldisclosure/2013/Jan/142" source="FULLDISC">20130118 [SE-2012-01] Java 7 Update 11 confirmed to be vulnerable</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53" source="MISC">http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53</ref>
      <ref url="http://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/" source="MISC">http://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0432" published="2013-02-01" name="CVE-2013-0432" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient clipboard access premission checks."</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html" source="SUSE">SUSE-SU-2013:0478</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/e46d557465da" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/e46d557465da</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907219" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_20"/>
        <vers num="1.4.2_21"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_24"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0433" published="2013-02-01" name="CVE-2013-0433" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect integrity via unknown vectors related to Networking.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to avoid triggering an exception during the deserialization of invalid InetSocketAddress data.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=907456" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=907456</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ab011765c4e8" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ab011765c4e8</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0434" published="2013-02-01" name="CVE-2013-0434" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAXP.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to the public declaration of the loadPropertyFile method in the JAXP FuncSystemProperty class, which allows remote attackers to obtain sensitive information.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html" source="SUSE">SUSE-SU-2013:0478</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jaxp/rev/91fcc41a0b4b" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jaxp/rev/91fcc41a0b4b</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907453" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_20"/>
        <vers num="1.4.2_21"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_24"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0435" published="2013-02-01" name="CVE-2013-0435" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAX-WS.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper restriction of com.sun.xml.internal packages and "Better handling of UI elements."</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/c1fa21042291" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/c1fa21042291</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=906892" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=906892</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0436" published="2013-02-01" name="CVE-2013-0436" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="javafx">
        <vers num="2.0"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.3"/>
        <vers prev="1" num="2.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0437" published="2013-02-01" name="CVE-2013-0437" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html  

"Applies to client and server deployment of Java. This vulnerability can be exploited through untrusted Java Web Start applications and untrusted Java applets. It can also be exploited by supplying data to APIs in the specified Component without using untrusted Java Web Start applications or untrusted Java applets, such as through a web service."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="javafx">
        <vers num="2.0"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.3"/>
        <vers prev="1" num="2.2.4"/>
      </prod>
      <prod vendor="oracle" name="jdk">
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0438" published="2013-02-01" name="CVE-2013-0438" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"
</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0439" published="2013-02-01" name="CVE-2013-0439" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="javafx">
        <vers num="2.0"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.3"/>
        <vers prev="1" num="2.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0440" published="2013-02-01" name="CVE-2013-0440" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect availability via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to CPU consumption in the the SSL/TLS implementation via a large number of ClientHello packets that are not properly handled by (1) ClientHandshaker.java and (2) ServerHandshaker.java.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html  

"Applies to server deployments of JSSE."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=859140" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=859140</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html" source="SUSE">SUSE-SU-2013:0478</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/5c1e8b779c65" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/5c1e8b779c65</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_20"/>
        <vers num="1.4.2_21"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_24"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0441" published="2013-02-01" name="CVE-2013-0441" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2013-1476 and CVE-2013-1475.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass Java sandbox restrictions via certain methods that should not be serialized, aka "missing serialization restriction."</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/corba/rev/307ddc7799c7" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/corba/rev/307ddc7799c7</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907458" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907458</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_20"/>
        <vers num="1.4.2_21"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_24"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0442" published="2013-02-01" name="CVE-2013-0442" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to an improper check of "privileges of the code" that bypasses the sandbox.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html 

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html" source="SUSE">SUSE-SU-2013:0478</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/6527ae06da69" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/6527ae06da69</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=906899" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=906899</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_20"/>
        <vers num="1.4.2_21"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_24"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0443" published="2013-02-01" name="CVE-2013-0443" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect validation of Diffie-Hellman keys, which allows remote attackers to conduct a "small subgroup attack" to force the use of weak session keys or obtain sensitive information about the private key.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to server deployments of JSSE."</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=907340" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=907340</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html" source="SUSE">SUSE-SU-2013:0478</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/496bced2d275" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/496bced2d275</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.4.2_38"/>
        <vers prev="1" num="1.4.2_40"/>
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2"/>
        <vers num="1.4.2_1"/>
        <vers num="1.4.2_10"/>
        <vers num="1.4.2_11"/>
        <vers num="1.4.2_12"/>
        <vers num="1.4.2_13"/>
        <vers num="1.4.2_14"/>
        <vers num="1.4.2_15"/>
        <vers num="1.4.2_16"/>
        <vers num="1.4.2_17"/>
        <vers num="1.4.2_18"/>
        <vers num="1.4.2_19"/>
        <vers num="1.4.2_2"/>
        <vers num="1.4.2_20"/>
        <vers num="1.4.2_21"/>
        <vers num="1.4.2_22"/>
        <vers num="1.4.2_23"/>
        <vers num="1.4.2_24"/>
        <vers num="1.4.2_25"/>
        <vers num="1.4.2_26"/>
        <vers num="1.4.2_27"/>
        <vers num="1.4.2_28"/>
        <vers num="1.4.2_29"/>
        <vers num="1.4.2_3"/>
        <vers num="1.4.2_30"/>
        <vers num="1.4.2_31"/>
        <vers num="1.4.2_32"/>
        <vers num="1.4.2_33"/>
        <vers num="1.4.2_34"/>
        <vers num="1.4.2_35"/>
        <vers num="1.4.2_36"/>
        <vers num="1.4.2_37"/>
        <vers num="1.4.2_4"/>
        <vers num="1.4.2_5"/>
        <vers num="1.4.2_6"/>
        <vers num="1.4.2_7"/>
        <vers num="1.4.2_8"/>
        <vers num="1.4.2_9"/>
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0444" published="2013-02-01" name="CVE-2013-0444" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient checks for cached results" by the Java Beans MethodFinder, which might allow attackers to access methods that should only be accessible to privileged code.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html  

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce04db4aba39" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce04db4aba39</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907218" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907218</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0445" published="2013-02-01" name="CVE-2013-0445" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to an improper check of "privileges of the code" that bypasses the sandbox.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=906900" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=906900</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/6527ae06da69" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/6527ae06da69</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0446" published="2013-02-01" name="CVE-2013-0446" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html  

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0447" published="2013-02-01" name="CVE-2013-0447" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html  

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="javafx">
        <vers num="2.0"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.3"/>
        <vers prev="1" num="2.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0448" published="2013-02-01" name="CVE-2013-0448" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 allows remote attackers to affect integrity via unknown vectors related to Libraries.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0449" published="2013-02-01" name="CVE-2013-0449" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html  

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0450" published="2013-02-01" name="CVE-2013-0450" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper checks of "access control context" in the JMX RequiredModelMBean class.</descript>
      <descript source="nvd">Per http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

"Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"
</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA13-032A.html" source="CERT">TA13-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/858729" source="CERT-VN">VU#858729</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=906911" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=906911</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0247.html" source="REDHAT">RHSA-2013:0247</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0246.html" source="REDHAT">RHSA-2013:0246</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0245.html" source="REDHAT">RHSA-2013:0245</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0237.html" source="REDHAT">RHSA-2013:0237</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0236.html" source="REDHAT">RHSA-2013:0236</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">SSRT101184</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136733161405818&amp;w=2" source="HP">HPSBMU02874</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">HPSBUX02864</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136570436423916&amp;w=2" source="HP">SSRT101156</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">HPSBUX02857</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=136439120408139&amp;w=2" source="HP">SSRT101103</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html" source="SUSE">openSUSE-SU-2013:0377</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html" source="SUSE">openSUSE-SU-2013:0312</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/6e0d9f4942af" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/6e0d9f4942af</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers num="1.5.0" edition="update_36"/>
        <vers num="1.5.0" edition="update_38"/>
        <vers num="1.6.0" edition="update_22"/>
        <vers num="1.6.0" edition="update_23"/>
        <vers num="1.6.0" edition="update_24"/>
        <vers num="1.6.0" edition="update_25"/>
        <vers num="1.6.0" edition="update_26"/>
        <vers num="1.6.0" edition="update_27"/>
        <vers num="1.6.0" edition="update_29"/>
        <vers num="1.6.0" edition="update_30"/>
        <vers num="1.6.0" edition="update_31"/>
        <vers num="1.6.0" edition="update_32"/>
        <vers num="1.6.0" edition="update_33"/>
        <vers num="1.6.0" edition="update_34"/>
        <vers num="1.6.0" edition="update_35"/>
        <vers num="1.6.0" edition="update_37"/>
        <vers num="1.6.0" edition="update_38"/>
        <vers num="1.7.0" edition="update1"/>
        <vers num="1.7.0" edition="update10"/>
        <vers num="1.7.0" edition="update11"/>
        <vers num="1.7.0" edition="update2"/>
        <vers num="1.7.0" edition="update3"/>
        <vers num="1.7.0" edition="update4"/>
        <vers num="1.7.0" edition="update5"/>
        <vers num="1.7.0" edition="update6"/>
        <vers num="1.7.0" edition="update7"/>
        <vers num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0452" published="2013-03-29" name="CVE-2013-0452" modified="2013-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the Software Use Analysis (SUA) application before 1.3.3 in IBM Tivoli Endpoint Manager 8.2 allows remote attackers to hijack the authentication of arbitrary users via a web site that contains crafted Flash Action Message Format (AMF) messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/80968" source="XF">tem-sua-csrf(80968)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21631350" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21631350</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IV38145" source="AIXAPAR">IV38145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="software_use_analysis">
        <vers prev="1" num="1.3.2"/>
      </prod>
      <prod vendor="ibm" name="tivoli_endpoint_manager">
        <vers num="8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0453" published="2013-03-21" name="CVE-2013-0453" modified="2013-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Web Reports in IBM Tivoli Endpoint Manager (TEM) before 8.2.1372 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/80969" source="XF">tem-web-reports-xss(80969)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg21631351" source="CONFIRM" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21631351</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IV37766" source="AIXAPAR">IV37766</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_endpoint_manager">
        <vers num="8.0"/>
        <vers num="8.1"/>
        <vers prev="1" num="8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0454" published="2013-03-26" name="CVE-2013-0454" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.samba.org/samba/security/CVE-2013-0454" source="CONFIRM">https://www.samba.org/samba/security/CVE-2013-0454</ref>
      <ref url="https://lists.samba.org/archive/samba-announce/2012/000259.html" source="MLIST">[samba-announce] 20120625 [Announce] Samba 3.6.6 Available for Download</ref>
      <ref url="https://bugzilla.samba.org/show_bug.cgi?id=8738" source="MISC">https://bugzilla.samba.org/show_bug.cgi?id=8738</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=928419" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=928419</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/80970" source="XF">storwize-cifs-incorrect-permissions(80970)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1802-1" source="UBUNTU">USN-1802-1</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=ssg1S1004289" source="CONFIRM" adv="1">http://www.ibm.com/support/docview.wss?uid=ssg1S1004289</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="storwize">
        <vers num="v7000" edition="1.3"/>
        <vers num="v7000" edition="1.4"/>
      </prod>
      <prod vendor="samba" name="samba">
        <vers num="1.9.17" edition="p1"/>
        <vers num="1.9.17" edition="p2"/>
        <vers num="1.9.17" edition="p3"/>
        <vers num="1.9.17" edition="p4"/>
        <vers num="1.9.17" edition="p5"/>
        <vers num="1.9.18" edition="p1"/>
        <vers num="1.9.18" edition="p10"/>
        <vers num="1.9.18" edition="p2"/>
        <vers num="1.9.18" edition="p3"/>
        <vers num="1.9.18" edition="p4"/>
        <vers num="1.9.18" edition="p5"/>
        <vers num="1.9.18" edition="p6"/>
        <vers num="1.9.18" edition="p7"/>
        <vers num="1.9.18" edition="p8"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5" edition="a"/>
        <vers num="2.0.5a"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.18.3"/>
        <vers num="2.2" edition="a"/>
        <vers num="2.2.0" edition="a"/>
        <vers num="2.2.0a"/>
        <vers num="2.2.1" edition="a"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.1a"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3" edition="a"/>
        <vers num="2.2.3a"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7" edition="a"/>
        <vers num="2.2.7a"/>
        <vers num="2.2.8" edition="a"/>
        <vers num="2.2.8a"/>
        <vers num="2.2.9"/>
        <vers num="2.2a"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14" edition="a"/>
        <vers num="3.0.14a"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2" edition="a"/>
        <vers num="3.0.20" edition="a"/>
        <vers num="3.0.20" edition="b"/>
        <vers num="3.0.20a"/>
        <vers num="3.0.20b"/>
        <vers num="3.0.21" edition="a"/>
        <vers num="3.0.21" edition="b"/>
        <vers num="3.0.21" edition="c"/>
        <vers num="3.0.21a"/>
        <vers num="3.0.21b"/>
        <vers num="3.0.21c"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23" edition="a"/>
        <vers num="3.0.23" edition="b"/>
        <vers num="3.0.23" edition="c"/>
        <vers num="3.0.23" edition="d"/>
        <vers num="3.0.23a"/>
        <vers num="3.0.23b"/>
        <vers num="3.0.23c"/>
        <vers num="3.0.23d"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25" edition="a"/>
        <vers num="3.0.25" edition="b"/>
        <vers num="3.0.25" edition="c"/>
        <vers num="3.0.25" edition="pre1"/>
        <vers num="3.0.25" edition="pre2"/>
        <vers num="3.0.25" edition="rc1"/>
        <vers num="3.0.25" edition="rc2"/>
        <vers num="3.0.25" edition="rc3"/>
        <vers num="3.0.25a"/>
        <vers num="3.0.25b"/>
        <vers num="3.0.25c"/>
        <vers num="3.0.26" edition="a"/>
        <vers num="3.0.26a"/>
        <vers num="3.0.27" edition="a"/>
        <vers num="3.0.28" edition="a"/>
        <vers num="3.0.29"/>
        <vers num="3.0.2a"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.4" edition="rc1"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.10"/>
        <vers num="3.3.11"/>
        <vers num="3.3.12"/>
        <vers num="3.3.13"/>
        <vers num="3.3.14"/>
        <vers num="3.3.15"/>
        <vers num="3.3.16"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.3.9"/>
        <vers num="3.4.0"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.0"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.19"/>
        <vers num="3.5.2"/>
        <vers num="3.5.20"/>
        <vers num="3.5.21"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers prev="1" num="3.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0457" published="2013-02-20" name="CVE-2013-0457" modified="2013-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a uisessionid.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81011" source="XF">mam-uisessionid-xss(81011)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21625624" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21625624</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IV20590" source="AIXAPAR">IV20590</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="maximo_asset_management">
        <vers num="7.5.0.0"/>
      </prod>
      <prod vendor="ibm" name="maximo_asset_management_essentials">
        <vers num="7.5.0.0"/>
      </prod>
      <prod vendor="ibm" name="smartcloud_control_desk">
        <vers num="7.5.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0458" published="2013-01-27" name="CVE-2013-0458" modified="2013-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2, when login security is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81012" source="XF">was-admin-login-xss(81012)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg21622444" source="CONFIRM" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21622444</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM71139" source="AIXAPAR">PM71139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.11"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.13"/>
        <vers num="6.1.0.14"/>
        <vers num="6.1.0.15"/>
        <vers num="6.1.0.17"/>
        <vers num="6.1.0.19"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.21"/>
        <vers num="6.1.0.23"/>
        <vers num="6.1.0.25"/>
        <vers num="6.1.0.27"/>
        <vers num="6.1.0.29"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.31"/>
        <vers num="6.1.0.33"/>
        <vers num="6.1.0.35"/>
        <vers num="6.1.0.37"/>
        <vers num="6.1.0.39"/>
        <vers num="6.1.0.41"/>
        <vers num="6.1.0.43"/>
        <vers num="6.1.0.45"/>
        <vers num="6.1.0.5"/>
        <vers num="6.1.0.7"/>
        <vers num="6.1.0.9"/>
        <vers num="7.0"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.15"/>
        <vers num="7.0.0.17"/>
        <vers num="7.0.0.19"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.21"/>
        <vers num="7.0.0.23"/>
        <vers num="7.0.0.25"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.9"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.0.3"/>
        <vers num="8.0.0.4"/>
        <vers num="8.0.0.5"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0459" published="2013-01-27" name="CVE-2013-0459" modified="2013-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81013" source="XF">was-admin-type-xss(81013)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg21622444" source="CONFIRM" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21622444</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM72536" source="AIXAPAR">PM72536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.11"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.13"/>
        <vers num="6.1.0.14"/>
        <vers num="6.1.0.15"/>
        <vers num="6.1.0.17"/>
        <vers num="6.1.0.19"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.21"/>
        <vers num="6.1.0.23"/>
        <vers num="6.1.0.25"/>
        <vers num="6.1.0.27"/>
        <vers num="6.1.0.29"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.31"/>
        <vers num="6.1.0.33"/>
        <vers num="6.1.0.35"/>
        <vers num="6.1.0.37"/>
        <vers num="6.1.0.39"/>
        <vers num="6.1.0.41"/>
        <vers num="6.1.0.43"/>
        <vers num="6.1.0.45"/>
        <vers num="6.1.0.5"/>
        <vers num="6.1.0.7"/>
        <vers num="6.1.0.9"/>
        <vers num="7.0"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.15"/>
        <vers num="7.0.0.17"/>
        <vers num="7.0.0.19"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.21"/>
        <vers num="7.0.0.23"/>
        <vers num="7.0.0.25"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.9"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.0.3"/>
        <vers num="8.0.0.4"/>
        <vers num="8.0.0.5"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0460" published="2013-01-27" name="CVE-2013-0460" modified="2013-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 and 7.0 before 7.0.0.27 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81014" source="XF">was-admin-portlet-csrf(81014)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg21622444" source="CONFIRM" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21622444</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM72275" source="AIXAPAR">PM72275</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.11"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.13"/>
        <vers num="6.1.0.14"/>
        <vers num="6.1.0.15"/>
        <vers num="6.1.0.17"/>
        <vers num="6.1.0.19"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.21"/>
        <vers num="6.1.0.23"/>
        <vers num="6.1.0.25"/>
        <vers num="6.1.0.27"/>
        <vers num="6.1.0.29"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.31"/>
        <vers num="6.1.0.33"/>
        <vers num="6.1.0.35"/>
        <vers num="6.1.0.37"/>
        <vers num="6.1.0.39"/>
        <vers num="6.1.0.41"/>
        <vers num="6.1.0.43"/>
        <vers num="6.1.0.45"/>
        <vers num="6.1.0.5"/>
        <vers num="6.1.0.7"/>
        <vers num="6.1.0.9"/>
        <vers num="7.0"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.15"/>
        <vers num="7.0.0.17"/>
        <vers num="7.0.0.19"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.21"/>
        <vers num="7.0.0.23"/>
        <vers num="7.0.0.25"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0461" published="2013-01-27" name="CVE-2013-0461" modified="2013-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the virtual member manager (VMM) administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81015" source="XF">was-admin-vmm-xss(81015)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg21622444" source="CONFIRM" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21622444</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM71389" source="AIXAPAR">PM71389</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.11"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.13"/>
        <vers num="6.1.0.14"/>
        <vers num="6.1.0.15"/>
        <vers num="6.1.0.17"/>
        <vers num="6.1.0.19"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.21"/>
        <vers num="6.1.0.23"/>
        <vers num="6.1.0.25"/>
        <vers num="6.1.0.27"/>
        <vers num="6.1.0.29"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.31"/>
        <vers num="6.1.0.33"/>
        <vers num="6.1.0.35"/>
        <vers num="6.1.0.37"/>
        <vers num="6.1.0.39"/>
        <vers num="6.1.0.41"/>
        <vers num="6.1.0.43"/>
        <vers num="6.1.0.45"/>
        <vers num="6.1.0.5"/>
        <vers num="6.1.0.7"/>
        <vers num="6.1.0.9"/>
        <vers num="7.0"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.15"/>
        <vers num="7.0.0.17"/>
        <vers num="7.0.0.19"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.21"/>
        <vers num="7.0.0.23"/>
        <vers num="7.0.0.25"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.9"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.0.3"/>
        <vers num="8.0.0.4"/>
        <vers num="8.0.0.5"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0462" published="2013-01-27" name="CVE-2013-0462" modified="2013-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1, 7.0 before 7.0.0.27, 8.0, and 8.5 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ibm.com/connections/blogs/PSIRT/entry/security_vulnerabilities_fixed_in_ibm_websphere_application_server_7_0_0_2785" source="CONFIRM" adv="1">http://www.ibm.com/connections/blogs/PSIRT/entry/security_vulnerabilities_fixed_in_ibm_websphere_application_server_7_0_0_2785</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0.0"/>
        <vers num="7.0"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.15"/>
        <vers num="7.0.0.17"/>
        <vers num="7.0.0.19"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.21"/>
        <vers num="7.0.0.23"/>
        <vers num="7.0.0.25"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.9"/>
        <vers num="8.0.0.0"/>
        <vers num="8.5.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0464" published="2013-06-03" name="CVE-2013-0464" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in IBM Eclipse Help System (IEHS) 3.4.3 and 3.6.2, as used in IBM SPSS Data Collection 6.0, 6.0.1, and 7.0, allow remote attackers to inject arbitrary web script or HTML via a crafted URL.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81060" source="XF">iehs-cve20130464-xss(81060)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21637954" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21637954</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="eclipse_help_system">
        <vers num="3.4.3"/>
        <vers num="3.6.2"/>
      </prod>
      <prod vendor="ibm" name="spss_data_collection">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0465" published="2013-02-22" name="CVE-2013-0465" modified="2013-03-04" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="5.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="5.5" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the IBM WebSphere Cast Iron physical and virtual appliance 6.0 and 6.1 before 6.1.0.15 and 6.3 before 6.3.0.1, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21623324" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21623324</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/81061" source="XF">was-castiron-security-bypass(81061)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1LI77155" source="AIXAPAR">LI77155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="webshere_cast_iron_cloud_integration">
        <vers num="6.0.0.0"/>
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.6"/>
        <vers num="6.1.0.9"/>
        <vers num="6.3.0.0"/>
      </prod>
      <prod vendor="ibm" name="webshere_cast_iron_cloud_integration">
        <vers num="6.0.0.0"/>
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.6"/>
        <vers num="6.1.0.9"/>
        <vers num="6.3.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0466" published="2013-02-20" name="CVE-2013-0466" modified="2013-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM WebSphere Message Broker 7.0 before 7.0.0.6 and 8.0 before 8.0.0.2, when wsdl support is enabled on a SOAPInput node, allows remote attackers to inject arbitrary web script or HTML via a wsdl request that is not properly handled during construction of an error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81062" source="XF">wmb-wsdl-xss(81062)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21623316" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21623316</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC89383" source="AIXAPAR">IC89383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_message_broker">
        <vers num="7.0."/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.4"/>
        <vers num="7.0.0.5"/>
        <vers num="8.0"/>
        <vers num="8.0.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0467" published="2013-02-20" name="CVE-2013-0467" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">IBM Eclipse Help System (IEHS), as used in IBM Data Studio 3.1 and 3.1.1 and other products, allows remote authenticated users to read source code via a crafted URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81102" source="XF" adv="1">iehs-source-disclosure(81102)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21625573" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21625573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="data_studio">
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0470" published="2013-04-05" name="CVE-2013-0470" modified="2013-04-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">HTTPD in IBM Netezza Performance Portal 1.0.2 allows remote authenticated users to list application directories containing asset files via a direct request to a directory URI, as demonstrated by listing image files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81336" source="XF">netezza-cve20130470-info-disclosure(81336)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21631945" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21631945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="netezza_performance_portal">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0471" published="2013-02-20" name="CVE-2013-0471" modified="2013-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The traditional scheduler in the client in IBM Tivoli Storage Manager (TSM) before 6.2.5.0, 6.3 before 6.3.1.0, and 6.4 before 6.4.0.1, when Prompted mode is enabled, allows remote attackers to cause a denial of service (scheduling outage) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81215" source="XF">tsm-scheduler-dos(81215)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21624135" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21624135</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC87331" source="AIXAPAR">IC87331</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_storage_manager">
        <vers num="3.1.0"/>
        <vers num="3.2.1"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.5"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.2"/>
        <vers num="5.2.0"/>
        <vers num="5.2.1"/>
        <vers num="5.2.2"/>
        <vers num="5.2.4"/>
        <vers num="5.2.5.1"/>
        <vers num="5.2.5.2"/>
        <vers num="5.2.5.3"/>
        <vers num="5.2.7"/>
        <vers num="5.2.8"/>
        <vers num="5.2.9"/>
        <vers num="5.3"/>
        <vers num="5.3.0"/>
        <vers num="5.3.1"/>
        <vers num="5.3.2"/>
        <vers num="5.3.2.4"/>
        <vers num="5.3.3"/>
        <vers num="5.3.4"/>
        <vers num="5.3.5.1"/>
        <vers num="5.3.6.1"/>
        <vers num="5.3.6.2"/>
        <vers num="5.3.6.3"/>
        <vers num="5.3.6.4"/>
        <vers num="5.3.6.5"/>
        <vers num="5.3.6.6"/>
        <vers num="5.4"/>
        <vers num="5.4.0"/>
        <vers num="5.4.1"/>
        <vers num="5.4.2"/>
        <vers num="5.4.2.2"/>
        <vers num="5.4.2.3"/>
        <vers num="5.4.2.4"/>
        <vers num="5.4.3.0"/>
        <vers num="5.4.3.2"/>
        <vers num="5.4.3.3"/>
        <vers num="5.4.4.0"/>
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="6.0"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.1.2"/>
        <vers num="6.1.3"/>
        <vers num="6.2.0"/>
        <vers num="6.2.0.0"/>
        <vers num="6.2.1"/>
        <vers prev="1" num="6.2.4.4"/>
        <vers num="6.3.0.0"/>
        <vers num="6.4.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0472" published="2013-02-20" name="CVE-2013-0472" modified="2013-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Web GUI in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.1.0 and 6.4 before 6.4.0.1 allows man-in-the-middle attackers to obtain unspecified client access, and consequently obtain unspecified server access, via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21624118" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21624118</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/81216" source="XF">tsm-gui-unauth-access(81216)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC87210" source="AIXAPAR">IC87210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_storage_manager">
        <vers num="3.1.0"/>
        <vers num="3.2.1"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.2.4"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.5"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.2"/>
        <vers num="5.2.0"/>
        <vers num="5.2.1"/>
        <vers num="5.2.2"/>
        <vers num="5.2.4"/>
        <vers num="5.2.5.1"/>
        <vers num="5.2.5.2"/>
        <vers num="5.2.5.3"/>
        <vers num="5.2.7"/>
        <vers num="5.2.8"/>
        <vers num="5.2.9"/>
        <vers num="5.3"/>
        <vers num="5.3.0"/>
        <vers num="5.3.1"/>
        <vers num="5.3.2"/>
        <vers num="5.3.2.4"/>
        <vers num="5.3.3"/>
        <vers num="5.3.4"/>
        <vers num="5.3.5.1"/>
        <vers num="5.3.6.1"/>
        <vers num="5.3.6.2"/>
        <vers num="5.3.6.3"/>
        <vers num="5.3.6.4"/>
        <vers num="5.3.6.5"/>
        <vers num="5.3.6.6"/>
        <vers num="5.4"/>
        <vers num="5.4.0"/>
        <vers num="5.4.1"/>
        <vers num="5.4.2"/>
        <vers num="5.4.2.2"/>
        <vers num="5.4.2.3"/>
        <vers num="5.4.2.4"/>
        <vers num="5.4.3.0"/>
        <vers num="5.4.3.2"/>
        <vers num="5.4.3.3"/>
        <vers num="5.4.4.0"/>
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.2"/>
        <vers num="6.0"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.1.2"/>
        <vers num="6.1.3"/>
        <vers num="6.2.0"/>
        <vers num="6.2.0.0"/>
        <vers num="6.2.1"/>
        <vers prev="1" num="6.2.4.4"/>
        <vers num="6.3.0.0"/>
        <vers num="6.4.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0473" published="2013-03-29" name="CVE-2013-0473" modified="2013-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allow remote attackers to inject arbitrary web script or HTML via a crafted report.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81337" source="XF">appscan-cve20130473-xss(81337)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21631304" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21631304</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21626264" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21626264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="rational_policy_tester">
        <vers num="5.6.0.0"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.1.0"/>
        <vers num="8.0.1.1"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.0.2"/>
        <vers num="8.5.0.3"/>
      </prod>
      <prod vendor="ibm" name="security_appscan">
        <vers num="5.6.0.0" edition="-"/>
        <vers num="5.6.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.0" edition="-"/>
        <vers num="8.0.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.1" edition="-"/>
        <vers num="8.0.0.1" edition="-:enterprise"/>
        <vers num="8.0.0.2" edition="-"/>
        <vers num="8.0.0.2" edition="-:enterprise"/>
        <vers num="8.0.1.0" edition="-"/>
        <vers num="8.0.1.0" edition="-:enterprise"/>
        <vers num="8.0.1.1" edition="-"/>
        <vers num="8.0.1.1" edition="-:enterprise"/>
        <vers num="8.0.11" edition="-"/>
        <vers num="8.0.11" edition="-:enterprise"/>
        <vers num="8.5.0.0" edition="-"/>
        <vers num="8.5.0.0" edition="-:enterprise"/>
        <vers num="8.5.0.1" edition="-"/>
        <vers num="8.5.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.0" edition="-"/>
        <vers num="8.6.0.0" edition="-:enterprise"/>
        <vers num="8.6.0.1" edition="-"/>
        <vers num="8.6.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.2" edition="-"/>
        <vers num="8.6.0.2" edition="-:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0474" published="2013-03-29" name="CVE-2013-0474" modified="2013-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Manual Explore browser plug-in in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to discover test Platform Authentication credentials via a crafted web site.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81338" source="XF">appscan-manual-explore-csrf(81338)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21631304" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21631304</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21626264" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21626264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="rational_policy_tester">
        <vers num="5.6.0.0"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.1.0"/>
        <vers num="8.0.1.1"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.0.2"/>
        <vers num="8.5.0.3"/>
      </prod>
      <prod vendor="ibm" name="security_appscan">
        <vers num="5.6.0.0" edition="-"/>
        <vers num="5.6.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.0" edition="-"/>
        <vers num="8.0.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.1" edition="-"/>
        <vers num="8.0.0.1" edition="-:enterprise"/>
        <vers num="8.0.0.2" edition="-"/>
        <vers num="8.0.0.2" edition="-:enterprise"/>
        <vers num="8.0.1.0" edition="-"/>
        <vers num="8.0.1.0" edition="-:enterprise"/>
        <vers num="8.0.1.1" edition="-"/>
        <vers num="8.0.1.1" edition="-:enterprise"/>
        <vers num="8.0.11" edition="-"/>
        <vers num="8.0.11" edition="-:enterprise"/>
        <vers num="8.5.0.0" edition="-"/>
        <vers num="8.5.0.0" edition="-:enterprise"/>
        <vers num="8.5.0.1" edition="-"/>
        <vers num="8.5.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.0" edition="-"/>
        <vers num="8.6.0.0" edition="-:enterprise"/>
        <vers num="8.6.0.1" edition="-"/>
        <vers num="8.6.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.2" edition="-"/>
        <vers num="8.6.0.2" edition="-:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0477" published="2013-02-20" name="CVE-2013-0477" modified="2013-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allow remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81481" source="XF">mdm-web-content-spoofing(81481)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21624952" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21624952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="infosphere_master_data_management_collaboration_server">
        <vers num="10.0.0"/>
        <vers num="10.0.1"/>
      </prod>
      <prod vendor="ibm" name="infosphere_master_data_management_server_for_product_information_management">
        <vers num="6.0.0"/>
        <vers num="9.0.0"/>
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0478" published="2013-02-20" name="CVE-2013-0478" modified="2013-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81482" source="XF">mdm-web-xss(81482)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21624952" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21624952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="infosphere_master_data_management_collaboration_server">
        <vers num="10.0.0"/>
        <vers num="10.0.1"/>
      </prod>
      <prod vendor="ibm" name="infosphere_master_data_management_server_for_product_information_management">
        <vers num="6.0.0"/>
        <vers num="9.0.0"/>
        <vers num="9.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0482" published="2013-05-29" name="CVE-2013-0482" modified="2013-05-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the signatures of messages via a crafted SOAP message, related to a "Signature Wrap attack," a different vulnerability than CVE-2011-1377 and CVE-2013-0489.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81548" source="XF">was-wssecurity-spoofing(81548)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21635474" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21635474</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21634646" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21634646</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM86026" source="AIXAPAR">PM86026</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM76582" source="AIXAPAR">PM76582</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC88185" source="AIXAPAR">IC88185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="7.0"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.10"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.12"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.14"/>
        <vers num="7.0.0.15"/>
        <vers num="7.0.0.16"/>
        <vers num="7.0.0.17"/>
        <vers num="7.0.0.18"/>
        <vers num="7.0.0.19"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.21"/>
        <vers num="7.0.0.22"/>
        <vers num="7.0.0.23"/>
        <vers num="7.0.0.24"/>
        <vers num="7.0.0.25"/>
        <vers num="7.0.0.27"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.4"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.6"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.8"/>
        <vers num="7.0.0.9"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.0.3"/>
        <vers num="8.0.0.4"/>
        <vers num="8.0.0.5"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
      </prod>
      <prod vendor="ibm" name="websphere_message_broker">
        <vers num="6.1"/>
        <vers num="7.0."/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.4"/>
        <vers num="7.0.0.5"/>
        <vers num="8.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0483" published="2013-04-05" name="CVE-2013-0483" modified="2013-04-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The login component in SOAP Gateway in IBM IMS Enterprise Suite 1.1, 2.1, and 2.2 uses cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81533" source="XF">ims-insecure-login(81533)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21631537" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21631537</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="ims_enterprise_suite">
        <vers num="1.1"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0486" published="2013-03-27" name="CVE-2013-0486" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Memory leak in the HTTP server in IBM Domino 8.5.x allows remote attackers to cause a denial of service (memory consumption and daemon crash) via GET requests, aka SPR KLYH92NKZY.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81812" source="XF">domino-get-dos(81812)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21627597" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21627597</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-000030.html" source="JVNDB">JVNDB-2013-000030</ref>
      <ref url="http://jvn.jp/en/jp/JVN51305555/index.html" source="JVN">JVN#51305555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="8.5.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.1"/>
        <vers num="8.5.1.2"/>
        <vers num="8.5.1.3"/>
        <vers num="8.5.1.4"/>
        <vers num="8.5.1.5"/>
        <vers num="8.5.2.0"/>
        <vers num="8.5.2.1"/>
        <vers num="8.5.2.2"/>
        <vers num="8.5.2.3"/>
        <vers num="8.5.2.4"/>
        <vers num="8.5.3.0"/>
        <vers num="8.5.3.1"/>
        <vers num="8.5.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0487" published="2013-03-27" name="CVE-2013-0487" modified="2013-03-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentials by leveraging knowledge of configuration details, aka SPR KLYH8TNNDN.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81852" source="XF">domino-controller-auth-bypass(81852)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21627597" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21627597</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="8.5.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.1"/>
        <vers num="8.5.1.2"/>
        <vers num="8.5.1.3"/>
        <vers num="8.5.1.4"/>
        <vers num="8.5.1.5"/>
        <vers num="8.5.2.0"/>
        <vers num="8.5.2.1"/>
        <vers num="8.5.2.2"/>
        <vers num="8.5.2.3"/>
        <vers num="8.5.2.4"/>
        <vers num="8.5.3.0"/>
        <vers num="8.5.3.1"/>
        <vers num="8.5.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0488" published="2013-03-27" name="CVE-2013-0488" modified="2013-03-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81853" source="XF">domino-webadmin-xss(81853)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21627597" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21627597</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="8.5.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.1"/>
        <vers num="8.5.1.2"/>
        <vers num="8.5.1.3"/>
        <vers num="8.5.1.4"/>
        <vers num="8.5.1.5"/>
        <vers num="8.5.2.0"/>
        <vers num="8.5.2.1"/>
        <vers num="8.5.2.2"/>
        <vers num="8.5.2.3"/>
        <vers num="8.5.2.4"/>
        <vers num="8.5.3.0"/>
        <vers num="8.5.3.1"/>
        <vers num="8.5.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0489" published="2013-03-27" name="CVE-2013-0489" modified="2013-03-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote authenticated users to hijack the authentication of administrators.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81854" source="XF">domino-webadmin-csrf(81854)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21627597" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21627597</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="8.5.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.1"/>
        <vers num="8.5.1.2"/>
        <vers num="8.5.1.3"/>
        <vers num="8.5.1.4"/>
        <vers num="8.5.1.5"/>
        <vers num="8.5.2.0"/>
        <vers num="8.5.2.1"/>
        <vers num="8.5.2.2"/>
        <vers num="8.5.2.3"/>
        <vers num="8.5.2.4"/>
        <vers num="8.5.3.0"/>
        <vers num="8.5.3.1"/>
        <vers num="8.5.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0490" published="2013-02-27" name="CVE-2013-0490" modified="2013-02-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM InfoSphere Guardium S-TAP 8.1 for DB2 on z/OS allows local users to gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81948" source="XF">ibm-zos-priv-esc(81948)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21626276" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21626276</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="infosphere_guardium">
        <vers num="8.00" edition="-"/>
        <vers num="8.00" edition="-:~~~z/os~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0499" published="2013-05-28" name="CVE-2013-0499" modified="2013-05-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web Token services.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20130523-0_IBM_Xi50_Echo-WebService_Xss_in_Xml_v10.txt" source="MISC">https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20130523-0_IBM_Xi50_Echo-WebService_Xss_in_Xml_v10.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/82221" source="XF">was-datapower-echo-xss(82221)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21637717" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21637717</ref>
      <ref url="http://seclists.org/bugtraq/2013/May/83" source="BUGTRAQ">20130523 SEC Consult SA-20130523-0 :: JavaScript Execution in IBM WebSphere DataPower Services</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_datapower_b2b_appliance_xb62">
        <vers num="-"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_integration_appliance_xi50">
        <vers num="-"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_integration_appliance_xi52">
        <vers num="-"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_integration_appliance_xi52_virtual_edition">
        <vers num="-"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_service_gateway_xg45">
        <vers num="-"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_service_gateway_xg45_virtual_edition">
        <vers num="-"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_xc10_appliance">
        <vers num="-"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_b2b_appliance_xb62_firmware">
        <vers num="3.8.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="5.0.0"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_integration_appliance_xi50_firmware">
        <vers num="3.8.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="5.0.0"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_integration_appliance_xi52_firmware">
        <vers num="3.8.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="5.0.0"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_integration_appliance_xi52_virtual_edition_firmware">
        <vers num="3.8.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="5.0.0"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_service_gateway_xg45_firmware">
        <vers num="3.8.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="5.0.0"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_service_gateway_xg45_virtual_edition_firmware">
        <vers num="3.8.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="5.0.0"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_xc10_appliance_firmware">
        <vers num="3.8.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="5.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0501" published="2013-04-12" name="CVE-2013-0501" modified="2013-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82345" source="XF">cdm-edrawsoft-activex(82345)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg21627070" source="CONFIRM" adv="1">http://www.ibm.com/support/docview.wss?uid=swg21627070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="cognos_disclosure_management">
        <vers num="10.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0502" published="2013-04-01" name="CVE-2013-0502" modified="2013-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server 8.1, 8.5 through FP3, 8.7 through FP2, and 9.1 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82233" source="XF">infosphere-web-console-xss(82233)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21632556" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21632556</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1JR45274" source="AIXAPAR">JR45274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="infosphere_information_server">
        <vers num="8.1"/>
        <vers num="8.5"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.0.2"/>
        <vers num="8.5.0.3"/>
        <vers num="8.7"/>
        <vers num="8.7.0.1"/>
        <vers num="8.7.0.2"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0503" published="2013-04-23" name="CVE-2013-0503" modified="2013-04-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Bookmarks component in IBM Lotus Connections before 4.0 CR3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82265" source="XF">lotus-connections-reflected-xss(82265)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21634538" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21634538</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1LO74182" source="AIXAPAR">LO74182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_connections">
        <vers num="1.0.0.0"/>
        <vers num="1.0.1.0"/>
        <vers num="1.0.2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.1.0"/>
        <vers num="2.0.1.1"/>
        <vers num="2.5.0.1"/>
        <vers num="2.5.0.2"/>
        <vers num="2.5.0.3"/>
        <vers num="3.0.0.0"/>
        <vers num="3.0.1.0"/>
        <vers num="3.0.1.1"/>
        <vers prev="1" num="4.0.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0504" published="2013-02-26" name="CVE-2013-0504" modified="2013-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the broker service in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb13-08.html

'Flash Player 11.6.602.168 and earlier versions for Windows 
Flash Player 11.6.602.167 and earlier versions for Macintosh
Flash Player 11.2.202.270 and earlier for Linux'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb13-08.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb13-08.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0574.html" source="REDHAT">RHSA-2013:0574</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00035.html" source="SUSE">SUSE-SU-2013:0373</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00026.html" source="SUSE">openSUSE-SU-2013:0360</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00025.html" source="SUSE">openSUSE-SU-2013:0359</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="flash_player">
        <vers num="10.0.0.584"/>
        <vers num="10.0.12.10"/>
        <vers num="10.0.12.36"/>
        <vers num="10.0.15.3"/>
        <vers num="10.0.2.54"/>
        <vers num="10.0.22.87"/>
        <vers num="10.0.32.18"/>
        <vers num="10.0.42.34"/>
        <vers num="10.0.45.2"/>
        <vers num="10.1"/>
        <vers num="10.1.102.64"/>
        <vers num="10.1.105.6"/>
        <vers num="10.1.106.16"/>
        <vers num="10.1.106.17"/>
        <vers num="10.1.52.14"/>
        <vers num="10.1.52.14.1"/>
        <vers num="10.1.52.15"/>
        <vers num="10.1.53.64"/>
        <vers num="10.1.82.76"/>
        <vers num="10.1.85.3"/>
        <vers num="10.1.92.10"/>
        <vers num="10.1.92.8"/>
        <vers num="10.1.95.1"/>
        <vers num="10.1.95.2"/>
        <vers num="10.2.152"/>
        <vers num="10.2.152.26"/>
        <vers num="10.2.152.32"/>
        <vers num="10.2.152.33"/>
        <vers num="10.2.153.1"/>
        <vers num="10.2.154.13"/>
        <vers num="10.2.154.25"/>
        <vers num="10.2.156.12"/>
        <vers num="10.2.157.51"/>
        <vers num="10.2.159.1"/>
        <vers num="10.3.181.14"/>
        <vers num="10.3.181.16"/>
        <vers num="10.3.181.22"/>
        <vers num="10.3.181.23"/>
        <vers num="10.3.181.26"/>
        <vers num="10.3.181.34"/>
        <vers num="10.3.183.10"/>
        <vers num="10.3.183.11"/>
        <vers num="10.3.183.15"/>
        <vers num="10.3.183.16"/>
        <vers num="10.3.183.18"/>
        <vers num="10.3.183.19"/>
        <vers num="10.3.183.20"/>
        <vers num="10.3.183.23"/>
        <vers num="10.3.183.25"/>
        <vers num="10.3.183.29"/>
        <vers num="10.3.183.43"/>
        <vers num="10.3.183.48"/>
        <vers num="10.3.183.5"/>
        <vers num="10.3.183.50"/>
        <vers num="10.3.183.51"/>
        <vers prev="1" num="10.3.183.61"/>
        <vers prev="1" num="10.3.183.63"/>
        <vers num="10.3.183.7"/>
        <vers num="10.3.185.22"/>
        <vers num="10.3.185.24"/>
        <vers num="10.3.186.3"/>
        <vers num="10.3.186.6"/>
        <vers num="10.3.186.7"/>
        <vers num="11.0"/>
        <vers num="11.0.1.152"/>
        <vers num="11.0.1.153"/>
        <vers num="11.1"/>
        <vers num="11.1.102.55"/>
        <vers num="11.1.102.59"/>
        <vers num="11.1.102.62"/>
        <vers num="11.1.102.63"/>
        <vers num="11.1.111.8"/>
        <vers num="11.1.115.34"/>
        <vers num="11.1.115.7"/>
        <vers num="11.2.202.223"/>
        <vers num="11.2.202.228"/>
        <vers num="11.2.202.233"/>
        <vers num="11.2.202.235"/>
        <vers num="11.2.202.236"/>
        <vers num="11.2.202.238"/>
        <vers num="11.2.202.243"/>
        <vers num="11.2.202.251"/>
        <vers num="11.2.202.258"/>
        <vers num="11.2.202.261"/>
        <vers num="11.2.202.262"/>
        <vers prev="1" num="11.2.202.270"/>
        <vers num="11.3.300.257"/>
        <vers num="11.3.300.262"/>
        <vers num="11.3.300.265"/>
        <vers num="11.3.300.268"/>
        <vers num="11.3.300.270"/>
        <vers num="11.3.300.271"/>
        <vers num="11.3.300.273"/>
        <vers num="11.4.402.265"/>
        <vers num="11.4.402.278"/>
        <vers num="11.4.402.287"/>
        <vers num="11.5.502.110"/>
        <vers num="11.5.502.135"/>
        <vers num="11.5.502.136"/>
        <vers num="11.5.502.146"/>
        <vers num="11.5.502.149"/>
        <vers prev="1" num="11.6.602.167"/>
        <vers prev="1" num="11.6.602.168"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0505" published="2013-03-19" name="CVE-2013-0505" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82339" source="XF">sterling-om-xpath-injection(82339)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21631302" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21631302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="sterling_multi-channel_fulfillment_solution">
        <vers num="8.0"/>
      </prod>
      <prod vendor="ibm" name="sterling_selling_and_fulfillment_foundation">
        <vers num="8.5"/>
        <vers num="9.0"/>
        <vers num="9.1.0"/>
        <vers num="9.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0506" published="2013-03-19" name="CVE-2013-0506" modified="2013-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82341" source="XF">sterling-om-address-xss(82341)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21631302" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21631302</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC90858" source="AIXAPAR">IC90858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="sterling_multi-channel_fulfillment_solution">
        <vers num="8.0"/>
      </prod>
      <prod vendor="ibm" name="sterling_selling_and_fulfillment_foundation">
        <vers num="8.5"/>
        <vers num="9.0"/>
        <vers num="9.1.0"/>
        <vers num="9.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0508" published="2013-06-04" name="CVE-2013-0508" modified="2013-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 and 4.0.1 before FP1 allow context-dependent attackers to execute arbitrary code or cause a denial of service via a long line in (1) hrfstable.idx, (2) hrdevice.idx, (3) hrstorage.idx, or (4) lotusmapfile in the SSM Config directory, or (5) .manifest.hive in the main agent directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82333" source="XF">netcool-cve20130508-config-bo(82333)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21638459" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21638459</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_netcool_application_service_monitors">
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
      </prod>
      <prod vendor="ibm" name="tivoli_netcool_system_service_monitors">
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0509" published="2013-06-04" name="CVE-2013-0509" modified="2013-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in the Transaction MIB agent in IBM Tivoli Netcool System Service Monitors (SSM) and Application Service Monitors (ASM) 4.0.0 before FP14 allows remote attackers to execute arbitrary code via a SQL transaction with a long table name that is not properly handled by a packet decoder.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82334" source="XF">netcool-cve20130509-mib-bo(82334)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21638183" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21638183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_netcool_application_service_monitors">
        <vers num="4.0.0"/>
      </prod>
      <prod vendor="ibm" name="tivoli_netcool_system_service_monitors">
        <vers num="4.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0510" published="2013-03-29" name="CVE-2013-0510" modified="2013-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 includes a security test that sends session cookies to a specific external server, which allows man-in-the-middle attackers to hijack the test account by capturing these cookies.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82592" source="XF">appscan-fwd-info-disclosure(82592)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21626264" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21626264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="security_appscan">
        <vers num="5.6.0.0" edition="-"/>
        <vers num="5.6.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.0" edition="-"/>
        <vers num="8.0.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.1" edition="-"/>
        <vers num="8.0.0.1" edition="-:enterprise"/>
        <vers num="8.0.0.2" edition="-"/>
        <vers num="8.0.0.2" edition="-:enterprise"/>
        <vers num="8.0.1.0" edition="-"/>
        <vers num="8.0.1.0" edition="-:enterprise"/>
        <vers num="8.0.1.1" edition="-"/>
        <vers num="8.0.1.1" edition="-:enterprise"/>
        <vers num="8.0.11" edition="-"/>
        <vers num="8.0.11" edition="-:enterprise"/>
        <vers num="8.5.0.0" edition="-"/>
        <vers num="8.5.0.0" edition="-:enterprise"/>
        <vers num="8.5.0.1" edition="-"/>
        <vers num="8.5.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.0" edition="-"/>
        <vers num="8.6.0.0" edition="-:enterprise"/>
        <vers num="8.6.0.1" edition="-"/>
        <vers num="8.6.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.2" edition="-"/>
        <vers num="8.6.0.2" edition="-:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0511" published="2013-03-29" name="CVE-2013-0511" modified="2013-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82344" source="XF">appscan-cve20130511-sql-injection(82344)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21626264" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21626264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="security_appscan">
        <vers num="5.6.0.0" edition="-"/>
        <vers num="5.6.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.0" edition="-"/>
        <vers num="8.0.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.1" edition="-"/>
        <vers num="8.0.0.1" edition="-:enterprise"/>
        <vers num="8.0.0.2" edition="-"/>
        <vers num="8.0.0.2" edition="-:enterprise"/>
        <vers num="8.0.1.0" edition="-"/>
        <vers num="8.0.1.0" edition="-:enterprise"/>
        <vers num="8.0.1.1" edition="-"/>
        <vers num="8.0.1.1" edition="-:enterprise"/>
        <vers num="8.0.11" edition="-"/>
        <vers num="8.0.11" edition="-:enterprise"/>
        <vers num="8.5.0.0" edition="-"/>
        <vers num="8.5.0.0" edition="-:enterprise"/>
        <vers num="8.5.0.1" edition="-"/>
        <vers num="8.5.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.0" edition="-"/>
        <vers num="8.6.0.0" edition="-:enterprise"/>
        <vers num="8.6.0.1" edition="-"/>
        <vers num="8.6.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.2" edition="-"/>
        <vers num="8.6.0.2" edition="-:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0512" published="2013-03-29" name="CVE-2013-0512" modified="2013-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Manual Explore browser plug-in for Firefox in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to cause a denial of service (plug-in crash) via a crafted web page.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82593" source="XF">appscan-fme-dos(82593)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21631304" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21631304</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21626264" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21626264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="rational_policy_tester">
        <vers num="5.6.0.0"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.1.0"/>
        <vers num="8.0.1.1"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.0.2"/>
        <vers num="8.5.0.3"/>
      </prod>
      <prod vendor="ibm" name="security_appscan">
        <vers num="5.6.0.0" edition="-"/>
        <vers num="5.6.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.0" edition="-"/>
        <vers num="8.0.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.1" edition="-"/>
        <vers num="8.0.0.1" edition="-:enterprise"/>
        <vers num="8.0.0.2" edition="-"/>
        <vers num="8.0.0.2" edition="-:enterprise"/>
        <vers num="8.0.1.0" edition="-"/>
        <vers num="8.0.1.0" edition="-:enterprise"/>
        <vers num="8.0.1.1" edition="-"/>
        <vers num="8.0.1.1" edition="-:enterprise"/>
        <vers num="8.0.11" edition="-"/>
        <vers num="8.0.11" edition="-:enterprise"/>
        <vers num="8.5.0.0" edition="-"/>
        <vers num="8.5.0.0" edition="-:enterprise"/>
        <vers num="8.5.0.1" edition="-"/>
        <vers num="8.5.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.0" edition="-"/>
        <vers num="8.6.0.0" edition="-:enterprise"/>
        <vers num="8.6.0.1" edition="-"/>
        <vers num="8.6.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.2" edition="-"/>
        <vers num="8.6.0.2" edition="-:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0513" published="2013-03-29" name="CVE-2013-0513" modified="2013-03-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 create a service that lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program, related to an "Unquoted Service Path Enumeration" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82594" source="XF">appscan-svc-path-priv-esc(82594)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21631304" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21631304</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21626264" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21626264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="rational_policy_tester">
        <vers num="5.6.0.0"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.1.0"/>
        <vers num="8.0.1.1"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.0.2"/>
        <vers num="8.5.0.3"/>
      </prod>
      <prod vendor="ibm" name="security_appscan">
        <vers num="5.6.0.0" edition="-"/>
        <vers num="5.6.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.0" edition="-"/>
        <vers num="8.0.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.1" edition="-"/>
        <vers num="8.0.0.1" edition="-:enterprise"/>
        <vers num="8.0.0.2" edition="-"/>
        <vers num="8.0.0.2" edition="-:enterprise"/>
        <vers num="8.0.1.0" edition="-"/>
        <vers num="8.0.1.0" edition="-:enterprise"/>
        <vers num="8.0.1.1" edition="-"/>
        <vers num="8.0.1.1" edition="-:enterprise"/>
        <vers num="8.0.11" edition="-"/>
        <vers num="8.0.11" edition="-:enterprise"/>
        <vers num="8.5.0.0" edition="-"/>
        <vers num="8.5.0.0" edition="-:enterprise"/>
        <vers num="8.5.0.1" edition="-"/>
        <vers num="8.5.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.0" edition="-"/>
        <vers num="8.6.0.0" edition="-:enterprise"/>
        <vers num="8.6.0.1" edition="-"/>
        <vers num="8.6.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.2" edition="-"/>
        <vers num="8.6.0.2" edition="-:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0518" published="2013-05-10" name="CVE-2013-0518" modified="2013-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 does not refuse to be rendered in different-origin frames, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83128" source="XF">ssp-cve20130518-content-spoofing(83128)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21636369" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21636369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="sterling_secure_proxy">
        <vers num="3.2.0.0"/>
        <vers num="3.3.0.1"/>
        <vers num="3.4.0.0"/>
        <vers num="3.4.1.0"/>
        <vers num="3.4.1.2"/>
        <vers num="3.4.1.5"/>
        <vers num="3.4.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0519" published="2013-05-10" name="CVE-2013-0519" modified="2013-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 provides web-server version data in (1) an unspecified page title and (2) an unspecified HTTP header field, which allows remote attackers to obtain potentially sensitive information by reading a version string.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82654" source="XF">ssp-cve20130519-info-disclosure(82654)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21636369" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21636369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="sterling_secure_proxy">
        <vers num="3.2.0.0"/>
        <vers num="3.3.0.1"/>
        <vers num="3.4.0.0"/>
        <vers num="3.4.1.0"/>
        <vers num="3.4.1.2"/>
        <vers num="3.4.1.5"/>
        <vers num="3.4.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0520" published="2013-05-10" name="CVE-2013-0520" modified="2013-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 allows remote authenticated users to obtain sensitive Java stack-trace information by providing invalid input data.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83433" source="XF">ssp-cve20130520-info-disclosure(83433)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21636369" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21636369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="sterling_secure_proxy">
        <vers num="3.2.0.0"/>
        <vers num="3.3.0.1"/>
        <vers num="3.4.0.0"/>
        <vers num="3.4.1.0"/>
        <vers num="3.4.1.2"/>
        <vers num="3.4.1.5"/>
        <vers num="3.4.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0525" published="2013-03-26" name="CVE-2013-0525" modified="2013-03-27" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="1.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="2.7" CVSS_base_score="1.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in IBM iNotes 8.5.x allow local users to inject arbitrary web script or HTML via a shared mail file, aka SPR DKEN8PDNTX.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82542" source="XF">inotes-folder-xss(82542)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21628658" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21628658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_inotes">
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.1.0"/>
        <vers num="8.5.1.1"/>
        <vers num="8.5.1.2"/>
        <vers num="8.5.1.3"/>
        <vers num="8.5.1.4"/>
        <vers num="8.5.1.5"/>
        <vers num="8.5.2.0"/>
        <vers num="8.5.2.1"/>
        <vers num="8.5.2.2"/>
        <vers num="8.5.2.3"/>
        <vers num="8.5.3.0"/>
        <vers num="8.5.3.1"/>
        <vers num="8.5.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0532" published="2013-03-29" name="CVE-2013-0532" modified="2013-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that cause a denial of service via malformed HTTP data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82595" source="XF">appscan-cve20130532-csrf(82595)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21631304" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21631304</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21626264" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21626264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="rational_policy_tester">
        <vers num="5.6.0.0"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.1.0"/>
        <vers num="8.0.1.1"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.0.2"/>
        <vers num="8.5.0.3"/>
      </prod>
      <prod vendor="ibm" name="security_appscan">
        <vers num="5.6.0.0" edition="-"/>
        <vers num="5.6.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.0" edition="-"/>
        <vers num="8.0.0.0" edition="-:enterprise"/>
        <vers num="8.0.0.1" edition="-"/>
        <vers num="8.0.0.1" edition="-:enterprise"/>
        <vers num="8.0.0.2" edition="-"/>
        <vers num="8.0.0.2" edition="-:enterprise"/>
        <vers num="8.0.1.0" edition="-"/>
        <vers num="8.0.1.0" edition="-:enterprise"/>
        <vers num="8.0.1.1" edition="-"/>
        <vers num="8.0.1.1" edition="-:enterprise"/>
        <vers num="8.0.11" edition="-"/>
        <vers num="8.0.11" edition="-:enterprise"/>
        <vers num="8.5.0.0" edition="-"/>
        <vers num="8.5.0.0" edition="-:enterprise"/>
        <vers num="8.5.0.1" edition="-"/>
        <vers num="8.5.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.0" edition="-"/>
        <vers num="8.6.0.0" edition="-:enterprise"/>
        <vers num="8.6.0.1" edition="-"/>
        <vers num="8.6.0.1" edition="-:enterprise"/>
        <vers num="8.6.0.2" edition="-"/>
        <vers num="8.6.0.2" edition="-:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0533" published="2013-04-27" name="CVE-2013-0533" modified="2013-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Sametime Links server in IBM Sametime 8.0.2 through 8.5.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82655" source="XF">inotes-webmail-xss(82655)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21633620" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21633620</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_sametime">
        <vers num="8.0.2"/>
        <vers num="8.0.2.1"/>
        <vers num="8.5"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.1"/>
        <vers num="8.5.2"/>
        <vers num="8.5.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0535" published="2013-05-02" name="CVE-2013-0535" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82657" source="XF">sametime-meeting-multiple-xss(82657)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21635545" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21635545</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21635185" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21635185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="classic_meeting_server">
        <vers num="7.5.1.2"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.5"/>
        <vers num="8.5.1.2"/>
        <vers num="8.5.2.1"/>
      </prod>
      <prod vendor="ibm" name="lotus_sametime">
        <vers num="7.5.1.2"/>
        <vers num="8.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.1.1"/>
        <vers num="8.0.2"/>
        <vers num="8.0.2.1"/>
        <vers num="8.5"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.1"/>
        <vers num="8.5.2"/>
        <vers num="8.5.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0538" published="2013-05-01" name="CVE-2013-0538" modified="2013-05-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element in an HTML e-mail message, aka SPRs JMOY95BLM6 and JMOY95BN49.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/912420" source="CERT-VN">VU#912420</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/83270" source="XF">ibm-notes-javascript-tags(83270)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21633819" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21633819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="8.0"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.0.2.0"/>
        <vers num="8.0.2.1"/>
        <vers num="8.0.2.2"/>
        <vers num="8.0.2.3"/>
        <vers num="8.0.2.4"/>
        <vers num="8.0.2.5"/>
        <vers num="8.0.2.6"/>
        <vers num="8.5"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.0"/>
        <vers num="8.5.1.1"/>
        <vers num="8.5.1.2"/>
        <vers num="8.5.1.3"/>
        <vers num="8.5.1.4"/>
        <vers num="8.5.1.5"/>
        <vers num="8.5.2.0"/>
        <vers num="8.5.2.1"/>
        <vers num="8.5.2.2"/>
        <vers num="8.5.2.3"/>
        <vers num="8.5.3"/>
        <vers num="8.5.3.1"/>
        <vers num="8.5.3.2"/>
        <vers num="8.5.3.3"/>
        <vers num="9.0.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0540" published="2013-04-24" name="CVE-2013-0540" modified="2013-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82695" source="XF">was-ssl-sec-bypass(82695)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM81056" source="AIXAPAR">PM81056</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?&amp;uid=swg21632423" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?&amp;uid=swg21632423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="8.5.0.0" edition="-"/>
        <vers num="8.5.0.0" edition="-:liberty_profile"/>
        <vers num="8.5.0.1" edition="-"/>
        <vers num="8.5.0.1" edition="-:liberty_profile"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0541" published="2013-04-24" name="CVE-2013-0541" modified="2013-04-24" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Buffer overflow in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Windows, when a localOS registry is used in conjunction with WebSphere Identity Manger (WIM), allows local users to cause a denial of service (daemon crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82696" source="XF">was-cve20130541-dos(82696)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM74909" source="AIXAPAR">PM74909</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?&amp;uid=swg21632423" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?&amp;uid=swg21632423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.11"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.13"/>
        <vers num="6.1.0.14"/>
        <vers num="6.1.0.15"/>
        <vers num="6.1.0.17"/>
        <vers num="6.1.0.19"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.21"/>
        <vers num="6.1.0.23"/>
        <vers num="6.1.0.25"/>
        <vers num="6.1.0.27"/>
        <vers num="6.1.0.29"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.31"/>
        <vers num="6.1.0.33"/>
        <vers num="6.1.0.35"/>
        <vers num="6.1.0.37"/>
        <vers num="6.1.0.39"/>
        <vers num="6.1.0.41"/>
        <vers num="6.1.0.43"/>
        <vers num="6.1.0.45"/>
        <vers num="6.1.0.5"/>
        <vers num="6.1.0.7"/>
        <vers num="6.1.0.9"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.15"/>
        <vers num="7.0.0.17"/>
        <vers num="7.0.0.19"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.21"/>
        <vers num="7.0.0.23"/>
        <vers num="7.0.0.25"/>
        <vers num="7.0.0.27"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.4"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.6"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.8"/>
        <vers num="7.0.0.9"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.0.3"/>
        <vers num="8.0.0.4"/>
        <vers num="8.0.0.5"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0542" published="2013-04-24" name="CVE-2013-0542" modified="2013-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via crafted field values.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82697" source="XF">was-cve20130542-xss(82697)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM81846" source="AIXAPAR">PM81846</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?&amp;uid=swg21632423" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?&amp;uid=swg21632423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0"/>
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.11"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.13"/>
        <vers num="6.1.0.14"/>
        <vers num="6.1.0.15"/>
        <vers num="6.1.0.17"/>
        <vers num="6.1.0.19"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.21"/>
        <vers num="6.1.0.23"/>
        <vers num="6.1.0.25"/>
        <vers num="6.1.0.27"/>
        <vers num="6.1.0.29"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.31"/>
        <vers num="6.1.0.33"/>
        <vers num="6.1.0.35"/>
        <vers num="6.1.0.37"/>
        <vers num="6.1.0.39"/>
        <vers num="6.1.0.41"/>
        <vers num="6.1.0.43"/>
        <vers prev="1" num="6.1.0.45"/>
        <vers num="6.1.0.5"/>
        <vers num="6.1.0.7"/>
        <vers num="6.1.0.9"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.15"/>
        <vers num="7.0.0.17"/>
        <vers num="7.0.0.19"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.21"/>
        <vers num="7.0.0.23"/>
        <vers num="7.0.0.25"/>
        <vers num="7.0.0.27"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.4"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.6"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.8"/>
        <vers num="7.0.0.9"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.0.3"/>
        <vers num="8.0.0.4"/>
        <vers num="8.0.0.5"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0543" published="2013-04-24" name="CVE-2013-0543" modified="2013-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82759" source="XF">was-cve20130543-sec-bypass(82759)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM75582" source="AIXAPAR">PM75582</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?&amp;uid=swg21632423" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?&amp;uid=swg21632423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.11"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.13"/>
        <vers num="6.1.0.14"/>
        <vers num="6.1.0.15"/>
        <vers num="6.1.0.17"/>
        <vers num="6.1.0.19"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.21"/>
        <vers num="6.1.0.23"/>
        <vers num="6.1.0.25"/>
        <vers num="6.1.0.27"/>
        <vers num="6.1.0.29"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.31"/>
        <vers num="6.1.0.33"/>
        <vers num="6.1.0.35"/>
        <vers num="6.1.0.37"/>
        <vers num="6.1.0.39"/>
        <vers num="6.1.0.41"/>
        <vers num="6.1.0.43"/>
        <vers num="6.1.0.45"/>
        <vers num="6.1.0.5"/>
        <vers num="6.1.0.7"/>
        <vers num="6.1.0.9"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.15"/>
        <vers num="7.0.0.17"/>
        <vers num="7.0.0.19"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.21"/>
        <vers num="7.0.0.23"/>
        <vers num="7.0.0.25"/>
        <vers num="7.0.0.27"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.4"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.6"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.8"/>
        <vers num="7.0.0.9"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.0.3"/>
        <vers num="8.0.0.4"/>
        <vers num="8.0.0.5"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0544" published="2013-04-24" name="CVE-2013-0544" modified="2013-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux and UNIX allows remote authenticated users to modify data via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82760" source="XF">was-cve20130544-dir-traversal(82760)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM82468" source="AIXAPAR">PM82468</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?&amp;uid=swg21632423" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?&amp;uid=swg21632423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.11"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.13"/>
        <vers num="6.1.0.14"/>
        <vers num="6.1.0.15"/>
        <vers num="6.1.0.17"/>
        <vers num="6.1.0.19"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.21"/>
        <vers num="6.1.0.23"/>
        <vers num="6.1.0.25"/>
        <vers num="6.1.0.27"/>
        <vers num="6.1.0.29"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.31"/>
        <vers num="6.1.0.33"/>
        <vers num="6.1.0.35"/>
        <vers num="6.1.0.37"/>
        <vers num="6.1.0.39"/>
        <vers num="6.1.0.41"/>
        <vers num="6.1.0.43"/>
        <vers num="6.1.0.45"/>
        <vers num="6.1.0.5"/>
        <vers num="6.1.0.7"/>
        <vers num="6.1.0.9"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.15"/>
        <vers num="7.0.0.17"/>
        <vers num="7.0.0.19"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.21"/>
        <vers num="7.0.0.23"/>
        <vers num="7.0.0.25"/>
        <vers num="7.0.0.27"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.4"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.6"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.8"/>
        <vers num="7.0.0.9"/>
        <vers num="8.0.0.0"/>
        <vers num="8.0.0.1"/>
        <vers num="8.0.0.2"/>
        <vers num="8.0.0.3"/>
        <vers num="8.0.0.4"/>
        <vers num="8.0.0.5"/>
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0549" published="2013-06-03" name="CVE-2013-0549" modified="2013-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Web Content Manager - Web Content Viewer Portlet in the server in IBM WebSphere Portal 7.0.0.x through 7.0.0.2 CF22 and 8.0.0.x through 8.0.0.1 CF5, when the IBM Portlet API is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82762" source="XF">was-portal-cve20130549-xss(82762)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21638984" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21638984</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM84525" source="AIXAPAR">PM84525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_portal">
        <vers num="7.0.0.0" edition="cf001"/>
        <vers num="7.0.0.1" edition="cf002"/>
        <vers num="7.0.0.1" edition="cf003"/>
        <vers num="7.0.0.1" edition="cf004"/>
        <vers num="7.0.0.1" edition="cf005"/>
        <vers num="7.0.0.1" edition="cf006"/>
        <vers num="7.0.0.1" edition="cf007"/>
        <vers num="7.0.0.1" edition="cf008"/>
        <vers num="7.0.0.1" edition="cf009"/>
        <vers num="7.0.0.1" edition="cf010"/>
        <vers num="7.0.0.1" edition="cf019"/>
        <vers num="7.0.0.2" edition="cf011"/>
        <vers num="7.0.0.2" edition="cf012"/>
        <vers num="7.0.0.2" edition="cf013"/>
        <vers num="7.0.0.2" edition="cf014"/>
        <vers num="7.0.0.2" edition="cf015"/>
        <vers num="7.0.0.2" edition="cf016"/>
        <vers num="7.0.0.2" edition="cf017"/>
        <vers num="7.0.0.2" edition="cf018"/>
        <vers num="7.0.0.2" edition="cf019"/>
        <vers num="7.0.0.2" edition="cf020"/>
        <vers num="7.0.0.2" edition="cf021"/>
        <vers num="7.0.0.2" edition="cf022"/>
        <vers num="8.0"/>
        <vers num="8.0.0.0" edition="cf01"/>
        <vers num="8.0.0.0" edition="cf02"/>
        <vers num="8.0.0.0" edition="cf03"/>
        <vers num="8.0.0.0" edition="cf04"/>
        <vers num="8.0.0.0" edition="cf05"/>
        <vers num="8.0.0.1" edition="cf04"/>
        <vers num="8.0.0.1" edition="cf05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0553" published="2013-04-27" name="CVE-2013-0553" modified="2013-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">The client implementation in IBM Sametime 8.5.1 through 8.5.2.1, as used in Sametime Connect client, Sametime Advanced Connect client, Sametime Advanced Web client, and other products, allows remote authenticated users to send commands to individual chat users, or to all participants in a chat room, via a crafted Sametime Instant Message (IM).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/82915" source="XF">ibm-sametime-commands(82915)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21633618" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21633618</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_sametime">
        <vers num="8.5.1"/>
        <vers num="8.5.1.1"/>
      </prod>
      <prod vendor="ibm" name="sametime">
        <vers num="8.5.2.0"/>
        <vers num="8.5.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0565" published="2013-04-24" name="CVE-2013-0565" modified="2013-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the RPC adapter for the Web 2.0 and Mobile toolkit in IBM WebSphere Application Server (WAS) 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted response.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83138" source="XF">was-cve20130565-xss(83138)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM83402" source="AIXAPAR">PM83402</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?&amp;uid=swg21632423" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?&amp;uid=swg21632423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="8.5.0.0"/>
        <vers num="8.5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0569" published="2013-04-26" name="CVE-2013-0569" modified="2013-05-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Communities component in IBM Connections 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83354" source="XF">ibm-communities-cve20130569-xss(83354)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21635059" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21635059</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1LO74629" source="AIXAPAR">LO74629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="connections">
        <vers num="4.5.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0571" published="2013-04-26" name="CVE-2013-0571" modified="2013-04-29" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="2.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="5.5" CVSS_base_score="2.9">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM Document Connect for Application Support Facility (aka DC4ASF) before 1.0.0.1218 in Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and AIX allows remote attackers to inject arbitrary web script or HTML via a crafted URL.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local_network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83246" source="XF">asf-cve20130571-xss(83246)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21635328" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21635328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="application_support_facility">
        <vers num="3.4.0" edition="-"/>
        <vers num="3.4.0" edition="-:~~~linux_kernel~~"/>
        <vers num="3.4.0" edition="-:~~~aix~~"/>
        <vers num="3.4.0" edition="-:~~~windows~~"/>
        <vers num="3.4.0" edition="-:~~~z/os~~"/>
      </prod>
      <prod vendor="ibm" name="document_connect_for_application_support_facility">
        <vers prev="1" num="1.0.0.1204"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0572" published="2013-04-26" name="CVE-2013-0572" modified="2013-05-01" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="2.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.4" CVSS_base_score="2.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM Document Connect for Application Support Facility (aka DC4ASF) before 1.0.0.1218 in Application Support Facility (ASF) 3.4 for z/OS on Windows, Linux, and AIX allows remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local_network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83247" source="XF">asf-cve20130572-spoofing(83247)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21635328" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21635328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="application_support_facility">
        <vers num="3.4.0" edition="-"/>
        <vers num="3.4.0" edition="-:~~~linux_kernel~~"/>
        <vers num="3.4.0" edition="-:~~~aix~~"/>
        <vers num="3.4.0" edition="-:~~~windows~~"/>
        <vers num="3.4.0" edition="-:~~~z/os~~"/>
      </prod>
      <prod vendor="ibm" name="document_connect_for_application_support_facility">
        <vers prev="1" num="1.0.0.1204"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0576" published="2013-05-28" name="CVE-2013-0576" modified="2013-05-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Tivoli Enterprise Portal browser client in IBM Tivoli Monitoring 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21634920" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21634920</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/83328" source="XF">ibm-tivoli-cve20130576-xss(83328)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IV32812" source="AIXAPAR">IV32812</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_monitoring">
        <vers num="6.2.0"/>
        <vers num="6.2.0.1"/>
        <vers num="6.2.0.2"/>
        <vers num="6.2.0.3"/>
        <vers num="6.2.1"/>
        <vers num="6.2.1.1"/>
        <vers num="6.2.1.2"/>
        <vers num="6.2.1.3"/>
        <vers num="6.2.1.4"/>
        <vers num="6.2.2"/>
        <vers num="6.2.2.1"/>
        <vers num="6.2.2.2"/>
        <vers num="6.2.2.3"/>
        <vers num="6.2.2.4"/>
        <vers num="6.2.2.5"/>
        <vers num="6.2.2.6"/>
        <vers num="6.2.2.7"/>
        <vers num="6.2.2.8"/>
        <vers num="6.2.2.9"/>
        <vers num="6.2.3"/>
        <vers num="6.2.3.1"/>
        <vers num="6.2.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-0578" published="2013-05-10" name="CVE-2013-0578" modified="2013-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">The Sterling Order Management APIs in IBM Sterling Multi-Channel Fulfillment Solution 8.0 before HF128 and IBM Sterling Selling and Fulfillment Foundation 8.5 before HF93, 9.0 before HF73, 9.1.0 before FP45, and 9.2.0 before FP17, when the API tester is enabled, do not require administrative credentials, which allows remote authenticated users to obtain sensitive database information via a request to the API tester URI.</descript>
      <descript source="nvd">Per: http://www-01.ibm.com/support/docview.wss?uid=swg21636034

'AFFECTED PRODUCTS AND VERSIONS:
IBM Sterling Selling and Fulfillment Foundation 9.2.0
IBM Sterling Selling and Fulfillment Foundation 9.1.0
IBM Sterling Selling and Fulfillment Foundation 9.0
IBM Sterling Selling and Fulfillment Foundation 8.5
IBM Sterling Multi-Channel Fulfillment Solution 8.0'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83330" source="XF">ibm-sterling-cve20130578-info-disclosure(83330)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21636034" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21636034</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC91829" source="AIXAPAR">IC91829</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="sterling_multi-channel_fulfillment_solution">
        <vers num="8.0"/>
      </prod>
      <prod vendor="ibm" name="sterling_selling_and_fulfillment_foundation">
        <vers num="8.5"/>
        <vers num="9.0"/>
        <vers num="9.1.0"/>
        <vers num="9.1.0.1"/>
        <vers num="9.1.0.10"/>
        <vers num="9.1.0.11"/>
        <vers num="9.1.0.12"/>
        <vers num="9.1.0.13"/>
        <vers num="9.1.0.14"/>
        <vers num="9.1.0.15"/>
        <vers num="9.1.0.16"/>
        <vers num="9.1.0.17"/>
        <vers num="9.1.0.18"/>
        <vers num="9.1.0.19"/>
        <vers num="9.1.0.2"/>
        <vers num="9.1.0.20"/>
        <vers num="9.1.0.21"/>
        <vers num="9.1.0.22"/>
        <vers num="9.1.0.23"/>
        <vers num="9.1.0.24"/>
        <vers num="9.1.0.25"/>
        <vers num="9.1.0.26"/>
        <vers num="9.1.0.27"/>
        <vers num="9.1.0.28"/>
        <vers num="9.1.0.29"/>
        <vers num="9.1.0.3"/>
        <vers num="9.1.0.30"/>
        <vers num="9.1.0.31"/>
        <vers num="9.1.0.32"/>
        <vers num="9.1.0.33"/>
        <vers num="9.1.0.34"/>
        <vers num="9.1.0.35"/>
        <vers num="9.1.0.36"/>
        <vers num="9.1.0.37"/>
        <vers num="9.1.0.38"/>
        <vers num="9.1.0.39"/>
        <vers num="9.1.0.4"/>
        <vers num="9.1.0.40"/>
        <vers num="9.1.0.41"/>
        <vers num="9.1.0.42"/>
        <vers num="9.1.0.43"/>
        <vers num="9.1.0.44"/>
        <vers num="9.1.0.5"/>
        <vers num="9.1.0.6"/>
        <vers num="9.1.0.7"/>
        <vers num="9.1.0.8"/>
        <vers num="9.1.0.9"/>
        <vers num="9.2.0"/>
        <vers num="9.2.0.1"/>
        <vers num="9.2.0.10"/>
        <vers num="9.2.0.11"/>
        <vers num="9.2.0.12"/>
        <vers num="9.2.0.13"/>
        <vers num="9.2.0.14"/>
        <vers num="9.2.0.15"/>
        <vers num="9.2.0.16"/>
        <vers num="9.2.0.2"/>
        <vers num="9.2.0.3"/>
        <vers num="9.2.0.4"/>
        <vers num="9.2.0.5"/>
        <vers num="9.2.0.6"/>
        <vers num="9.2.0.7"/>
        <vers num="9.2.0.8"/>
        <vers num="9.2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0582" published="2013-05-02" name="CVE-2013-0582" modified="2013-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.12, 6.2.1 before 6.2.1.5, and 6.2.2 before 6.2.2.4 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.12 and 6.2.1 before 6.2.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a SAML 2.0 response.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21635688" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21635688</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IV31640" source="AIXAPAR">IV31640</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IV26034" source="AIXAPAR">IV26034</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IV26033" source="AIXAPAR">IV26033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_federated_identity_manager">
        <vers num="6.2.0"/>
        <vers num="6.2.0.1"/>
        <vers num="6.2.0.10"/>
        <vers num="6.2.0.11"/>
        <vers num="6.2.0.2"/>
        <vers num="6.2.0.3"/>
        <vers num="6.2.0.8"/>
        <vers num="6.2.0.9"/>
        <vers num="6.2.1"/>
        <vers num="6.2.1.1"/>
        <vers num="6.2.1.2"/>
        <vers num="6.2.1.3"/>
        <vers num="6.2.1.4"/>
        <vers num="6.2.2"/>
        <vers num="6.2.2.2"/>
        <vers num="6.2.2.3"/>
      </prod>
      <prod vendor="ibm" name="tivoli_federated_identity_manager_business_gateway">
        <vers num="6.2.0"/>
        <vers num="6.2.0.1"/>
        <vers num="6.2.0.10"/>
        <vers num="6.2.0.11"/>
        <vers num="6.2.0.2"/>
        <vers num="6.2.0.3"/>
        <vers num="6.2.0.8"/>
        <vers num="6.2.0.9"/>
        <vers num="6.2.1"/>
        <vers num="6.2.1.3"/>
        <vers num="6.2.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0584" published="2013-04-23" name="CVE-2013-0584" modified="2013-04-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Data Replication Dashboard component in IBM InfoSphere Replication Server 9.7 and 10.x before 10.2.0.0-b113 allows remote attackers to obtain a list of all user accounts, along with information about whether each account requires a password, via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83355" source="XF">ibm-infosphere-cve20130584-info-disclosure(83355)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21634798" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21634798</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="infosphere_replication_server">
        <vers num="10.1.0"/>
        <vers num="10.1.0.1"/>
        <vers num="10.1.0.2"/>
        <vers num="10.1.0.3"/>
        <vers num="10.1.0.4"/>
        <vers num="10.2.0.0"/>
        <vers num="9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0593" published="2013-04-26" name="CVE-2013-0593" modified="2013-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the olch2x32 ActiveX control in IBM SPSS SamplePower 3.0 before 3.0-IM-S3SAMPC-WIN32-FP001 allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83382" source="XF">ibm-spss-cve20130593-code-exec(83382)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21635503" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21635503</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="spss_samplepower">
        <vers num="3.0.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0599" published="2013-05-28" name="CVE-2013-0599" modified="2013-05-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83613" source="XF">ibm-iehs-cve20130599-info-disclosure(83613)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21637151" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21637151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="rational_directory_server">
        <vers num="5.1.1"/>
        <vers num="5.1.1.1"/>
        <vers prev="1" num="5.1.1.2"/>
        <vers num="5.2"/>
        <vers num="5.2.0.1"/>
        <vers num="5.2.0.2"/>
        <vers prev="1" num="5.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0600" published="2013-05-09" name="CVE-2013-0600" modified="2013-05-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability on IBM WebSphere DataPower XC10 Appliance devices 2.0 and 2.1 through 2.1 FP3 allows remote attackers to bypass authentication and perform administrative actions via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21636324" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21636324</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC91726" source="AIXAPAR">IC91726</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_datapower_xc10_appliance">
        <vers num="-"/>
      </prod>
      <prod vendor="ibm" name="websphere_datapower_xc10_appliance_firmware">
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.3"/>
        <vers num="2.1.0.0"/>
        <vers num="2.1.0.1"/>
        <vers num="2.1.0.2"/>
        <vers num="2.1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0601" published="2013-01-10" name="CVE-2013-0601" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, CVE-2013-0620, and CVE-2013-0623.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb13-02.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb13-02.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0150.html" source="REDHAT">RHSA-2013:0150</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-01/msg00081.html" source="SUSE">openSUSE-SU-2013:0193</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-01/msg00028.html" source="SUSE">openSUSE-SU-2013:0138</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00005.html" source="SUSE">SUSE-SU-2013:0047</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00004.html" source="SUSE">SUSE-SU-2013:0044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="10.0" edition="-"/>
        <vers num="10.0" edition="-:pro"/>
        <vers num="10.0.1" edition="-"/>
        <vers num="10.0.1" edition="-:pro"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="11.0"/>
        <vers num="9.0" edition="-"/>
        <vers num="9.0" edition="-:pro"/>
        <vers num="9.1" edition="-"/>
        <vers num="9.1" edition="-:pro"/>
        <vers num="9.1.1" edition="-"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3" edition="-"/>
        <vers num="9.2" edition="-"/>
        <vers num="9.3" edition="-"/>
        <vers num="9.3" edition="-:pro"/>
        <vers num="9.3.1" edition="-"/>
        <vers num="9.3.2" edition="-"/>
        <vers num="9.3.3"/>
        <vers num="9.3.4" edition="-"/>
        <vers num="9.4"/>
        <vers num="9.4.1" edition="-"/>
        <vers num="9.4.2" edition="-"/>
        <vers num="9.4.3" edition="-"/>
        <vers num="9.4.4" edition="-"/>
        <vers num="9.4.5" edition="-"/>
        <vers num="9.4.6" edition="-"/>
        <vers num="9.4.7"/>
        <vers num="9.5"/>
        <vers num="9.5.1"/>
        <vers num="9.5.2"/>
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="11.0"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3"/>
        <vers num="9.2"/>
        <vers num="9.3"/>
        <vers num="9.3.1"/>
        <vers num="9.3.2"/>
        <vers num="9.3.3"/>
        <vers num="9.3.4"/>
        <vers num="9.4"/>
        <vers num="9.4.1"/>
        <vers num="9.4.2"/>
        <vers num="9.4.3"/>
        <vers num="9.4.4"/>
        <vers num="9.4.5"/>
        <vers num="9.4.6"/>
        <vers num="9.4.7"/>
        <vers num="9.5"/>
        <vers num="9.5.1"/>
        <vers num="9.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0602" published="2013-01-10" name="CVE-2013-0602" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb13-02.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb13-02.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0150.html" source="REDHAT">RHSA-2013:0150</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-01/msg00081.html" source="SUSE">openSUSE-SU-2013:0193</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-01/msg00028.html" source="SUSE">openSUSE-SU-2013:0138</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00005.html" source="SUSE">SUSE-SU-2013:0047</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00004.html" source="SUSE">SUSE-SU-2013:0044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="10.0" edition="-"/>
        <vers num="10.0" edition="-:pro"/>
        <vers num="10.0.1" edition="-"/>
        <vers num="10.0.1" edition="-:pro"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="11.0"/>
        <vers num="9.0" edition="-"/>
        <vers num="9.0" edition="-:pro"/>
        <vers num="9.1" edition="-"/>
        <vers num="9.1" edition="-:pro"/>
        <vers num="9.1.1" edition="-"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3" edition="-"/>
        <vers num="9.2" edition="-"/>
        <vers num="9.3" edition="-"/>
        <vers num="9.3" edition="-:pro"/>
        <vers num="9.3.1" edition="-"/>
        <vers num="9.3.2" edition="-"/>
        <vers num="9.3.3"/>
        <vers num="9.3.4" edition="-"/>
        <vers num="9.4"/>
        <vers num="9.4.1" edition="-"/>
        <vers num="9.4.2" edition="-"/>
        <vers num="9.4.3" edition="-"/>
        <vers num="9.4.4" edition="-"/>
        <vers num="9.4.5" edition="-"/>
        <vers num="9.4.6" edition="-"/>
        <vers num="9.4.7"/>
        <vers num="9.5"/>
        <vers num="9.5.1"/>
        <vers num="9.5.2"/>
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="11.0"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3"/>
        <vers num="9.2"/>
        <vers num="9.3"/>
        <vers num="9.3.1"/>
        <vers num="9.3.2"/>
        <vers num="9.3.3"/>
        <vers num="9.3.4"/>
        <vers num="9.4"/>
        <vers num="9.4.1"/>
        <vers num="9.4.2"/>
        <vers num="9.4.3"/>
        <vers num="9.4.4"/>
        <vers num="9.4.5"/>
        <vers num="9.4.6"/>
        <vers num="9.4.7"/>
        <vers num="9.5"/>
        <vers num="9.5.1"/>
        <vers num="9.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0603" published="2013-01-10" name="CVE-2013-0603" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0604.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb13-02.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb13-02.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0150.html" source="REDHAT">RHSA-2013:0150</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-01/msg00081.html" source="SUSE">openSUSE-SU-2013:0193</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-01/msg00028.html" source="SUSE">openSUSE-SU-2013:0138</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00005.html" source="SUSE">SUSE-SU-2013:0047</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00004.html" source="SUSE">SUSE-SU-2013:0044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="10.0" edition="-"/>
        <vers num="10.0" edition="-:pro"/>
        <vers num="10.0.1" edition="-"/>
        <vers num="10.0.1" edition="-:pro"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="11.0"/>
        <vers num="9.0" edition="-"/>
        <vers num="9.0" edition="-:pro"/>
        <vers num="9.1" edition="-"/>
        <vers num="9.1" edition="-:pro"/>
        <vers num="9.1.1" edition="-"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3" edition="-"/>
        <vers num="9.2" edition="-"/>
        <vers num="9.3" edition="-"/>
        <vers num="9.3" edition="-:pro"/>
        <vers num="9.3.1" edition="-"/>
        <vers num="9.3.2" edition="-"/>
        <vers num="9.3.3"/>
        <vers num="9.3.4" edition="-"/>
        <vers num="9.4"/>
        <vers num="9.4.1" edition="-"/>
        <vers num="9.4.2" edition="-"/>
        <vers num="9.4.3" edition="-"/>
        <vers num="9.4.4" edition="-"/>
        <vers num="9.4.5" edition="-"/>
        <vers num="9.4.6" edition="-"/>
        <vers num="9.4.7"/>
        <vers num="9.5"/>
        <vers num="9.5.1"/>
        <vers num="9.5.2"/>
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="11.0"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3"/>
        <vers num="9.2"/>
        <vers num="9.3"/>
        <vers num="9.3.1"/>
        <vers num="9.3.2"/>
        <vers num="9.3.3"/>
        <vers num="9.3.4"/>
        <vers num="9.4"/>
        <vers num="9.4.1"/>
        <vers num="9.4.2"/>
        <vers num="9.4.3"/>
        <vers num="9.4.4"/>
        <vers num="9.4.5"/>
        <vers num="9.4.6"/>
        <vers num="9.4.7"/>
        <vers num="9.5"/>
        <vers num="9.5.1"/>
        <vers num="9.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0604" published="2013-01-10" name="CVE-2013-0604" modified="2013-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0603.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb13-02.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/bulletins/apsb13-02.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0150.html" source="REDHAT">RHSA-2013:0150</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-01/msg00081.html" source="SUSE">openSUSE-SU-2013:0193</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-01/msg00028.html" source="SUSE">openSUSE-SU-2013:0138</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00005.html" source="SUSE">SUSE-SU-2013:0047</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00004.html" source="SUSE">SUSE-SU-2013:0044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="10.0" edition="-"/>
        <vers num="10.0" edition="-:pro"/>
        <vers num="10.0.1" edition="-"/>
        <vers num="10.0.1" edition="-:pro"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="11.0"/>
        <vers num="9.0" edition="-"/>
        <vers num="9.0" edition="-:pro"/>
        <vers num="9.1" edition="-"/>
        <vers num="9.1" edition="-:pro"/>
        <vers num="9.1.1" edition="-"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3" edition="-"/>
        <vers num="9.2" edition="-"/>
        <vers num="9.3" edition="-"/>
        <vers num="9.3" edition="-:pro"/>
        <vers num="9.3.1" edition="-"/>
        <vers num="9.3.2" edition="-"/>
        <vers num="9.3.3"/>
        <vers num="9.3.4" edition="-"/>
        <vers num="9.4"/>
        <vers num="9.4.1" edition="-"/>
        <vers num="9.4.2" edition="-"/>
        <vers num="9.4.3" edition="-"/>
        <vers num="9.4.4" edition="-"/>
        <vers num="9.4.5" edition="-"/>
        <vers num="9.4.6" edition="-"/>
        <vers num="9.4.7"/>
        <vers num="9.5"/>
        <vers num="9.5.1"/>
        <vers num="9.5.2"/>
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"