<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2013-06-19" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="Medium" seq="2002-2443" published="2013-05-29" name="CVE-2002-2443" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://github.com/krb5/krb5/commit/cf1a0c411b2668c57c41e9c4efd15ba17b6b322c" source="CONFIRM">https://github.com/krb5/krb5/commit/cf1a0c411b2668c57c41e9c4efd15ba17b6b322c</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=962531" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=962531</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2701" source="DEBIAN">DSA-2701</ref>
      <ref url="http://krbdev.mit.edu/rt/Ticket/Display.html?id=7637" source="CONFIRM">http://krbdev.mit.edu/rt/Ticket/Display.html?id=7637</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers prev="1" num="5-1.11.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-2885" published="2012-09-26" name="CVE-2012-2885" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double free vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to application exit.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html" source="CONFIRM" patch="1" adv="1">http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html</ref>
      <ref url="https://code.google.com/p/chromium/issues/detail?id=142310" source="CONFIRM">https://code.google.com/p/chromium/issues/detail?id=142310</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/78840" source="XF">google-chrome-cve20122885(78840)</ref>
      <ref url="http://osvdb.org/85755" source="OSVDB">85755</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00012.html" source="SUSE">openSUSE-SU-2012:1376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="22.0.1229.0"/>
        <vers num="22.0.1229.1"/>
        <vers num="22.0.1229.10"/>
        <vers num="22.0.1229.11"/>
        <vers num="22.0.1229.12"/>
        <vers num="22.0.1229.14"/>
        <vers num="22.0.1229.16"/>
        <vers num="22.0.1229.17"/>
        <vers num="22.0.1229.18"/>
        <vers num="22.0.1229.2"/>
        <vers num="22.0.1229.20"/>
        <vers num="22.0.1229.21"/>
        <vers num="22.0.1229.22"/>
        <vers num="22.0.1229.23"/>
        <vers num="22.0.1229.24"/>
        <vers num="22.0.1229.25"/>
        <vers num="22.0.1229.26"/>
        <vers num="22.0.1229.27"/>
        <vers num="22.0.1229.28"/>
        <vers num="22.0.1229.29"/>
        <vers num="22.0.1229.3"/>
        <vers num="22.0.1229.31"/>
        <vers num="22.0.1229.32"/>
        <vers num="22.0.1229.33"/>
        <vers num="22.0.1229.35"/>
        <vers num="22.0.1229.36"/>
        <vers num="22.0.1229.37"/>
        <vers num="22.0.1229.39"/>
        <vers num="22.0.1229.4"/>
        <vers num="22.0.1229.48"/>
        <vers num="22.0.1229.49"/>
        <vers num="22.0.1229.50"/>
        <vers num="22.0.1229.51"/>
        <vers num="22.0.1229.52"/>
        <vers num="22.0.1229.53"/>
        <vers num="22.0.1229.54"/>
        <vers num="22.0.1229.55"/>
        <vers num="22.0.1229.56"/>
        <vers num="22.0.1229.57"/>
        <vers num="22.0.1229.58"/>
        <vers num="22.0.1229.59"/>
        <vers num="22.0.1229.6"/>
        <vers num="22.0.1229.60"/>
        <vers num="22.0.1229.62"/>
        <vers num="22.0.1229.63"/>
        <vers num="22.0.1229.64"/>
        <vers num="22.0.1229.65"/>
        <vers num="22.0.1229.67"/>
        <vers num="22.0.1229.7"/>
        <vers num="22.0.1229.76"/>
        <vers prev="1" num="22.0.1229.78"/>
        <vers num="22.0.1229.8"/>
        <vers num="22.0.1229.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-3422" published="2012-08-07" name="CVE-2012-3422" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=840592" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=840592</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1521-1" source="UBUNTU">USN-1521-1</ref>
      <ref url="http://secunia.com/advisories/50089" source="SECUNIA" adv="1">50089</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1132.html" source="REDHAT">RHSA-2012:1132</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-05/msg00032.html" source="SUSE">openSUSE-SU-2013:0826</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.html" source="SUSE">SUSE-SU-2013:0851</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00005.html" source="SUSE">openSUSE-SU-2012:0982</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00004.html" source="SUSE">openSUSE-SU-2012:0981</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00003.html" source="SUSE">SUSE-SU-2012:0979</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="icedtea-web">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers prev="1" num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2012-3423" published="2012-08-07" name="CVE-2012-3423" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/d7375e2a9076" source="CONFIRM" patch="1">http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/d7375e2a9076</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/d65bd94e0ba9" source="CONFIRM" patch="1">http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/d65bd94e0ba9</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=841345" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=841345</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1521-1" source="UBUNTU">USN-1521-1</ref>
      <ref url="http://secunia.com/advisories/50089" source="SECUNIA" adv="1">50089</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1132.html" source="REDHAT">RHSA-2012:1132</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-05/msg00032.html" source="SUSE">openSUSE-SU-2013:0826</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.html" source="SUSE">SUSE-SU-2013:0851</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00005.html" source="SUSE">openSUSE-SU-2012:0982</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00004.html" source="SUSE">openSUSE-SU-2012:0981</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00003.html" source="SUSE">SUSE-SU-2012:0979</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWS</ref>
      <ref url="http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=863" source="CONFIRM" adv="1">http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=863</ref>
      <ref url="http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=518" source="CONFIRM">http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=518</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="icedtea-web">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers prev="1" num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-3488" published="2012-10-03" name="CVE-2012-3488" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The libxslt support in contrib/xml2 in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 does not properly restrict access to files and URLs, which allows remote authenticated users to modify data, obtain sensitive information, or trigger outbound traffic to arbitrary external hosts by leveraging (1) stylesheet commands that are permitted by the libxslt security options or (2) an xslt_process feature, related to an XML External Entity (aka XXE) issue.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=849172" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=849172</ref>
      <ref url="https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_postgresql2" source="CONFIRM">https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_postgresql2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1542-1" source="UBUNTU">USN-1542-1</ref>
      <ref url="http://www.securityfocus.com/bid/55072" source="BID">55072</ref>
      <ref url="http://www.postgresql.org/support/security/" source="CONFIRM" adv="1">http://www.postgresql.org/support/security/</ref>
      <ref url="http://www.postgresql.org/docs/9.1/static/release-9-1-5.html" source="CONFIRM">http://www.postgresql.org/docs/9.1/static/release-9-1-5.html</ref>
      <ref url="http://www.postgresql.org/docs/9.0/static/release-9-0-9.html" source="CONFIRM">http://www.postgresql.org/docs/9.0/static/release-9-0-9.html</ref>
      <ref url="http://www.postgresql.org/docs/8.4/static/release-8-4-13.html" source="CONFIRM">http://www.postgresql.org/docs/8.4/static/release-8-4-13.html</ref>
      <ref url="http://www.postgresql.org/docs/8.3/static/release-8-3-20.html" source="CONFIRM">http://www.postgresql.org/docs/8.3/static/release-8-3-20.html</ref>
      <ref url="http://www.postgresql.org/about/news/1407/" source="CONFIRM" adv="1">http://www.postgresql.org/about/news/1407/</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2012:139" source="MANDRIVA">MDVSA-2012:139</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2534" source="DEBIAN">DSA-2534</ref>
      <ref url="http://secunia.com/advisories/50946" source="SECUNIA">50946</ref>
      <ref url="http://secunia.com/advisories/50859" source="SECUNIA">50859</ref>
      <ref url="http://secunia.com/advisories/50718" source="SECUNIA">50718</ref>
      <ref url="http://secunia.com/advisories/50636" source="SECUNIA">50636</ref>
      <ref url="http://secunia.com/advisories/50635" source="SECUNIA">50635</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1264.html" source="REDHAT">RHSA-2012:1264</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1263.html" source="REDHAT">RHSA-2012:1263</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.html" source="SUSE">openSUSE-SU-2012:1299</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.html" source="SUSE">openSUSE-SU-2012:1288</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.html" source="SUSE">openSUSE-SU-2012:1251</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html" source="APPLE">APPLE-SA-2013-03-14-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="8.3"/>
        <vers num="8.3.1"/>
        <vers num="8.3.10"/>
        <vers num="8.3.11"/>
        <vers num="8.3.12"/>
        <vers num="8.3.13"/>
        <vers num="8.3.14"/>
        <vers num="8.3.15"/>
        <vers num="8.3.16"/>
        <vers num="8.3.17"/>
        <vers num="8.3.18"/>
        <vers num="8.3.19"/>
        <vers num="8.3.2"/>
        <vers num="8.3.3"/>
        <vers num="8.3.4"/>
        <vers num="8.3.5"/>
        <vers num="8.3.6"/>
        <vers num="8.3.7"/>
        <vers num="8.3.8"/>
        <vers num="8.3.9"/>
        <vers num="8.4"/>
        <vers num="8.4.1"/>
        <vers num="8.4.10"/>
        <vers num="8.4.11"/>
        <vers num="8.4.12"/>
        <vers num="8.4.2"/>
        <vers num="8.4.3"/>
        <vers num="8.4.4"/>
        <vers num="8.4.5"/>
        <vers num="8.4.6"/>
        <vers num="8.4.7"/>
        <vers num="8.4.8"/>
        <vers num="8.4.9"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.0.4"/>
        <vers num="9.0.5"/>
        <vers num="9.0.6"/>
        <vers num="9.0.7"/>
        <vers num="9.0.8"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3"/>
        <vers num="9.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-3489" published="2012-10-03" name="CVE-2012-3489" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=849173" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=849173</ref>
      <ref url="https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_postgresql2" source="CONFIRM">https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_postgresql2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1542-1" source="UBUNTU">USN-1542-1</ref>
      <ref url="http://www.securityfocus.com/bid/55074" source="BID">55074</ref>
      <ref url="http://www.postgresql.org/support/security/" source="CONFIRM" adv="1">http://www.postgresql.org/support/security/</ref>
      <ref url="http://www.postgresql.org/docs/9.1/static/release-9-1-5.html" source="CONFIRM">http://www.postgresql.org/docs/9.1/static/release-9-1-5.html</ref>
      <ref url="http://www.postgresql.org/docs/9.0/static/release-9-0-9.html" source="CONFIRM">http://www.postgresql.org/docs/9.0/static/release-9-0-9.html</ref>
      <ref url="http://www.postgresql.org/docs/8.4/static/release-8-4-13.html" source="CONFIRM">http://www.postgresql.org/docs/8.4/static/release-8-4-13.html</ref>
      <ref url="http://www.postgresql.org/docs/8.3/static/release-8-3-20.html" source="CONFIRM">http://www.postgresql.org/docs/8.3/static/release-8-3-20.html</ref>
      <ref url="http://www.postgresql.org/about/news/1407/" source="CONFIRM" adv="1">http://www.postgresql.org/about/news/1407/</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2012:139" source="MANDRIVA">MDVSA-2012:139</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2534" source="DEBIAN">DSA-2534</ref>
      <ref url="http://secunia.com/advisories/50946" source="SECUNIA">50946</ref>
      <ref url="http://secunia.com/advisories/50859" source="SECUNIA">50859</ref>
      <ref url="http://secunia.com/advisories/50718" source="SECUNIA">50718</ref>
      <ref url="http://secunia.com/advisories/50635" source="SECUNIA">50635</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1263.html" source="REDHAT">RHSA-2012:1263</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2012-10/msg00024.html" source="SUSE">openSUSE-SU-2012:1299</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2012-10/msg00013.html" source="SUSE">openSUSE-SU-2012:1288</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2012-09/msg00102.html" source="SUSE">openSUSE-SU-2012:1251</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html" source="APPLE">APPLE-SA-2013-03-14-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="8.3"/>
        <vers num="8.3.1"/>
        <vers num="8.3.10"/>
        <vers num="8.3.11"/>
        <vers num="8.3.12"/>
        <vers num="8.3.13"/>
        <vers num="8.3.14"/>
        <vers num="8.3.15"/>
        <vers num="8.3.16"/>
        <vers num="8.3.17"/>
        <vers num="8.3.18"/>
        <vers num="8.3.19"/>
        <vers num="8.3.2"/>
        <vers num="8.3.3"/>
        <vers num="8.3.4"/>
        <vers num="8.3.5"/>
        <vers num="8.3.6"/>
        <vers num="8.3.7"/>
        <vers num="8.3.8"/>
        <vers num="8.3.9"/>
        <vers num="8.4"/>
        <vers num="8.4.1"/>
        <vers num="8.4.10"/>
        <vers num="8.4.11"/>
        <vers num="8.4.12"/>
        <vers num="8.4.2"/>
        <vers num="8.4.3"/>
        <vers num="8.4.4"/>
        <vers num="8.4.5"/>
        <vers num="8.4.6"/>
        <vers num="8.4.7"/>
        <vers num="8.4.8"/>
        <vers num="8.4.9"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.0.4"/>
        <vers num="9.0.5"/>
        <vers num="9.0.6"/>
        <vers num="9.0.7"/>
        <vers num="9.0.8"/>
        <vers num="9.1"/>
        <vers num="9.1.1"/>
        <vers num="9.1.2"/>
        <vers num="9.1.3"/>
        <vers num="9.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-3525" published="2012-08-25" name="CVE-2012-3525" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://github.com/Jabberd2/jabberd2/commit/aabcffae560d5fd00cd1d2ffce5d760353cf0a4d" source="CONFIRM" patch="1">https://github.com/Jabberd2/jabberd2/commit/aabcffae560d5fd00cd1d2ffce5d760353cf0a4d</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=850872" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=850872</ref>
      <ref url="http://xmpp.org/resources/security-notices/server-dialback/" source="MISC" adv="1">http://xmpp.org/resources/security-notices/server-dialback/</ref>
      <ref url="http://www.securityfocus.com/bid/55167" source="BID">55167</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/08/22/6" source="MLIST">[oss-security] 20120822 Re: CVE Request -- jabberd2: Prone to unsolicited XMPP Dialback attacks</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/08/22/5" source="MLIST">[oss-security] 20120822 CVE Request -- jabberd2: Prone to unsolicited XMPP Dialback attacks</ref>
      <ref url="http://www.mail-archive.com/jabberd2@lists.xiaoka.com/msg01903.html" source="MLIST">[jabberd2] 20120821 Fwd: [Security] Vulnerability in XMPP Server Dialback Implementations</ref>
      <ref url="http://secunia.com/advisories/50859" source="SECUNIA">50859</ref>
      <ref url="http://secunia.com/advisories/50124" source="SECUNIA" adv="1">50124</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1539.html" source="REDHAT">RHSA-2012:1539</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1538.html" source="REDHAT">RHSA-2012:1538</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html" source="APPLE">APPLE-SA-2013-03-14-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jabber2" name="jabberd2">
        <vers num="2.1.19"/>
      </prod>
      <prod vendor="jabberd2" name="jabberd2">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.1.12"/>
        <vers num="2.1.13"/>
        <vers num="2.1.14"/>
        <vers num="2.1.15"/>
        <vers num="2.1.16"/>
        <vers num="2.1.17"/>
        <vers num="2.1.18"/>
        <vers num="2.1.2"/>
        <vers num="2.1.20"/>
        <vers num="2.1.21"/>
        <vers num="2.1.22"/>
        <vers num="2.1.23"/>
        <vers num="2.1.24"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15"/>
        <vers prev="1" num="2.2.16"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.7.1"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-3544" published="2013-06-01" name="CVE-2012-3544" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1476592" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1476592</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1378921" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1378921</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1378702" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1378702</ref>
      <ref url="http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/java/org/apache/coyote/http11/filters/ChunkedInputFilter.java?r1=1476592&amp;r2=1476591&amp;pathrev=1476592" source="CONFIRM" patch="1">http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/java/org/apache/coyote/http11/filters/ChunkedInputFilter.java?r1=1476592&amp;r2=1476591&amp;pathrev=1476592</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1841-1" source="UBUNTU">USN-1841-1</ref>
      <ref url="http://tomcat.apache.org/security-7.html" source="CONFIRM" adv="1">http://tomcat.apache.org/security-7.html</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM" adv="1">http://tomcat.apache.org/security-6.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="6.0"/>
        <vers num="6.0.0" edition="alpha"/>
        <vers num="6.0.1" edition="alpha"/>
        <vers num="6.0.10"/>
        <vers num="6.0.11"/>
        <vers num="6.0.12"/>
        <vers num="6.0.13"/>
        <vers num="6.0.14"/>
        <vers num="6.0.15"/>
        <vers num="6.0.16"/>
        <vers num="6.0.17"/>
        <vers num="6.0.18"/>
        <vers num="6.0.19"/>
        <vers num="6.0.2" edition="alpha"/>
        <vers num="6.0.2" edition="beta"/>
        <vers num="6.0.20"/>
        <vers num="6.0.24"/>
        <vers num="6.0.26"/>
        <vers num="6.0.27"/>
        <vers num="6.0.28"/>
        <vers num="6.0.29"/>
        <vers num="6.0.3"/>
        <vers num="6.0.30"/>
        <vers num="6.0.31"/>
        <vers num="6.0.32"/>
        <vers num="6.0.33"/>
        <vers num="6.0.35"/>
        <vers num="6.0.36"/>
        <vers num="6.0.4" edition="alpha"/>
        <vers num="6.0.5"/>
        <vers num="6.0.6" edition="alpha"/>
        <vers num="6.0.7" edition="alpha"/>
        <vers num="6.0.7" edition="beta"/>
        <vers num="6.0.8" edition="alpha"/>
        <vers num="6.0.9" edition="beta"/>
        <vers num="7.0.0" edition="beta"/>
        <vers num="7.0.1"/>
        <vers num="7.0.10"/>
        <vers num="7.0.11"/>
        <vers num="7.0.12"/>
        <vers num="7.0.13"/>
        <vers num="7.0.14"/>
        <vers num="7.0.15"/>
        <vers num="7.0.16"/>
        <vers num="7.0.17"/>
        <vers num="7.0.18"/>
        <vers num="7.0.19"/>
        <vers num="7.0.2" edition="beta"/>
        <vers num="7.0.20"/>
        <vers num="7.0.21"/>
        <vers num="7.0.22"/>
        <vers num="7.0.23"/>
        <vers num="7.0.25"/>
        <vers num="7.0.28"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4" edition="beta"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8"/>
        <vers num="7.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-4008" published="2012-08-31" name="CVE-2012-4008" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://magazine.cybozulive.com/2012/08/291200.html" source="CONFIRM">http://magazine.cybozulive.com/2012/08/291200.html</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000081" source="JVNDB">JVNDB-2012-000081</ref>
      <ref url="http://jvn.jp/en/jp/JVN23009798/index.html" source="JVN">JVN#23009798</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cybozu" name="cybozu_live">
        <vers prev="1" num="1.0.4" edition="-"/>
        <vers prev="1" num="1.0.4" edition="-:~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-4009" published="2012-08-31" name="CVE-2012-4009" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The WebView class in the Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://magazine.cybozulive.com/2012/08/291200.html" source="CONFIRM">http://magazine.cybozulive.com/2012/08/291200.html</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2012-000082" source="JVNDB">JVNDB-2012-000082</ref>
      <ref url="http://jvn.jp/en/jp/JVN77393797/index.html" source="JVN">JVN#77393797</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cybozu" name="cybozu_live">
        <vers prev="1" num="1.0.4" edition="-"/>
        <vers prev="1" num="1.0.4" edition="-:~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-4444" published="2012-12-21" name="CVE-2012-4444" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ip6_frag_queue function in net/ipv6/reassembly.c in the Linux kernel before 2.6.36 allows remote attackers to bypass intended network restrictions via overlapping IPv6 fragments.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/70789d7052239992824628db8133de08dc78e593" source="CONFIRM" patch="1" adv="1">https://github.com/torvalds/linux/commit/70789d7052239992824628db8133de08dc78e593</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=874835" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=874835</ref>
      <ref url="https://media.blackhat.com/bh-eu-12/Atlasis/bh-eu-12-Atlasis-Attacking_IPv6-WP.pdf" source="MISC">https://media.blackhat.com/bh-eu-12/Atlasis/bh-eu-12-Atlasis-Attacking_IPv6-WP.pdf</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1661-1" source="UBUNTU">USN-1661-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1660-1" source="UBUNTU">USN-1660-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/11/09/2" source="MLIST">[oss-security] 20121109 Re: CVE request --- acceptation of overlapping ipv6 fragments</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-1580.html" source="REDHAT">RHSA-2012:1580</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00000.html" source="SUSE">SUSE-SU-2013:0856</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=70789d7052239992824628db8133de08dc78e593" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=70789d7052239992824628db8133de08dc78e593</ref>
      <ref url="http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36" source="CONFIRM">http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.36</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.30" edition="rc1"/>
        <vers num="2.6.30" edition="rc2"/>
        <vers num="2.6.30" edition="rc3"/>
        <vers num="2.6.30" edition="rc4"/>
        <vers num="2.6.30" edition="rc4:x86_32"/>
        <vers num="2.6.30" edition="rc5"/>
        <vers num="2.6.30" edition="rc6"/>
        <vers num="2.6.30" edition="rc7"/>
        <vers num="2.6.30" edition="rc8"/>
        <vers num="2.6.30.1"/>
        <vers num="2.6.30.10"/>
        <vers num="2.6.30.2"/>
        <vers num="2.6.30.3"/>
        <vers num="2.6.30.4"/>
        <vers num="2.6.30.5"/>
        <vers num="2.6.30.6"/>
        <vers num="2.6.30.7"/>
        <vers num="2.6.30.8"/>
        <vers num="2.6.30.9"/>
        <vers num="2.6.31" edition="rc1"/>
        <vers num="2.6.31" edition="rc2"/>
        <vers num="2.6.31" edition="rc3"/>
        <vers num="2.6.31" edition="rc4"/>
        <vers num="2.6.31" edition="rc5"/>
        <vers num="2.6.31" edition="rc6"/>
        <vers num="2.6.31" edition="rc7"/>
        <vers num="2.6.31" edition="rc8"/>
        <vers num="2.6.31" edition="rc9"/>
        <vers num="2.6.31-rc10"/>
        <vers num="2.6.31-rc2"/>
        <vers num="2.6.31-rc3"/>
        <vers num="2.6.31-rc4"/>
        <vers num="2.6.31-rc5"/>
        <vers num="2.6.31-rc6"/>
        <vers num="2.6.31-rc7"/>
        <vers num="2.6.31-rc8"/>
        <vers num="2.6.31-rc9"/>
        <vers num="2.6.31.1"/>
        <vers num="2.6.31.10"/>
        <vers num="2.6.31.11"/>
        <vers num="2.6.31.12"/>
        <vers num="2.6.31.13"/>
        <vers num="2.6.31.14"/>
        <vers num="2.6.31.2"/>
        <vers num="2.6.31.3"/>
        <vers num="2.6.31.4"/>
        <vers num="2.6.31.5"/>
        <vers num="2.6.31.6"/>
        <vers num="2.6.31.7"/>
        <vers num="2.6.31.8"/>
        <vers num="2.6.31.9"/>
        <vers num="2.6.32" edition="rc1"/>
        <vers num="2.6.32" edition="rc3"/>
        <vers num="2.6.32" edition="rc4"/>
        <vers num="2.6.32" edition="rc5"/>
        <vers num="2.6.32" edition="rc6"/>
        <vers num="2.6.32" edition="rc7"/>
        <vers num="2.6.32" edition="rc8"/>
        <vers num="2.6.32.1"/>
        <vers num="2.6.32.10"/>
        <vers num="2.6.32.11"/>
        <vers num="2.6.32.12"/>
        <vers num="2.6.32.13"/>
        <vers num="2.6.32.14"/>
        <vers num="2.6.32.15"/>
        <vers num="2.6.32.16"/>
        <vers num="2.6.32.17"/>
        <vers num="2.6.32.18"/>
        <vers num="2.6.32.19"/>
        <vers num="2.6.32.2"/>
        <vers num="2.6.32.20"/>
        <vers num="2.6.32.21"/>
        <vers num="2.6.32.22"/>
        <vers num="2.6.32.23"/>
        <vers num="2.6.32.24"/>
        <vers num="2.6.32.25"/>
        <vers num="2.6.32.26"/>
        <vers num="2.6.32.27"/>
        <vers num="2.6.32.28"/>
        <vers num="2.6.32.29"/>
        <vers num="2.6.32.3"/>
        <vers num="2.6.32.30"/>
        <vers num="2.6.32.31"/>
        <vers num="2.6.32.32"/>
        <vers num="2.6.32.33"/>
        <vers num="2.6.32.34"/>
        <vers num="2.6.32.35"/>
        <vers num="2.6.32.36"/>
        <vers num="2.6.32.37"/>
        <vers num="2.6.32.38"/>
        <vers num="2.6.32.39"/>
        <vers num="2.6.32.4"/>
        <vers num="2.6.32.40"/>
        <vers num="2.6.32.41"/>
        <vers num="2.6.32.42"/>
        <vers num="2.6.32.43"/>
        <vers num="2.6.32.44"/>
        <vers num="2.6.32.45"/>
        <vers num="2.6.32.46"/>
        <vers num="2.6.32.47"/>
        <vers num="2.6.32.48"/>
        <vers num="2.6.32.49"/>
        <vers num="2.6.32.5"/>
        <vers num="2.6.32.50"/>
        <vers num="2.6.32.51"/>
        <vers num="2.6.32.52"/>
        <vers num="2.6.32.53"/>
        <vers num="2.6.32.54"/>
        <vers num="2.6.32.55"/>
        <vers num="2.6.32.56"/>
        <vers num="2.6.32.57"/>
        <vers num="2.6.32.58"/>
        <vers num="2.6.32.6"/>
        <vers num="2.6.32.7"/>
        <vers num="2.6.32.8"/>
        <vers num="2.6.32.9"/>
        <vers num="2.6.33" edition="rc1"/>
        <vers num="2.6.33" edition="rc2"/>
        <vers num="2.6.33" edition="rc3"/>
        <vers num="2.6.33" edition="rc4"/>
        <vers num="2.6.33" edition="rc5"/>
        <vers num="2.6.33" edition="rc6"/>
        <vers num="2.6.33" edition="rc7"/>
        <vers num="2.6.33" edition="rc8"/>
        <vers num="2.6.33.1"/>
        <vers num="2.6.33.10"/>
        <vers num="2.6.33.11"/>
        <vers num="2.6.33.12"/>
        <vers num="2.6.33.13"/>
        <vers num="2.6.33.14"/>
        <vers num="2.6.33.15"/>
        <vers num="2.6.33.16"/>
        <vers num="2.6.33.17"/>
        <vers num="2.6.33.18"/>
        <vers num="2.6.33.19"/>
        <vers num="2.6.33.2"/>
        <vers num="2.6.33.20"/>
        <vers num="2.6.33.3"/>
        <vers num="2.6.33.4"/>
        <vers num="2.6.33.5"/>
        <vers num="2.6.33.6"/>
        <vers num="2.6.33.7"/>
        <vers num="2.6.33.8"/>
        <vers num="2.6.33.9"/>
        <vers num="2.6.34" edition="rc1"/>
        <vers num="2.6.34" edition="rc2"/>
        <vers num="2.6.34" edition="rc3"/>
        <vers num="2.6.34" edition="rc4"/>
        <vers num="2.6.34" edition="rc5"/>
        <vers num="2.6.34" edition="rc6"/>
        <vers num="2.6.34" edition="rc7"/>
        <vers num="2.6.34.1"/>
        <vers num="2.6.34.10"/>
        <vers num="2.6.34.2"/>
        <vers num="2.6.34.3"/>
        <vers num="2.6.34.4"/>
        <vers num="2.6.34.5"/>
        <vers num="2.6.34.6"/>
        <vers num="2.6.34.7"/>
        <vers num="2.6.34.8"/>
        <vers num="2.6.34.9"/>
        <vers num="2.6.35" edition="rc1"/>
        <vers num="2.6.35" edition="rc2"/>
        <vers num="2.6.35" edition="rc3"/>
        <vers num="2.6.35" edition="rc4"/>
        <vers num="2.6.35" edition="rc5"/>
        <vers num="2.6.35" edition="rc6"/>
        <vers num="2.6.35.1"/>
        <vers num="2.6.35.10"/>
        <vers num="2.6.35.11"/>
        <vers num="2.6.35.12"/>
        <vers num="2.6.35.13"/>
        <vers num="2.6.35.2"/>
        <vers num="2.6.35.3"/>
        <vers num="2.6.35.4"/>
        <vers num="2.6.35.5"/>
        <vers num="2.6.35.6"/>
        <vers num="2.6.35.7"/>
        <vers num="2.6.35.8"/>
        <vers num="2.6.35.9"/>
        <vers prev="1" num="2.6.36" edition="rc1"/>
        <vers prev="1" num="2.6.36" edition="rc2"/>
        <vers prev="1" num="2.6.36" edition="rc3"/>
        <vers prev="1" num="2.6.36" edition="rc4"/>
        <vers prev="1" num="2.6.36" edition="rc5"/>
        <vers prev="1" num="2.6.36" edition="rc6"/>
        <vers prev="1" num="2.6.36" edition="rc7"/>
        <vers prev="1" num="2.6.36" edition="rc8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-4461" published="2013-01-22" name="CVE-2012-4461" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The KVM subsystem in the Linux kernel before 3.6.9, when running on hosts that use qemu userspace without XSAVE, allows local users to cause a denial of service (kernel OOPS) by using the KVM_SET_SREGS ioctl to set the X86_CR4_OSXSAVE bit in the guest cr4 register, then calling the KVM_RUN ioctl.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux.git;a=commit;h=6d1068b3a98519247d8ba4ec85cd40ac136dbdf9" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux.git;a=commit;h=6d1068b3a98519247d8ba4ec85cd40ac136dbdf9</ref>
      <ref url="https://www.suse.com/support/update/announcement/2012/suse-su-20121679-1.html" source="SUSE">SUSE-SU-2012:1679</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=862900" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=862900</ref>
      <ref url="http://www.securityfocus.com/bid/56414" source="BID">56414</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2012/11/06/14" source="MLIST">[oss-security] 20121106 CVE-2012-4461 -- kernel: kvm: invalid opcode oops on SET_SREGS with OSXSAVE bit set</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.6.9" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.6.9</ref>
      <ref url="http://secunia.com/advisories/51160" source="SECUNIA">51160</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0882.html" source="REDHAT">RHSA-2013:0882</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0223.html" source="REDHAT">RHSA-2013:0223</ref>
      <ref url="http://article.gmane.org/gmane.comp.emulators.kvm.devel/100742" source="MISC">http://article.gmane.org/gmane.comp.emulators.kvm.devel/100742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers prev="1" num="3.6.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-4542" published="2013-02-28" name="CVE-2012-4542" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">block/scsi_ioctl.c in the Linux kernel through 3.8 does not properly consider the SCSI device class during authorization of SCSI commands, which allows local users to bypass intended access restrictions via an SG_IO ioctl call that leverages overlapping opcodes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://oss.oracle.com/git/?p=redpatch.git;a=commit;h=76a274e17114abf1a77de6b651424648ce9e10c8" source="CONFIRM">https://oss.oracle.com/git/?p=redpatch.git;a=commit;h=76a274e17114abf1a77de6b651424648ce9e10c8</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=875360" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=875360</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0882.html" source="REDHAT">RHSA-2013:0882</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0579.html" source="REDHAT">RHSA-2013:0579</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0496.html" source="REDHAT">RHSA-2013:0496</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=135904012416042&amp;w=2" source="MLIST">[linux-kernel] 20130124 [PATCH 04/13] sg_io: resolve conflicts between commands assigned to multiple classes (CVE-2012-4542)</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=135903967015813&amp;w=2" source="MLIST">[linux-kernel] 20130124 [PATCH 00/13] Corrections and customization of the SG_IO command whitelist (CVE-2012-4542)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.10"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers num="3.7.9"/>
        <vers prev="1" num="3.8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-6564" published="2013-06-17" name="CVE-2012-6564" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in REDCap before 4.14.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers prev="1" num="4.14.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-6565" published="2013-06-17" name="CVE-2012-6565" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in REDCap before 4.14.3 allows remote authenticated users to inject arbitrary web script or HTML via uppercase characters in JavaScript events within user-defined labels.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers prev="1" num="4.14.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-6566" published="2013-06-17" name="CVE-2012-6566" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in REDCap before 4.14.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.14.0"/>
        <vers prev="1" num="4.14.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-6567" published="2013-06-17" name="CVE-2012-6567" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">REDCap before 4.14.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the logic of a custom rule.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers prev="1" num="4.13.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0148" published="2013-06-16" name="CVE-2013-0148" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The Data Camouflage (aka Faircom Standard Encryption) algorithm in Faircom c-treeACE does not ensure that a decryption key is needed for accessing database contents, which allows context-dependent attackers to read cleartext database records by copying a database to another system that has a certain default configuration.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/900031" source="CERT-VN">VU#900031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="faircom" name="c-treeace">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0311" published="2013-02-21" name="CVE-2013-0311" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:A/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="6.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.5" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The translate_desc function in drivers/vhost/vhost.c in the Linux kernel before 3.7 does not properly handle cross-region descriptors, which allows guest OS users to obtain host OS privileges by leveraging KVM guest OS privileges.</descript>
      <descript source="nvd">Per https://access.redhat.com/security/cve/CVE-2013-0311
"This issue did affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 6."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/patch-3.7.bz2" source="CONFIRM" patch="1">http://www.kernel.org/pub/linux/kernel/v3.x/patch-3.7.bz2</ref>
      <ref url="https://github.com/torvalds/linux/commit/bd97120fc3d1a11f3124c7c9ba1d91f51829eb85" source="CONFIRM">https://github.com/torvalds/linux/commit/bd97120fc3d1a11f3124c7c9ba1d91f51829eb85</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=912905" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=912905</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/20/6" source="MLIST">[oss-security] 20130219 Re: CVE request -- Linux kernel: vhost: fix length for cross region descriptor</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0882.html" source="REDHAT">RHSA-2013:0882</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0579.html" source="REDHAT">RHSA-2013:0579</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0496.html" source="REDHAT">RHSA-2013:0496</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=bd97120fc3d1a11f3124c7c9ba1d91f51829eb85" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=bd97120fc3d1a11f3124c7c9ba1d91f51829eb85</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6.10"/>
        <vers prev="1" num="3.6.11"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0467" published="2013-02-20" name="CVE-2013-0467" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">IBM Eclipse Help System (IEHS), as used in IBM Data Studio 3.1 and 3.1.1 and other products, allows remote authenticated users to read source code via a crafted URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81102" source="XF" adv="1">iehs-source-disclosure(81102)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21625573" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21625573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="data_studio">
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0484" published="2013-06-19" name="CVE-2013-0484" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The server process in IBM Cognos TM1 10.1.x before 10.1.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via an undocumented API call that triggers the transmission of unexpected data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81612" source="XF">tm1-undocumented-api(81612)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21637655" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21637655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="cognos_tm1">
        <vers num="10.1.0"/>
        <vers num="10.1.0.1"/>
        <vers num="10.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0773" published="2013-02-19" name="CVE-2013-0773" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent modifications to a prototype, which allows remote attackers to obtain sensitive information from chrome objects or possibly execute arbitrary JavaScript code with chrome privileges via a crafted web site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=809652" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=809652</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1748-1" source="UBUNTU">USN-1748-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1729-2" source="UBUNTU">USN-1729-2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1729-1" source="UBUNTU">USN-1729-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-24.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-24.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html" source="SUSE">openSUSE-SU-2013:0324</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html" source="SUSE">openSUSE-SU-2013:0323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1"/>
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.4.1"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.8"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="11.0"/>
        <vers num="12.0" edition="beta6"/>
        <vers num="13.0"/>
        <vers num="13.0.1"/>
        <vers num="14.0"/>
        <vers num="14.0.1"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="18.0"/>
        <vers num="18.0.1"/>
        <vers prev="1" num="18.0.2"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.17"/>
        <vers num="3.6.18"/>
        <vers num="3.6.19"/>
        <vers num="3.6.2"/>
        <vers num="3.6.20"/>
        <vers num="3.6.21"/>
        <vers num="3.6.22"/>
        <vers num="3.6.23"/>
        <vers num="3.6.24"/>
        <vers num="3.6.25"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
        <vers num="4.0.1"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="8.0.1"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.14.1"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers prev="1" num="2.16" edition="beta1"/>
        <vers prev="1" num="2.16" edition="beta2"/>
        <vers prev="1" num="2.16" edition="beta3"/>
        <vers prev="1" num="2.16" edition="beta4"/>
        <vers prev="1" num="2.16" edition="beta5"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5" edition="beta"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="11.0"/>
        <vers num="11.0.1"/>
        <vers num="12.0"/>
        <vers num="12.0.1"/>
        <vers num="13.0"/>
        <vers num="13.0.1"/>
        <vers num="14.0"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
        <vers num="17.0"/>
        <vers prev="1" num="17.0.2"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.11"/>
        <vers num="3.1.12"/>
        <vers num="3.1.13"/>
        <vers num="3.1.14"/>
        <vers num="3.1.15"/>
        <vers num="3.1.16"/>
        <vers num="3.1.17"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0775" published="2013-02-19" name="CVE-2013-0775" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via crafted web script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=831095" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=831095</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1748-1" source="UBUNTU">USN-1748-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1729-2" source="UBUNTU">USN-1729-2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1729-1" source="UBUNTU">USN-1729-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-26.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-26.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0272.html" source="REDHAT">RHSA-2013:0272</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0271.html" source="REDHAT">RHSA-2013:0271</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html" source="SUSE">openSUSE-SU-2013:0324</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html" source="SUSE">openSUSE-SU-2013:0323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1"/>
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.4.1"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.8"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="11.0"/>
        <vers num="12.0" edition="beta6"/>
        <vers num="13.0"/>
        <vers num="13.0.1"/>
        <vers num="14.0"/>
        <vers num="14.0.1"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="18.0"/>
        <vers num="18.0.1"/>
        <vers prev="1" num="18.0.2"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.17"/>
        <vers num="3.6.18"/>
        <vers num="3.6.19"/>
        <vers num="3.6.2"/>
        <vers num="3.6.20"/>
        <vers num="3.6.21"/>
        <vers num="3.6.22"/>
        <vers num="3.6.23"/>
        <vers num="3.6.24"/>
        <vers num="3.6.25"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
        <vers num="4.0.1"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="8.0.1"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":dev"/>
        <vers num="1.0" edition=":beta"/>
        <vers num="1.0" edition=":alpha"/>
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.0.99"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5" edition="1.1.10"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0a1" edition=""/>
        <vers num="2.0a1" edition=":pre"/>
        <vers num="2.0a1pre"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.14.1"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers prev="1" num="2.16" edition="beta1"/>
        <vers prev="1" num="2.16" edition="beta2"/>
        <vers prev="1" num="2.16" edition="beta3"/>
        <vers prev="1" num="2.16" edition="beta4"/>
        <vers prev="1" num="2.16" edition="beta5"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5" edition="beta"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="11.0"/>
        <vers num="11.0.1"/>
        <vers num="12.0"/>
        <vers num="12.0.1"/>
        <vers num="13.0"/>
        <vers num="13.0.1"/>
        <vers num="14.0"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
        <vers num="17.0"/>
        <vers prev="1" num="17.0.2"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.11"/>
        <vers num="3.1.12"/>
        <vers num="3.1.13"/>
        <vers num="3.1.14"/>
        <vers num="3.1.15"/>
        <vers num="3.1.16"/>
        <vers num="3.1.17"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0776" published="2013-02-19" name="CVE-2013-0776" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow man-in-the-middle attackers to spoof the address bar by operating a proxy server that provides a 407 HTTP status code accompanied by web script, as demonstrated by a phishing attack on an HTTPS site.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=796475" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=796475</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1748-1" source="UBUNTU">USN-1748-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1729-2" source="UBUNTU">USN-1729-2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1729-1" source="UBUNTU">USN-1729-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-27.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-27.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0272.html" source="REDHAT">RHSA-2013:0272</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0271.html" source="REDHAT">RHSA-2013:0271</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html" source="SUSE">openSUSE-SU-2013:0324</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html" source="SUSE">openSUSE-SU-2013:0323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1"/>
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.4.1"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.8"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="11.0"/>
        <vers num="12.0" edition="beta6"/>
        <vers num="13.0"/>
        <vers num="13.0.1"/>
        <vers num="14.0"/>
        <vers num="14.0.1"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="18.0"/>
        <vers num="18.0.1"/>
        <vers prev="1" num="18.0.2"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.17"/>
        <vers num="3.6.18"/>
        <vers num="3.6.19"/>
        <vers num="3.6.2"/>
        <vers num="3.6.20"/>
        <vers num="3.6.21"/>
        <vers num="3.6.22"/>
        <vers num="3.6.23"/>
        <vers num="3.6.24"/>
        <vers num="3.6.25"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
        <vers num="4.0.1"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="8.0.1"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":dev"/>
        <vers num="1.0" edition=":beta"/>
        <vers num="1.0" edition=":alpha"/>
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.0.99"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5" edition="1.1.10"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0a1" edition=""/>
        <vers num="2.0a1" edition=":pre"/>
        <vers num="2.0a1pre"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.14.1"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers prev="1" num="2.16" edition="beta1"/>
        <vers prev="1" num="2.16" edition="beta2"/>
        <vers prev="1" num="2.16" edition="beta3"/>
        <vers prev="1" num="2.16" edition="beta4"/>
        <vers prev="1" num="2.16" edition="beta5"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5" edition="beta"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="11.0"/>
        <vers num="11.0.1"/>
        <vers num="12.0"/>
        <vers num="12.0.1"/>
        <vers num="13.0"/>
        <vers num="13.0.1"/>
        <vers num="14.0"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
        <vers num="17.0"/>
        <vers prev="1" num="17.0.2"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.11"/>
        <vers num="3.1.12"/>
        <vers num="3.1.13"/>
        <vers num="3.1.14"/>
        <vers num="3.1.15"/>
        <vers num="3.1.16"/>
        <vers num="3.1.17"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0780" published="2013-02-19" name="CVE-2013-0780" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the nsOverflowContinuationTracker::Finish function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted document that uses Cascading Style Sheets (CSS) -moz-column-* properties.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=812893" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=812893</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1748-1" source="UBUNTU">USN-1748-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1729-2" source="UBUNTU">USN-1729-2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1729-1" source="UBUNTU">USN-1729-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-28.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-28.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0272.html" source="REDHAT">RHSA-2013:0272</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0271.html" source="REDHAT">RHSA-2013:0271</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html" source="SUSE">openSUSE-SU-2013:0324</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html" source="SUSE">openSUSE-SU-2013:0323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1"/>
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.4.1"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.8"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="11.0"/>
        <vers num="12.0" edition="beta6"/>
        <vers num="13.0"/>
        <vers num="13.0.1"/>
        <vers num="14.0"/>
        <vers num="14.0.1"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="18.0"/>
        <vers num="18.0.1"/>
        <vers prev="1" num="18.0.2"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.17"/>
        <vers num="3.6.18"/>
        <vers num="3.6.19"/>
        <vers num="3.6.2"/>
        <vers num="3.6.20"/>
        <vers num="3.6.21"/>
        <vers num="3.6.22"/>
        <vers num="3.6.23"/>
        <vers num="3.6.24"/>
        <vers num="3.6.25"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
        <vers num="4.0.1"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="8.0.1"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":dev"/>
        <vers num="1.0" edition=":beta"/>
        <vers num="1.0" edition=":alpha"/>
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.0.99"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5" edition="1.1.10"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0a1" edition=""/>
        <vers num="2.0a1" edition=":pre"/>
        <vers num="2.0a1pre"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.14.1"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers prev="1" num="2.16" edition="beta1"/>
        <vers prev="1" num="2.16" edition="beta2"/>
        <vers prev="1" num="2.16" edition="beta3"/>
        <vers prev="1" num="2.16" edition="beta4"/>
        <vers prev="1" num="2.16" edition="beta5"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5" edition="beta"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="11.0"/>
        <vers num="11.0.1"/>
        <vers num="12.0"/>
        <vers num="12.0.1"/>
        <vers num="13.0"/>
        <vers num="13.0.1"/>
        <vers num="14.0"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
        <vers num="17.0"/>
        <vers prev="1" num="17.0.2"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.11"/>
        <vers num="3.1.12"/>
        <vers num="3.1.13"/>
        <vers num="3.1.14"/>
        <vers num="3.1.15"/>
        <vers num="3.1.16"/>
        <vers num="3.1.17"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0782" published="2013-02-19" name="CVE-2013-0782" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the nsSaveAsCharset::DoCharsetConversion function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=827070" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=827070</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1748-1" source="UBUNTU">USN-1748-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1729-2" source="UBUNTU">USN-1729-2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1729-1" source="UBUNTU">USN-1729-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-28.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-28.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0272.html" source="REDHAT">RHSA-2013:0272</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0271.html" source="REDHAT">RHSA-2013:0271</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html" source="SUSE">openSUSE-SU-2013:0324</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html" source="SUSE">openSUSE-SU-2013:0323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1"/>
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.4.1"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.8"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="11.0"/>
        <vers num="12.0" edition="beta6"/>
        <vers num="13.0"/>
        <vers num="13.0.1"/>
        <vers num="14.0"/>
        <vers num="14.0.1"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="18.0"/>
        <vers num="18.0.1"/>
        <vers prev="1" num="18.0.2"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.17"/>
        <vers num="3.6.18"/>
        <vers num="3.6.19"/>
        <vers num="3.6.2"/>
        <vers num="3.6.20"/>
        <vers num="3.6.21"/>
        <vers num="3.6.22"/>
        <vers num="3.6.23"/>
        <vers num="3.6.24"/>
        <vers num="3.6.25"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
        <vers num="4.0.1"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="8.0.1"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":dev"/>
        <vers num="1.0" edition=":beta"/>
        <vers num="1.0" edition=":alpha"/>
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.0.99"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5" edition="1.1.10"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0a1" edition=""/>
        <vers num="2.0a1" edition=":pre"/>
        <vers num="2.0a1pre"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.14.1"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers prev="1" num="2.16" edition="beta1"/>
        <vers prev="1" num="2.16" edition="beta2"/>
        <vers prev="1" num="2.16" edition="beta3"/>
        <vers prev="1" num="2.16" edition="beta4"/>
        <vers prev="1" num="2.16" edition="beta5"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5" edition="beta"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="11.0"/>
        <vers num="11.0.1"/>
        <vers num="12.0"/>
        <vers num="12.0.1"/>
        <vers num="13.0"/>
        <vers num="13.0.1"/>
        <vers num="14.0"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
        <vers num="17.0"/>
        <vers prev="1" num="17.0.2"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.11"/>
        <vers num="3.1.12"/>
        <vers num="3.1.13"/>
        <vers num="3.1.14"/>
        <vers num="3.1.15"/>
        <vers num="3.1.16"/>
        <vers num="3.1.17"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0783" published="2013-02-19" name="CVE-2013-0783" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=832162" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=832162</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=830975" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=830975</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=830399" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=830399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=826471" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=826471</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=822858" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=822858</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=818241" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=818241</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=812380" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=812380</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=780549" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=780549</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=761448" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=761448</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=690970" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=690970</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1748-1" source="UBUNTU">USN-1748-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1729-2" source="UBUNTU">USN-1729-2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1729-1" source="UBUNTU">USN-1729-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-21.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-21.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0272.html" source="REDHAT">RHSA-2013:0272</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0271.html" source="REDHAT">RHSA-2013:0271</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-02/msg00062.html" source="SUSE">openSUSE-SU-2013:0324</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00017.html" source="SUSE">openSUSE-SU-2013:0323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1"/>
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.4.1"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.8"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="11.0"/>
        <vers num="12.0" edition="beta6"/>
        <vers num="13.0"/>
        <vers num="13.0.1"/>
        <vers num="14.0"/>
        <vers num="14.0.1"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="18.0"/>
        <vers num="18.0.1"/>
        <vers prev="1" num="18.0.2"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.17"/>
        <vers num="3.6.18"/>
        <vers num="3.6.19"/>
        <vers num="3.6.2"/>
        <vers num="3.6.20"/>
        <vers num="3.6.21"/>
        <vers num="3.6.22"/>
        <vers num="3.6.23"/>
        <vers num="3.6.24"/>
        <vers num="3.6.25"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
        <vers num="4.0.1"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="8.0.1"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":dev"/>
        <vers num="1.0" edition=":beta"/>
        <vers num="1.0" edition=":alpha"/>
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.0.99"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5" edition="1.1.10"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0a1" edition=""/>
        <vers num="2.0a1" edition=":pre"/>
        <vers num="2.0a1pre"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.14.1"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers prev="1" num="2.16" edition="beta1"/>
        <vers prev="1" num="2.16" edition="beta2"/>
        <vers prev="1" num="2.16" edition="beta3"/>
        <vers prev="1" num="2.16" edition="beta4"/>
        <vers prev="1" num="2.16" edition="beta5"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5" edition="beta"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="11.0"/>
        <vers num="11.0.1"/>
        <vers num="12.0"/>
        <vers num="12.0.1"/>
        <vers num="13.0"/>
        <vers num="13.0.1"/>
        <vers num="14.0"/>
        <vers num="15.0"/>
        <vers num="15.0.1"/>
        <vers num="16.0"/>
        <vers num="16.0.1"/>
        <vers num="16.0.2"/>
        <vers num="17.0"/>
        <vers prev="1" num="17.0.2"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.11"/>
        <vers num="3.1.12"/>
        <vers num="3.1.13"/>
        <vers num="3.1.14"/>
        <vers num="3.1.15"/>
        <vers num="3.1.16"/>
        <vers num="3.1.17"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0"/>
        <vers num="9.0"/>
        <vers num="9.0.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0787" published="2013-03-11" name="CVE-2013-0787" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEditor.cpp in Mozilla Firefox before 19.0.2, Firefox ESR 17.x before 17.0.4, Thunderbird before 17.0.4, Thunderbird ESR 17.x before 17.0.4, and SeaMonkey before 2.16.1 allows remote attackers to execute arbitrary code via vectors involving an execCommand call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=848644" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=848644</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1758-1" source="UBUNTU">USN-1758-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-29.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-29.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://twitter.com/VUPEN/statuses/309505403631325184" source="MISC">http://twitter.com/VUPEN/statuses/309505403631325184</ref>
      <ref url="http://twitter.com/thezdi/statuses/309484730506698752" source="MISC">http://twitter.com/thezdi/statuses/309484730506698752</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0627.html" source="REDHAT">RHSA-2013:0627</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0614.html" source="REDHAT">RHSA-2013:0614</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00028.html" source="SUSE">SUSE-SU-2013:0470</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00026.html" source="SUSE">openSUSE-SU-2013:0468</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00025.html" source="SUSE">openSUSE-SU-2013:0467</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00023.html" source="SUSE">openSUSE-SU-2013:0465</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00010.html" source="SUSE">openSUSE-SU-2013:0431</ref>
      <ref url="http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157" source="MISC">http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers prev="1" num="19.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="2.16" edition="beta1"/>
        <vers prev="1" num="2.16" edition="beta2"/>
        <vers prev="1" num="2.16" edition="beta3"/>
        <vers prev="1" num="2.16" edition="beta4"/>
        <vers prev="1" num="2.16" edition="beta5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers prev="1" num="17.0.3"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0788" published="2013-04-03" name="CVE-2013-0788" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=852923" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=852923</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=840353" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=840353</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=840263" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=840263</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=839621" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=839621</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=834240" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=834240</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=827870" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=827870</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=813442" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=813442</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=784730" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=784730</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=771942" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=771942</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=635852" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=635852</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1791-1" source="UBUNTU">USN-1791-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-30.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-30.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0697.html" source="REDHAT">RHSA-2013:0697</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0696.html" source="REDHAT">RHSA-2013:0696</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html" source="SUSE">SUSE-SU-2013:0850</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html" source="SUSE">SUSE-SU-2013:0645</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.html" source="SUSE">openSUSE-SU-2013:0631</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.html" source="SUSE">openSUSE-SU-2013:0630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers prev="1" num="19.0.2"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers num="2.16" edition="beta1"/>
        <vers num="2.16" edition="beta2"/>
        <vers num="2.16" edition="beta3"/>
        <vers num="2.16" edition="beta4"/>
        <vers num="2.16" edition="beta5"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers prev="1" num="2.17" edition="beta1"/>
        <vers prev="1" num="2.17" edition="beta2"/>
        <vers prev="1" num="2.17" edition="beta3"/>
        <vers prev="1" num="2.17" edition="beta4"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0791" published="2013-04-03" name="CVE-2013-0791" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=629816" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=629816</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1791-1" source="UBUNTU">USN-1791-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-40.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-40.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html" source="SUSE">SUSE-SU-2013:0850</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html" source="SUSE">SUSE-SU-2013:0645</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.html" source="SUSE">openSUSE-SU-2013:0631</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.html" source="SUSE">openSUSE-SU-2013:0630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers prev="1" num="19.0.2"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="network_security_services">
        <vers num=""/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers num="2.16" edition="beta1"/>
        <vers num="2.16" edition="beta2"/>
        <vers num="2.16" edition="beta3"/>
        <vers num="2.16" edition="beta4"/>
        <vers num="2.16" edition="beta5"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers prev="1" num="2.17" edition="beta1"/>
        <vers prev="1" num="2.17" edition="beta2"/>
        <vers prev="1" num="2.17" edition="beta3"/>
        <vers prev="1" num="2.17" edition="beta4"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0792" published="2013-04-03" name="CVE-2013-0792" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_management.enablev4 is used, do not properly handle color profiles during PNG rendering, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a grayscale PNG image.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=722831" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=722831</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-39.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-39.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html" source="SUSE">SUSE-SU-2013:0850</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html" source="SUSE">SUSE-SU-2013:0645</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.html" source="SUSE">openSUSE-SU-2013:0631</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.html" source="SUSE">openSUSE-SU-2013:0630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers prev="1" num="19.0.2"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers num="2.16" edition="beta1"/>
        <vers num="2.16" edition="beta2"/>
        <vers num="2.16" edition="beta3"/>
        <vers num="2.16" edition="beta4"/>
        <vers num="2.16" edition="beta5"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers prev="1" num="2.17" edition="beta1"/>
        <vers prev="1" num="2.17" edition="beta2"/>
        <vers prev="1" num="2.17" edition="beta3"/>
        <vers prev="1" num="2.17" edition="beta4"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0793" published="2013-04-03" name="CVE-2013-0793" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 do not ensure the correctness of the address bar during history navigation, which allows remote attackers to conduct cross-site scripting (XSS) attacks or phishing attacks by leveraging control over navigation timing.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=803870" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=803870</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1791-1" source="UBUNTU">USN-1791-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-38.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-38.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0697.html" source="REDHAT">RHSA-2013:0697</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0696.html" source="REDHAT">RHSA-2013:0696</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html" source="SUSE">SUSE-SU-2013:0850</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html" source="SUSE">SUSE-SU-2013:0645</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.html" source="SUSE">openSUSE-SU-2013:0631</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.html" source="SUSE">openSUSE-SU-2013:0630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers prev="1" num="19.0.2"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers num="2.16" edition="beta1"/>
        <vers num="2.16" edition="beta2"/>
        <vers num="2.16" edition="beta3"/>
        <vers num="2.16" edition="beta4"/>
        <vers num="2.16" edition="beta5"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers prev="1" num="2.17" edition="beta1"/>
        <vers prev="1" num="2.17" edition="beta2"/>
        <vers prev="1" num="2.17" edition="beta3"/>
        <vers prev="1" num="2.17" edition="beta4"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0794" published="2013-04-03" name="CVE-2013-0794" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal dialogs, which allows remote attackers to conduct phishing attacks via a crafted web site.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=626775" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=626775</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-37.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-37.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html" source="SUSE">SUSE-SU-2013:0850</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html" source="SUSE">SUSE-SU-2013:0645</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.html" source="SUSE">openSUSE-SU-2013:0631</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.html" source="SUSE">openSUSE-SU-2013:0630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers prev="1" num="19.0.2"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers num="2.16" edition="beta1"/>
        <vers num="2.16" edition="beta2"/>
        <vers num="2.16" edition="beta3"/>
        <vers num="2.16" edition="beta4"/>
        <vers num="2.16" edition="beta5"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers prev="1" num="2.17" edition="beta1"/>
        <vers prev="1" num="2.17" edition="beta2"/>
        <vers prev="1" num="2.17" edition="beta3"/>
        <vers prev="1" num="2.17" edition="beta4"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0795" published="2013-04-03" name="CVE-2013-0795" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 does not prevent use of the cloneNode method for cloning a protected node, which allows remote attackers to bypass the Same Origin Policy or possibly execute arbitrary JavaScript code with chrome privileges via a crafted web site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=825697" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=825697</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1791-1" source="UBUNTU">USN-1791-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-36.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-36.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0697.html" source="REDHAT">RHSA-2013:0697</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0696.html" source="REDHAT">RHSA-2013:0696</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html" source="SUSE">SUSE-SU-2013:0850</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html" source="SUSE">SUSE-SU-2013:0645</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.html" source="SUSE">openSUSE-SU-2013:0631</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.html" source="SUSE">openSUSE-SU-2013:0630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers prev="1" num="19.0.2"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers num="2.16" edition="beta1"/>
        <vers num="2.16" edition="beta2"/>
        <vers num="2.16" edition="beta3"/>
        <vers num="2.16" edition="beta4"/>
        <vers num="2.16" edition="beta5"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers prev="1" num="2.17" edition="beta1"/>
        <vers prev="1" num="2.17" edition="beta2"/>
        <vers prev="1" num="2.17" edition="beta3"/>
        <vers prev="1" num="2.17" edition="beta4"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0796" published="2013-04-03" name="CVE-2013-0796" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The WebGL subsystem in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 on Linux does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (free of unallocated memory) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=838413" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=838413</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=827106" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=827106</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1791-1" source="UBUNTU">USN-1791-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-35.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-35.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0697.html" source="REDHAT">RHSA-2013:0697</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0696.html" source="REDHAT">RHSA-2013:0696</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html" source="SUSE">SUSE-SU-2013:0850</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html" source="SUSE">SUSE-SU-2013:0645</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.html" source="SUSE">openSUSE-SU-2013:0631</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.html" source="SUSE">openSUSE-SU-2013:0630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers prev="1" num="19.0.2"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers num="2.16" edition="beta1"/>
        <vers num="2.16" edition="beta2"/>
        <vers num="2.16" edition="beta3"/>
        <vers num="2.16" edition="beta4"/>
        <vers num="2.16" edition="beta5"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers prev="1" num="2.17" edition="beta1"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0797" published="2013-04-03" name="CVE-2013-0797" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the Mozilla Updater in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 allows local users to gain privileges via a Trojan horse DLL file in an unspecified directory.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=830134" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=830134</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-34.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-34.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html" source="SUSE">SUSE-SU-2013:0850</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html" source="SUSE">SUSE-SU-2013:0645</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers prev="1" num="19.0.2"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers num="2.16" edition="beta1"/>
        <vers num="2.16" edition="beta2"/>
        <vers num="2.16" edition="beta3"/>
        <vers num="2.16" edition="beta4"/>
        <vers num="2.16" edition="beta5"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers prev="1" num="2.17" edition="beta1"/>
        <vers prev="1" num="2.17" edition="beta2"/>
        <vers prev="1" num="2.17" edition="beta3"/>
        <vers prev="1" num="2.17" edition="beta4"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0799" published="2013-04-03" name="CVE-2013-0799" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Mozilla Maintenance Service in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, and Thunderbird ESR 17.x before 17.0.5 on Windows allows local users to gain privileges via crafted arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=848417" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=848417</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-32.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-32.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html" source="SUSE">SUSE-SU-2013:0850</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html" source="SUSE">SUSE-SU-2013:0645</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers prev="1" num="19.0.2"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0800" published="2013-04-03" name="CVE-2013-0800" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=825721" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=825721</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1791-1" source="UBUNTU">USN-1791-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-31.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-31.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0697.html" source="REDHAT">RHSA-2013:0697</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0696.html" source="REDHAT">RHSA-2013:0696</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.html" source="SUSE">SUSE-SU-2013:0850</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.html" source="SUSE">SUSE-SU-2013:0645</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.html" source="SUSE">openSUSE-SU-2013:0631</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.html" source="SUSE">openSUSE-SU-2013:0630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cairographics" name="cairo">
        <vers num="-"/>
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers prev="1" num="19.0.2"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
        <vers num="2.1" edition="beta1"/>
        <vers num="2.1" edition="beta2"/>
        <vers num="2.1" edition="beta3"/>
        <vers num="2.1" edition="rc1"/>
        <vers num="2.1" edition="rc2"/>
        <vers num="2.10" edition="beta1"/>
        <vers num="2.10" edition="beta2"/>
        <vers num="2.10" edition="beta3"/>
        <vers num="2.10.1"/>
        <vers num="2.11" edition="beta1"/>
        <vers num="2.11" edition="beta2"/>
        <vers num="2.11" edition="beta3"/>
        <vers num="2.11" edition="beta4"/>
        <vers num="2.11" edition="beta5"/>
        <vers num="2.11" edition="beta6"/>
        <vers num="2.12" edition="beta1"/>
        <vers num="2.12" edition="beta2"/>
        <vers num="2.12" edition="beta3"/>
        <vers num="2.12" edition="beta4"/>
        <vers num="2.12" edition="beta5"/>
        <vers num="2.12" edition="beta6"/>
        <vers num="2.12.1"/>
        <vers num="2.13" edition="beta1"/>
        <vers num="2.13" edition="beta2"/>
        <vers num="2.13" edition="beta3"/>
        <vers num="2.13" edition="beta4"/>
        <vers num="2.13" edition="beta5"/>
        <vers num="2.13" edition="beta6"/>
        <vers num="2.13.1"/>
        <vers num="2.13.2"/>
        <vers num="2.14" edition="beta1"/>
        <vers num="2.14" edition="beta2"/>
        <vers num="2.14" edition="beta3"/>
        <vers num="2.14" edition="beta4"/>
        <vers num="2.14" edition="beta5"/>
        <vers num="2.15" edition="beta1"/>
        <vers num="2.15" edition="beta2"/>
        <vers num="2.15" edition="beta3"/>
        <vers num="2.15" edition="beta4"/>
        <vers num="2.15" edition="beta5"/>
        <vers num="2.15" edition="beta6"/>
        <vers num="2.15.1"/>
        <vers num="2.15.2"/>
        <vers num="2.16" edition="beta1"/>
        <vers num="2.16" edition="beta2"/>
        <vers num="2.16" edition="beta3"/>
        <vers num="2.16" edition="beta4"/>
        <vers num="2.16" edition="beta5"/>
        <vers num="2.16.1"/>
        <vers num="2.16.2"/>
        <vers prev="1" num="2.17" edition="beta1"/>
        <vers prev="1" num="2.17" edition="beta2"/>
        <vers prev="1" num="2.17" edition="beta3"/>
        <vers prev="1" num="2.17" edition="beta4"/>
        <vers num="2.2" edition="beta1"/>
        <vers num="2.2" edition="beta2"/>
        <vers num="2.2" edition="beta3"/>
        <vers num="2.3" edition="beta1"/>
        <vers num="2.3" edition="beta2"/>
        <vers num="2.3" edition="beta3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.4" edition="beta1"/>
        <vers num="2.4" edition="beta2"/>
        <vers num="2.4" edition="beta3"/>
        <vers num="2.4.1"/>
        <vers num="2.5" edition="beta1"/>
        <vers num="2.5" edition="beta2"/>
        <vers num="2.5" edition="beta3"/>
        <vers num="2.5" edition="beta4"/>
        <vers num="2.6" edition="beta1"/>
        <vers num="2.6" edition="beta2"/>
        <vers num="2.6" edition="beta3"/>
        <vers num="2.6" edition="beta4"/>
        <vers num="2.6.1"/>
        <vers num="2.7" edition="beta1"/>
        <vers num="2.7" edition="beta2"/>
        <vers num="2.7" edition="beta3"/>
        <vers num="2.7" edition="beta4"/>
        <vers num="2.7" edition="beta5"/>
        <vers num="2.7.1"/>
        <vers num="2.7.2"/>
        <vers num="2.8" edition="beta1"/>
        <vers num="2.8" edition="beta2"/>
        <vers num="2.8" edition="beta3"/>
        <vers num="2.8" edition="beta4"/>
        <vers num="2.8" edition="beta5"/>
        <vers num="2.8" edition="beta6"/>
        <vers num="2.9" edition="beta1"/>
        <vers num="2.9" edition="beta2"/>
        <vers num="2.9" edition="beta3"/>
        <vers num="2.9" edition="beta4"/>
        <vers num="2.9.1"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
      </prod>
      <prod vendor="pixman" name="pixman">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0801" published="2013-05-16" name="CVE-2013-0801" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=866544" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=866544</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=864558" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=864558</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=852315" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=852315</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=849597" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=849597</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=808402" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=808402</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=787283" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=787283</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1823-1" source="UBUNTU">USN-1823-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1822-1" source="UBUNTU">USN-1822-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-41.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-41.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0821.html" source="REDHAT">RHSA-2013:0821</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0820.html" source="REDHAT">RHSA-2013:0820</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html" source="SUSE">openSUSE-SU-2013:0834</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html" source="SUSE">openSUSE-SU-2013:0831</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html" source="SUSE">openSUSE-SU-2013:0825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers num="19.0.2"/>
        <vers num="20.0"/>
        <vers prev="1" num="20.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers prev="1" num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0913" published="2013-03-18" name="CVE-2013-0913" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted application that triggers many relocation copies, and potentially leads to a race condition.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://lkml.org/lkml/2013/3/11/501" source="MLIST">[linux-kernel] 20130311 [PATCH] drm/i915: bounds check execbuffer relocations</ref>
      <ref url="https://gerrit.chromium.org/gerrit/45118" source="CONFIRM">https://gerrit.chromium.org/gerrit/45118</ref>
      <ref url="https://code.google.com/p/chromium-os/issues/detail?id=39733" source="CONFIRM">https://code.google.com/p/chromium-os/issues/detail?id=39733</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=920471" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=920471</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1814-1" source="UBUNTU">USN-1814-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1813-1" source="UBUNTU">USN-1813-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1812-1" source="UBUNTU">USN-1812-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1811-1" source="UBUNTU">USN-1811-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1809-1" source="UBUNTU">USN-1809-1</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0744.html" source="REDHAT">RHSA-2013:0744</ref>
      <ref url="http://openwall.com/lists/oss-security/2013/03/14/22" source="MLIST">[oss-security] 20130314 Re: CVE-2013-0913 Linux kernel i915 integer overflow</ref>
      <ref url="http://openwall.com/lists/oss-security/2013/03/13/9" source="MLIST">[oss-security] 20130313 Re: CVE-2013-0913 Linux kernel i915 integer overflow</ref>
      <ref url="http://openwall.com/lists/oss-security/2013/03/11/6" source="MLIST">[oss-security] 20130311 CVE-2013-0913 Linux kernel i915 integer overflow</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE">openSUSE-SU-2013:0847</ref>
      <ref url="http://googlechromereleases.blogspot.com/2013/03/stable-channel-update-for-chrome-os_15.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2013/03/stable-channel-update-for-chrome-os_15.html</ref>
      <ref url="http://git.chromium.org/gitweb/?p=chromiumos/third_party/kernel.git;a=commit;h=c79efdf2b7f68f985922a8272d64269ecd490477" source="CONFIRM">http://git.chromium.org/gitweb/?p=chromiumos/third_party/kernel.git;a=commit;h=c79efdf2b7f68f985922a8272d64269ecd490477</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.45"/>
        <vers num="3.0.46"/>
        <vers num="3.0.47"/>
        <vers num="3.0.48"/>
        <vers num="3.0.49"/>
        <vers num="3.0.5"/>
        <vers num="3.0.50"/>
        <vers num="3.0.51"/>
        <vers num="3.0.52"/>
        <vers num="3.0.53"/>
        <vers num="3.0.54"/>
        <vers num="3.0.55"/>
        <vers num="3.0.56"/>
        <vers num="3.0.57"/>
        <vers num="3.0.58"/>
        <vers num="3.0.59"/>
        <vers num="3.0.6"/>
        <vers num="3.0.60"/>
        <vers num="3.0.61"/>
        <vers num="3.0.62"/>
        <vers num="3.0.63"/>
        <vers num="3.0.64"/>
        <vers num="3.0.65"/>
        <vers num="3.0.66"/>
        <vers num="3.0.67"/>
        <vers num="3.0.68"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.25"/>
        <vers num="3.4.26"/>
        <vers num="3.4.27"/>
        <vers num="3.4.28"/>
        <vers num="3.4.29"/>
        <vers num="3.4.3"/>
        <vers num="3.4.30"/>
        <vers num="3.4.31"/>
        <vers num="3.4.32"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.10"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers num="3.7.9"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers prev="1" num="3.8.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1093" published="2013-06-17" name="CVE-2013-1093" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the directToPage parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012499" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012499</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012025" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="zenworks_configuration_management">
        <vers num="11.2"/>
        <vers num="11.2.1"/>
        <vers num="11.2.2"/>
        <vers num="11.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1094" published="2013-06-17" name="CVE-2013-1094" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in a ZCC page in zenworks-core in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via an invalid locale.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012501" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012501</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012025" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="zenworks_configuration_management">
        <vers num="11.2"/>
        <vers num="11.2.1"/>
        <vers num="11.2.2"/>
        <vers num="11.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1095" published="2013-06-17" name="CVE-2013-1095" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError event.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012500" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012500</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012025" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="zenworks_configuration_management">
        <vers num="11.2"/>
        <vers num="11.2.1"/>
        <vers num="11.2.2"/>
        <vers num="11.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1097" published="2013-06-17" name="CVE-2013-1097" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onload event.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012502" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012502</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012025" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="zenworks_configuration_management">
        <vers num="11.2"/>
        <vers num="11.2.1"/>
        <vers num="11.2.2"/>
        <vers num="11.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1203" published="2013-06-18" name="CVE-2013-1203" modified="2013-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:C)" CVSS_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">Cisco ASA CX Context-Aware Security Software allows remote attackers to cause a denial of service (device reload) via crafted TCP packets that appear to have been forwarded by a Cisco Adaptive Security Appliances (ASA) device, aka Bug ID CSCue88386.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1203" source="CISCO">20130617 Cisco ASA CX TCP Traffic Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_cx_context-aware_security_software">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-1331" published="2013-06-11" name="CVE-2013-1331" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-051" source="MS" patch="1" adv="1">MS13-051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp3"/>
        <vers num="2011" edition=""/>
        <vers num="2011" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-1339" published="2013-06-11" name="CVE-2013-1339" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-050" source="MS" patch="1" adv="1">MS13-050</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x86"/>
        <vers num="-" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_8">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="-:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_rt">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2012">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2013-1355" reject="1" published="2013-06-13" name="CVE-2013-1355" modified="2013-06-13">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: The CNA or individual who requested this candidate subsequently withdrew it.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-1500" published="2013-06-18" name="CVE-2013-1500" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows local users to affect confidentiality and integrity via unknown vectors related to 2D.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This issue cannot be exploited through sandboxed Java Web Start applications and sandboxed Java applets. Local access is required to leverage this issue.'</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1571" published="2013-06-18" name="CVE-2013-1571" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, and JavaFX 2.2.21 and earlier allows remote attackers to affect integrity via unknown vectors related to Javadoc.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to the Javadoc tool and documentation generated by the tool. This vulnerability can be exploited only through Javadoc output hosted on a web server. This addresses CERT/CC VU#225657.'</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="javafx">
        <vers num="2.0"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers prev="1" num="2.2.21"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.7"/>
      </prod>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1670" published="2013-05-16" name="CVE-2013-1670" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content level constructors, which allows remote attackers to bypass certain read-only restrictions and conduct cross-site scripting (XSS) attacks via a crafted web site.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=853709" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=853709</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1823-1" source="UBUNTU">USN-1823-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1822-1" source="UBUNTU">USN-1822-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-42.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-42.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0821.html" source="REDHAT">RHSA-2013:0821</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0820.html" source="REDHAT">RHSA-2013:0820</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html" source="SUSE">openSUSE-SU-2013:0834</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html" source="SUSE">openSUSE-SU-2013:0831</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html" source="SUSE">openSUSE-SU-2013:0825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers num="19.0.2"/>
        <vers num="20.0"/>
        <vers prev="1" num="20.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers prev="1" num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-1674" published="2013-05-16" name="CVE-2013-1674" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code via vectors involving an onresize event during the playing of a video.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=860971" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=860971</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1823-1" source="UBUNTU">USN-1823-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1822-1" source="UBUNTU">USN-1822-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-46.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-46.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0821.html" source="REDHAT">RHSA-2013:0821</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0820.html" source="REDHAT">RHSA-2013:0820</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html" source="SUSE">openSUSE-SU-2013:0834</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html" source="SUSE">openSUSE-SU-2013:0831</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html" source="SUSE">openSUSE-SU-2013:0825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers num="19.0.2"/>
        <vers num="20.0"/>
        <vers prev="1" num="20.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers prev="1" num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1675" published="2013-05-16" name="CVE-2013-1675" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=866825" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=866825</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1823-1" source="UBUNTU">USN-1823-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1822-1" source="UBUNTU">USN-1822-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-47.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-47.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0821.html" source="REDHAT">RHSA-2013:0821</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0820.html" source="REDHAT">RHSA-2013:0820</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html" source="SUSE">openSUSE-SU-2013:0834</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html" source="SUSE">openSUSE-SU-2013:0831</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html" source="SUSE">openSUSE-SU-2013:0825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers num="19.0.2"/>
        <vers num="20.0"/>
        <vers prev="1" num="20.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers prev="1" num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-1676" published="2013-05-16" name="CVE-2013-1676" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The SelectionIterator::GetNextSegment function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=818454" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=818454</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1823-1" source="UBUNTU">USN-1823-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1822-1" source="UBUNTU">USN-1822-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-48.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-48.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0821.html" source="REDHAT">RHSA-2013:0821</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0820.html" source="REDHAT">RHSA-2013:0820</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html" source="SUSE">openSUSE-SU-2013:0834</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html" source="SUSE">openSUSE-SU-2013:0831</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html" source="SUSE">openSUSE-SU-2013:0825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers num="19.0.2"/>
        <vers num="20.0"/>
        <vers prev="1" num="20.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers prev="1" num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-1677" published="2013-05-16" name="CVE-2013-1677" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The gfxSkipCharsIterator::SetOffsets function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=826163" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=826163</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1823-1" source="UBUNTU">USN-1823-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1822-1" source="UBUNTU">USN-1822-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-48.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-48.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0821.html" source="REDHAT">RHSA-2013:0821</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0820.html" source="REDHAT">RHSA-2013:0820</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html" source="SUSE">openSUSE-SU-2013:0834</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html" source="SUSE">openSUSE-SU-2013:0831</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html" source="SUSE">openSUSE-SU-2013:0825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers num="19.0.2"/>
        <vers num="20.0"/>
        <vers prev="1" num="20.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers prev="1" num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-1678" published="2013-05-16" name="CVE-2013-1678" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The _cairo_xlib_surface_add_glyph function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (invalid write operation) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=839745" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=839745</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1823-1" source="UBUNTU">USN-1823-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1822-1" source="UBUNTU">USN-1822-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-48.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-48.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0821.html" source="REDHAT">RHSA-2013:0821</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0820.html" source="REDHAT">RHSA-2013:0820</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html" source="SUSE">openSUSE-SU-2013:0834</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html" source="SUSE">openSUSE-SU-2013:0831</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html" source="SUSE">openSUSE-SU-2013:0825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers num="19.0.2"/>
        <vers num="20.0"/>
        <vers prev="1" num="20.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers prev="1" num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-1679" published="2013-05-16" name="CVE-2013-1679" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the mozilla::plugins::child::_geturlnotify function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=848237" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=848237</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1823-1" source="UBUNTU">USN-1823-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1822-1" source="UBUNTU">USN-1822-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-48.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-48.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0821.html" source="REDHAT">RHSA-2013:0821</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0820.html" source="REDHAT">RHSA-2013:0820</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html" source="SUSE">openSUSE-SU-2013:0834</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html" source="SUSE">openSUSE-SU-2013:0831</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html" source="SUSE">openSUSE-SU-2013:0825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers num="19.0.2"/>
        <vers num="20.0"/>
        <vers prev="1" num="20.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers prev="1" num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-1680" published="2013-05-16" name="CVE-2013-1680" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=850931" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=850931</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1823-1" source="UBUNTU">USN-1823-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1822-1" source="UBUNTU">USN-1822-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-48.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-48.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0821.html" source="REDHAT">RHSA-2013:0821</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0820.html" source="REDHAT">RHSA-2013:0820</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html" source="SUSE">openSUSE-SU-2013:0834</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html" source="SUSE">openSUSE-SU-2013:0831</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html" source="SUSE">openSUSE-SU-2013:0825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers num="19.0.2"/>
        <vers num="20.0"/>
        <vers prev="1" num="20.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers prev="1" num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-1681" published="2013-05-16" name="CVE-2013-1681" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=851781" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=851781</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1823-1" source="UBUNTU">USN-1823-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1822-1" source="UBUNTU">USN-1822-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2013/mfsa2013-48.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2013/mfsa2013-48.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2699" source="DEBIAN">DSA-2699</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0821.html" source="REDHAT">RHSA-2013:0821</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0820.html" source="REDHAT">RHSA-2013:0820</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00012.html" source="SUSE">openSUSE-SU-2013:0834</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00011.html" source="SUSE">openSUSE-SU-2013:0831</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00010.html" source="SUSE">openSUSE-SU-2013:0825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="19.0"/>
        <vers num="19.0.1"/>
        <vers num="19.0.2"/>
        <vers num="20.0"/>
        <vers prev="1" num="20.0.1"/>
      </prod>
      <prod vendor="mozilla" name="firefox_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers prev="1" num="17.0.5"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird_esr">
        <vers num="17.0"/>
        <vers num="17.0.1"/>
        <vers num="17.0.2"/>
        <vers num="17.0.3"/>
        <vers num="17.0.4"/>
        <vers num="17.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1767" published="2013-02-28" name="CVE-2013-1767" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/5f00110f7273f9ff04ac69a5f85bb535a4fd0987" source="CONFIRM" patch="1">https://github.com/torvalds/linux/commit/5f00110f7273f9ff04ac69a5f85bb535a4fd0987</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=915592" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=915592</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=5f00110f7273f9ff04ac69a5f85bb535a4fd0987" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=5f00110f7273f9ff04ac69a5f85bb535a4fd0987</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1798-1" source="UBUNTU">USN-1798-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1797-1" source="UBUNTU">USN-1797-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1796-1" source="UBUNTU">USN-1796-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1795-1" source="UBUNTU">USN-1795-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1794-1" source="UBUNTU">USN-1794-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1793-1" source="UBUNTU">USN-1793-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1792-1" source="UBUNTU">USN-1792-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1788-1" source="UBUNTU">USN-1788-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1787-1" source="UBUNTU">USN-1787-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/25/23" source="MLIST">[oss-security] 20130225 Re: kernel: tmpfs use-after-free</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.10" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.10</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0882.html" source="REDHAT">RHSA-2013:0882</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0744.html" source="REDHAT">RHSA-2013:0744</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE">openSUSE-SU-2013:0847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers num="3.7.3"/>
        <vers num="3.7.4"/>
        <vers num="3.7.5"/>
        <vers num="3.7.6"/>
        <vers num="3.7.7"/>
        <vers num="3.7.8"/>
        <vers prev="1" num="3.7.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1774" published="2013-02-28" name="CVE-2013-1774" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:C)" CVSS_score="4.0" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="1.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per https://access.redhat.com/security/cve/CVE-2013-1774
"This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2 may address this issue."</impact>
    </impacts>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/1ee0a224bc9aad1de496c795f96bc6ba2c394811" source="CONFIRM">https://github.com/torvalds/linux/commit/1ee0a224bc9aad1de496c795f96bc6ba2c394811</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=916191" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=916191</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1808-1" source="UBUNTU">USN-1808-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1805-1" source="UBUNTU">USN-1805-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/02/27/29" source="MLIST">[oss-security] 20130227 Re: CVE request: Linux kernel: USB: io_ti: NULL pointer dereference</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.4" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.4</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0744.html" source="REDHAT">RHSA-2013:0744</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE">openSUSE-SU-2013:0847</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=1ee0a224bc9aad1de496c795f96bc6ba2c394811" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=1ee0a224bc9aad1de496c795f96bc6ba2c394811</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_mrg">
        <vers num="2.0"/>
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.2"/>
        <vers prev="1" num="3.7.3"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1796" published="2013-03-22" name="CVE-2013-1796" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:A/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.2" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The kvm_set_msr_common function in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 does not ensure a required time_page alignment during an MSR_KVM_SYSTEM_TIME operation, which allows guest OS users to cause a denial of service (buffer overflow and host OS memory corruption) or possibly have unspecified other impact via a crafted application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/c300aa64ddf57d9c5d9c898a64b36877345dd4a9" source="CONFIRM" patch="1">https://github.com/torvalds/linux/commit/c300aa64ddf57d9c5d9c898a64b36877345dd4a9</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c300aa64ddf57d9c5d9c898a64b36877345dd4a9" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c300aa64ddf57d9c5d9c898a64b36877345dd4a9</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=917012" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=917012</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1813-1" source="UBUNTU">USN-1813-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1812-1" source="UBUNTU">USN-1812-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1809-1" source="UBUNTU">USN-1809-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1808-1" source="UBUNTU">USN-1808-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1805-1" source="UBUNTU">USN-1805-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/03/20/9" source="MLIST">[oss-security] 20130320 linux kernel: kvm: CVE-2013-179[6..8]</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0746.html" source="REDHAT">RHSA-2013:0746</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0744.html" source="REDHAT">RHSA-2013:0744</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0727.html" source="REDHAT">RHSA-2013:0727</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE">openSUSE-SU-2013:0847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers prev="1" num="3.8.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1797" published="2013-03-22" name="CVE-2013-1797" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:A/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.2" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Use-after-free vulnerability in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 allows guest OS users to cause a denial of service (host OS memory corruption) or possibly have unspecified other impact via a crafted application that triggers use of a guest physical address (GPA) in (1) movable or (2) removable memory during an MSR_KVM_SYSTEM_TIME kvm_set_msr_common operation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/0b79459b482e85cb7426aa7da683a9f2c97aeae1" source="CONFIRM">https://github.com/torvalds/linux/commit/0b79459b482e85cb7426aa7da683a9f2c97aeae1</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=917013" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=917013</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1813-1" source="UBUNTU">USN-1813-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1812-1" source="UBUNTU">USN-1812-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1809-1" source="UBUNTU">USN-1809-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/03/20/9" source="MLIST">[oss-security] 20130320 linux kernel: kvm: CVE-2013-179[6..8]</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0746.html" source="REDHAT">RHSA-2013:0746</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0744.html" source="REDHAT">RHSA-2013:0744</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0727.html" source="REDHAT">RHSA-2013:0727</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE">openSUSE-SU-2013:0847</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0b79459b482e85cb7426aa7da683a9f2c97aeae1" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0b79459b482e85cb7426aa7da683a9f2c97aeae1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers prev="1" num="3.8.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1798" published="2013-03-22" name="CVE-2013-1798" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:A/AC:H/Au:N/C:C/I:N/A:C)" CVSS_score="6.2" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.2" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IOAPIC_REG_SELECT and IOAPIC_REG_WINDOW operations, which allows guest OS users to obtain sensitive information from host OS memory or cause a denial of service (host OS OOPS) via a crafted application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/a2c118bfab8bc6b8bb213abfc35201e441693d55" source="CONFIRM" patch="1">https://github.com/torvalds/linux/commit/a2c118bfab8bc6b8bb213abfc35201e441693d55</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a2c118bfab8bc6b8bb213abfc35201e441693d55" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a2c118bfab8bc6b8bb213abfc35201e441693d55</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=917017" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=917017</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1813-1" source="UBUNTU">USN-1813-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1812-1" source="UBUNTU">USN-1812-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1809-1" source="UBUNTU">USN-1809-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/03/20/9" source="MLIST">[oss-security] 20130320 linux kernel: kvm: CVE-2013-179[6..8]</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0746.html" source="REDHAT">RHSA-2013:0746</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0744.html" source="REDHAT">RHSA-2013:0744</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0727.html" source="REDHAT">RHSA-2013:0727</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE">openSUSE-SU-2013:0847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers prev="1" num="3.8.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1926" published="2013-04-29" name="CVE-2013-1926" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://www.ubuntu.com/usn/USN-1804-1/ "A security issue affects these releases of Ubuntu and its derivatives:
    Ubuntu 12.10
    Ubuntu 12.04 LTS
    Ubuntu 11.10
    Ubuntu 10.04 LTS"

Per http://lists.opensuse.org/opensuse-updates/2013-04/msg00106.html
"Affected Products:
openSUSE 12.2"</impact>
    </impacts>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0123" source="MISC">https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0123</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=916774" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=916774</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/83642" source="XF">icedtea-cve20131940-security-bypass(83642)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1804-1" source="UBUNTU">USN-1804-1</ref>
      <ref url="http://www.securityfocus.com/bid/59281" source="BID">59281</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2013:146" source="MANDRIVA">MDVSA-2013:146</ref>
      <ref url="http://secunia.com/advisories/53117" source="SECUNIA" adv="1">53117</ref>
      <ref url="http://secunia.com/advisories/53109" source="SECUNIA" adv="1">53109</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0753.html" source="REDHAT">RHSA-2013:0753</ref>
      <ref url="http://osvdb.org/92543" source="OSVDB">92543</ref>
      <ref url="http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022790.html" source="MLIST">[distro-pkg-dev] 20130417 IcedTea-Web 1.3.2 and 1.2.3 released!</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-05/msg00032.html" source="SUSE">openSUSE-SU-2013:0826</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-05/msg00003.html" source="SUSE">openSUSE-SU-2013:0735</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-04/msg00106.html" source="SUSE">openSUSE-SU-2013:0715</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.html" source="SUSE">SUSE-SU-2013:0851</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/25dd7c7ac39c" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/25dd7c7ac39c</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/34b6f60ae586" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/34b6f60ae586</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.3/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.3/NEWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="icedtea-web">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers prev="1" num="1.2.2"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
      </prod>
      <prod vendor="canonical" name="ubuntu_linux">
        <vers num="10.04" edition="-"/>
        <vers num="10.04" edition="-:lts"/>
        <vers num="11.10"/>
        <vers num="12.04" edition="-"/>
        <vers num="12.04" edition="-:lts"/>
        <vers num="12.10"/>
      </prod>
      <prod vendor="novell" name="opensuse">
        <vers num="12.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1927" published="2013-04-29" name="CVE-2013-1927" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://www.ubuntu.com/usn/USN-1804-1/ "A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.10 Ubuntu 12.04 LTS Ubuntu 11.10 Ubuntu 10.04 LTS" Per http://lists.opensuse.org/opensuse-updates/2013-04/msg00106.html "Affected Products: openSUSE 12.2"</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0123" source="MISC">https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0123</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=884705" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=884705</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/83640" source="XF">icedtea-cve20131927-sec-bypass(83640)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1804-1" source="UBUNTU">USN-1804-1</ref>
      <ref url="http://www.securityfocus.com/bid/59286" source="BID">59286</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2013:146" source="MANDRIVA">MDVSA-2013:146</ref>
      <ref url="http://secunia.com/advisories/53117" source="SECUNIA" adv="1">53117</ref>
      <ref url="http://secunia.com/advisories/53109" source="SECUNIA" adv="1">53109</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0753.html" source="REDHAT">RHSA-2013:0753</ref>
      <ref url="http://osvdb.org/92544" source="OSVDB">92544</ref>
      <ref url="http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022790.html" source="MLIST">[distro-pkg-dev] 20130417 IcedTea-Web 1.3.2 and 1.2.3 released!</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-05/msg00032.html" source="SUSE">openSUSE-SU-2013:0826</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-05/msg00003.html" source="SUSE">openSUSE-SU-2013:0735</ref>
      <ref url="http://lists.opensuse.org/opensuse-updates/2013-04/msg00106.html" source="SUSE">openSUSE-SU-2013:0715</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.html" source="SUSE">SUSE-SU-2013:0851</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/19f5282f53e8" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/19f5282f53e8</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/cb58b31c450e" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/cb58b31c450e</ref>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.3/NEWS" source="CONFIRM">http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.3/NEWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="icedtea-web">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers prev="1" num="1.2.2"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
      </prod>
      <prod vendor="canonical" name="ubuntu_linux">
        <vers num="10.04" edition="-"/>
        <vers num="10.04" edition="-:lts"/>
        <vers num="11.10"/>
        <vers num="12.04" edition="-"/>
        <vers num="12.04" edition="-:lts"/>
        <vers num="12.10"/>
      </prod>
      <prod vendor="novell" name="opensuse">
        <vers num="12.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1928" published="2013-04-29" name="CVE-2013-1928" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted VIDEO_SET_SPU_PALETTE ioctl call on a /dev/dvb device.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per https://access.redhat.com/security/cve/CVE-2013-1928 "This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6. Future kernel updates for Red Hat Enterprise Linux 6 may address this issue."</impact>
    </impacts>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/12176503366885edd542389eed3aaf94be163fdb" source="CONFIRM">https://github.com/torvalds/linux/commit/12176503366885edd542389eed3aaf94be163fdb</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=949567" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=949567</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1829-1" source="UBUNTU">USN-1829-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/04/09/6" source="MLIST">[oss-security] 20130409 Re: CVE Request: kernel information leak in fs/compat_ioctl.c VIDEO_SET_SPU_PALETTE</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/04/06/2" source="MLIST">[oss-security] 20130405 Re: CVE Request: kernel information leak in fs/compat_ioctl.c VIDEO_SET_SPU_PALETTE</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.6.5" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.6.5</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00000.html" source="SUSE">SUSE-SU-2013:0856</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE">openSUSE-SU-2013:0847</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=12176503366885edd542389eed3aaf94be163fdb" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=12176503366885edd542389eed3aaf94be163fdb</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.0" edition="rc1"/>
        <vers num="3.0" edition="rc2"/>
        <vers num="3.0" edition="rc3"/>
        <vers num="3.0" edition="rc4"/>
        <vers num="3.0" edition="rc5"/>
        <vers num="3.0" edition="rc6"/>
        <vers num="3.0" edition="rc7"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.2"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
        <vers num="3.0.26"/>
        <vers num="3.0.27"/>
        <vers num="3.0.28"/>
        <vers num="3.0.29"/>
        <vers num="3.0.3"/>
        <vers num="3.0.30"/>
        <vers num="3.0.31"/>
        <vers num="3.0.32"/>
        <vers num="3.0.33"/>
        <vers num="3.0.34"/>
        <vers num="3.0.35"/>
        <vers num="3.0.36"/>
        <vers num="3.0.37"/>
        <vers num="3.0.38"/>
        <vers num="3.0.39"/>
        <vers num="3.0.4"/>
        <vers num="3.0.40"/>
        <vers num="3.0.41"/>
        <vers num="3.0.42"/>
        <vers num="3.0.43"/>
        <vers num="3.0.44"/>
        <vers num="3.0.45"/>
        <vers num="3.0.46"/>
        <vers num="3.0.47"/>
        <vers num="3.0.48"/>
        <vers num="3.0.49"/>
        <vers num="3.0.5"/>
        <vers num="3.0.50"/>
        <vers num="3.0.51"/>
        <vers num="3.0.52"/>
        <vers num="3.0.53"/>
        <vers num="3.0.54"/>
        <vers num="3.0.55"/>
        <vers num="3.0.56"/>
        <vers num="3.0.57"/>
        <vers num="3.0.58"/>
        <vers num="3.0.59"/>
        <vers num="3.0.6"/>
        <vers num="3.0.60"/>
        <vers num="3.0.61"/>
        <vers num="3.0.62"/>
        <vers num="3.0.63"/>
        <vers num="3.0.64"/>
        <vers num="3.0.65"/>
        <vers num="3.0.66"/>
        <vers num="3.0.67"/>
        <vers num="3.0.68"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1" edition="rc1"/>
        <vers num="3.1" edition="rc2"/>
        <vers num="3.1" edition="rc3"/>
        <vers num="3.1" edition="rc4"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2" edition="rc3"/>
        <vers num="3.2" edition="rc4"/>
        <vers num="3.2" edition="rc5"/>
        <vers num="3.2" edition="rc6"/>
        <vers num="3.2" edition="rc7"/>
        <vers num="3.2.1"/>
        <vers num="3.2.10"/>
        <vers num="3.2.11"/>
        <vers num="3.2.12"/>
        <vers num="3.2.13"/>
        <vers num="3.2.14"/>
        <vers num="3.2.15"/>
        <vers num="3.2.16"/>
        <vers num="3.2.17"/>
        <vers num="3.2.18"/>
        <vers num="3.2.19"/>
        <vers num="3.2.2"/>
        <vers num="3.2.20"/>
        <vers num="3.2.21"/>
        <vers num="3.2.22"/>
        <vers num="3.2.23"/>
        <vers num="3.2.24"/>
        <vers num="3.2.25"/>
        <vers num="3.2.26"/>
        <vers num="3.2.27"/>
        <vers num="3.2.28"/>
        <vers num="3.2.29"/>
        <vers num="3.2.3"/>
        <vers num="3.2.30"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.3" edition="rc1"/>
        <vers num="3.3" edition="rc2"/>
        <vers num="3.3" edition="rc3"/>
        <vers num="3.3" edition="rc4"/>
        <vers num="3.3" edition="rc5"/>
        <vers num="3.3" edition="rc6"/>
        <vers num="3.3" edition="rc7"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="3.3.7"/>
        <vers num="3.3.8"/>
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4" edition="rc2"/>
        <vers num="3.4" edition="rc3"/>
        <vers num="3.4" edition="rc4"/>
        <vers num="3.4" edition="rc5"/>
        <vers num="3.4" edition="rc6"/>
        <vers num="3.4" edition="rc7"/>
        <vers num="3.4.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.12"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.15"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.20"/>
        <vers num="3.4.21"/>
        <vers num="3.4.22"/>
        <vers num="3.4.23"/>
        <vers num="3.4.24"/>
        <vers num="3.4.25"/>
        <vers num="3.4.26"/>
        <vers num="3.4.27"/>
        <vers num="3.4.28"/>
        <vers num="3.4.29"/>
        <vers num="3.4.3"/>
        <vers num="3.4.30"/>
        <vers num="3.4.31"/>
        <vers num="3.4.32"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers prev="1" num="3.6.4"/>
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1981" published="2013-06-15" name="CVE-2013-1981" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XQueryFont, (2) _XF86BigfontQueryFont, (3) XListFontsWithInfo, (4) XGetMotionEvents, (5) XListHosts, (6) XGetModifierMapping, (7) XGetPointerMapping, (8) XGetKeyboardMapping, (9) XGetWindowProperty, (10) XGetImage, (11) LoadColornameDB, (12) XrmGetFileDatabase, (13) _XimParseStringFile, or (14) TransFileName functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libx11">
        <vers num="1.5.0"/>
        <vers prev="1" num="1.5.99.901"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1982" published="2013-06-15" name="CVE-2013-1982" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXext 1.3.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XcupGetReservedColormapEntries, (2) XcupStoreColors, (3) XdbeGetVisualInfo, (4) XeviGetVisualInfo, (5) XShapeGetRectangles, and (6) XSyncListSystemCounters functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" patch="1" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxext">
        <vers num="1.0.99.2"/>
        <vers num="1.0.99.3"/>
        <vers num="1.0.99.4"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.3.0"/>
        <vers prev="1" num="1.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1983" published="2013-06-15" name="CVE-2013-1983" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in X.org libXfixes 5.0 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XFixesGetCursorImage function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxfixes">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers prev="1" num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1984" published="2013-06-15" name="CVE-2013-1984" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXi 1.7.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XGetDeviceControl, (2) XGetFeedbackControl, (3) XGetDeviceDontPropagateList, (4) XGetDeviceMotionEvents, (5) XIGetProperty, (6) XIGetSelectedEvents, (7) XGetDeviceProperties, and (8) XListInputDevices functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxi">
        <vers num="1.5.0"/>
        <vers num="1.5.99.2"/>
        <vers num="1.5.99.3"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.99.1"/>
        <vers num="1.7"/>
        <vers prev="1" num="1.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1985" published="2013-06-15" name="CVE-2013-1985" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in X.org libXinerama 1.1.2 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XineramaQueryScreens function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxinerama">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.99.1"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers prev="1" num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1986" published="2013-06-15" name="CVE-2013-1986" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXrandr 1.4.0 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRRQueryOutputProperty and (2) XRRQueryProviderProperty functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxrandr">
        <vers num="1.2.3"/>
        <vers num="1.2.99.1"/>
        <vers num="1.2.99.2"/>
        <vers num="1.2.99.3"/>
        <vers num="1.2.99.4"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers prev="1" num="1.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1987" published="2013-06-15" name="CVE-2013-1987" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRender QueryFilters, (2) XRenderQueryFormats, and (3) XRenderQueryPictIndexValues functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxrender">
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers prev="1" num="0.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1988" published="2013-06-15" name="CVE-2013-1988" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXRes 1.0.6 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XResQueryClients and (2) XResQueryClientResources functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxres">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers prev="1" num="1.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1989" published="2013-06-15" name="CVE-2013-1989" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXv 1.0.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XvQueryPortAttributes, (2) XvListImageFormats, and (3) XvCreateImage function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxv">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers prev="1" num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1990" published="2013-06-15" name="CVE-2013-1990" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXvMC 1.0.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XvMCListSurfaceTypes and (2) XvMCListSubpictureTypes functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxvmc">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers prev="1" num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1991" published="2013-06-15" name="CVE-2013-1991" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXxf86dga 1.1.3 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XDGAQueryModes and (2) XDGASetMode functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxxf86dga">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.99.1"/>
        <vers num="1.0.99.2"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers prev="1" num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1992" published="2013-06-15" name="CVE-2013-1992" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libdmx 1.1.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) DMXGetScreenAttributes, (2) DMXGetWindowAttributes, and (3) DMXGetInputAttributes functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libdmx">
        <vers num="1.0.2"/>
        <vers num="1.0.99.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers prev="1" num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1993" published="2013-06-15" name="CVE-2013-1993" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mesa3d.org" name="mesa">
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.1"/>
        <vers prev="1" num="9.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1994" published="2013-06-15" name="CVE-2013-1994" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libchromeXvMC and libchromeXvMCPro in openChrome 0.3.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) uniDRIOpenConnection and (2) uniDRIGetClientDriverName functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openchrome" name="openchrome">
        <vers prev="1" num="0.3.2"/>
      </prod>
      <prod vendor="x" name="libchromexvmc">
        <vers num="-"/>
      </prod>
      <prod vendor="x" name="libchromexvmcpro">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1995" published="2013-06-15" name="CVE-2013-1995" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">X.org libXi 1.7.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the XListInputDevices function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxi">
        <vers num="1.5.0"/>
        <vers num="1.5.99.2"/>
        <vers num="1.5.99.3"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.99.1"/>
        <vers num="1.7"/>
        <vers prev="1" num="1.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1996" published="2013-06-15" name="CVE-2013-1996" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">X.org libFS 1.0.4 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the FSOpenServer function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libfs">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers prev="1" num="1.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1997" published="2013-06-15" name="CVE-2013-1997" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XAllocColorCells, (2) _XkbReadGetDeviceInfoReply, (3) _XkbReadGeomShapes, (4) _XkbReadGetGeometryReply, (5) _XkbReadKeySyms, (6) _XkbReadKeyActions, (7) _XkbReadKeyBehaviors, (8) _XkbReadModifierMap, (9) _XkbReadExplicitComponents, (10) _XkbReadVirtualModMap, (11) _XkbReadGetNamesReply, (12) _XkbReadGetMapReply, (13) _XimXGetReadData, (14) XListFonts, (15) XListExtensions, and (16) XGetFontPath functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libx11">
        <vers num="1.5.0"/>
        <vers prev="1" num="1.5.99.901"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1998" published="2013-06-15" name="CVE-2013-1998" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (2) XIPassiveGrabDevice, and (3) XQueryDeviceState functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxi">
        <vers num="1.5.0"/>
        <vers num="1.5.99.2"/>
        <vers num="1.5.99.3"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.99.1"/>
        <vers num="1.7"/>
        <vers prev="1" num="1.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1999" published="2013-06-15" name="CVE-2013-1999" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in X.org libXvMC 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvMCGetDRInfo function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxvmc">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers prev="1" num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2000" published="2013-06-15" name="CVE-2013-2000" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in X.org libXxf86dga 1.1.3 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XDGAQueryModes and (2) XDGASetMode functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxxf86dga">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.99.1"/>
        <vers num="1.0.99.2"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers prev="1" num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2001" published="2013-06-15" name="CVE-2013-2001" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in X.org libXxf86vm 1.1.2 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XF86VidModeGetGammaRamp function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxxf86vm">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.99.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers prev="1" num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2002" published="2013-06-15" name="CVE-2013-2002" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in X.org libXt 1.1.3 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the _XtResourceConfigurationEH function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxt">
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers prev="1" num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2003" published="2013-06-15" name="CVE-2013-2003" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in X.org libXcursor 1.1.13 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the _XcursorFileHeaderCreate function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxcursor">
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers prev="1" num="1.1.13"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2004" published="2013-06-15" name="CVE-2013-2004" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The (1) GetDatabase and (2) _XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier do not restrict the recursion depth when processing directives to include files, which allows X servers to cause a denial of service (stack consumption) via a crafted file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libx11">
        <vers num="1.5.0"/>
        <vers prev="1" num="1.5.99.901"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2005" published="2013-06-15" name="CVE-2013-2005" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxt">
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers prev="1" num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2007" published="2013-05-21" name="CVE-2013-2007" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows local users to read and write to these files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=956082" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=956082</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/84047" source="XF">qemu-cve20132007-priv-esc(84047)</ref>
      <ref url="http://www.securitytracker.com/id/1028521" source="SECTRACK">1028521</ref>
      <ref url="http://www.securityfocus.com/bid/59675" source="BID">59675</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/06/5" source="MLIST">[oss-security] 20130506 Xen Security Advisory 51 (CVE-2013-2007) - qemu guest agent (qga) insecure file permissions</ref>
      <ref url="http://secunia.com/advisories/53325" source="SECUNIA" adv="1">53325</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0896.html" source="REDHAT">RHSA-2013:0896</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0791.html" source="REDHAT">RHSA-2013:0791</ref>
      <ref url="http://osvdb.org/93032" source="OSVDB">93032</ref>
      <ref url="http://git.qemu.org/?p=qemu.git;a=commit;h=c689b4f1bac352dcfd6ecb9a1d45337de0f1de67" source="CONFIRM">http://git.qemu.org/?p=qemu.git;a=commit;h=c689b4f1bac352dcfd6ecb9a1d45337de0f1de67</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qemu" name="qemu">
        <vers num="1.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2062" published="2013-06-15" name="CVE-2013-2062" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXp 1.0.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XpGetAttributes, (2) XpGetOneAttribute, (3) XpGetPrinterList, and (4) XpQueryScreens functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxp">
        <vers num="1.0.0"/>
        <vers prev="1" num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2063" published="2013-06-15" name="CVE-2013-2063" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in X.org libXtst 1.2.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XRecordGetContext function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxtst">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.99.1"/>
        <vers num="1.0.99.2"/>
        <vers num="1.1.0"/>
        <vers num="1.2.0"/>
        <vers prev="1" num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2064" published="2013-06-15" name="CVE-2013-2064" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxcb">
        <vers num="1.1.90.1"/>
        <vers num="1.1.91"/>
        <vers num="1.1.92"/>
        <vers num="1.1.93"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.8.1"/>
        <vers prev="1" num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2066" published="2013-06-15" name="CVE-2013-2066" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in X.org libXv 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvQueryPortAttributes function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxv">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers prev="1" num="1.0.7"/>
      </prod>
      <prod vendor="x.org" name="libxv">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2067" published="2013-06-01" name="CVE-2013-2067" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1417891" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1417891</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1408044" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1408044</ref>
      <ref url="http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1408044&amp;r2=1408043&amp;pathrev=1408044" source="CONFIRM" patch="1">http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1408044&amp;r2=1408043&amp;pathrev=1408044</ref>
      <ref url="http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1417891&amp;r2=1417890&amp;pathrev=1417891" source="CONFIRM" patch="1">http://svn.apache.org/viewvc/tomcat/tc6.0.x/trunk/java/org/apache/catalina/authenticator/FormAuthenticator.java?r1=1417891&amp;r2=1417890&amp;pathrev=1417891</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1841-1" source="UBUNTU">USN-1841-1</ref>
      <ref url="http://tomcat.apache.org/security-7.html" source="CONFIRM" adv="1">http://tomcat.apache.org/security-7.html</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM" adv="1">http://tomcat.apache.org/security-6.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="6.0.21"/>
        <vers num="6.0.24"/>
        <vers num="6.0.26"/>
        <vers num="6.0.27"/>
        <vers num="6.0.28"/>
        <vers num="6.0.29"/>
        <vers num="6.0.30"/>
        <vers num="6.0.31"/>
        <vers num="6.0.32"/>
        <vers num="6.0.33"/>
        <vers num="6.0.35"/>
        <vers num="6.0.36"/>
        <vers num="7.0.0" edition="beta"/>
        <vers num="7.0.1"/>
        <vers num="7.0.10"/>
        <vers num="7.0.11"/>
        <vers num="7.0.12"/>
        <vers num="7.0.13"/>
        <vers num="7.0.14"/>
        <vers num="7.0.15"/>
        <vers num="7.0.16"/>
        <vers num="7.0.17"/>
        <vers num="7.0.18"/>
        <vers num="7.0.19"/>
        <vers num="7.0.2" edition="beta"/>
        <vers num="7.0.20"/>
        <vers num="7.0.21"/>
        <vers num="7.0.22"/>
        <vers num="7.0.23"/>
        <vers num="7.0.25"/>
        <vers num="7.0.28"/>
        <vers num="7.0.3"/>
        <vers num="7.0.30"/>
        <vers num="7.0.32"/>
        <vers num="7.0.4" edition="beta"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8"/>
        <vers num="7.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-2071" published="2013-06-01" name="CVE-2013-2071" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1471372" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1471372</ref>
      <ref url="http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/core/AsyncContextImpl.java?r1=1471372&amp;r2=1471371&amp;pathrev=1471372" source="CONFIRM" patch="1">http://svn.apache.org/viewvc/tomcat/tc7.0.x/trunk/java/org/apache/catalina/core/AsyncContextImpl.java?r1=1471372&amp;r2=1471371&amp;pathrev=1471372</ref>
      <ref url="https://issues.apache.org/bugzilla/show_bug.cgi?id=54178" source="CONFIRM">https://issues.apache.org/bugzilla/show_bug.cgi?id=54178</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1841-1" source="UBUNTU">USN-1841-1</ref>
      <ref url="http://tomcat.apache.org/security-7.html" source="CONFIRM" adv="1">http://tomcat.apache.org/security-7.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="7.0.0" edition="beta"/>
        <vers num="7.0.1"/>
        <vers num="7.0.10"/>
        <vers num="7.0.11"/>
        <vers num="7.0.12"/>
        <vers num="7.0.13"/>
        <vers num="7.0.14"/>
        <vers num="7.0.15"/>
        <vers num="7.0.16"/>
        <vers num="7.0.17"/>
        <vers num="7.0.18"/>
        <vers num="7.0.19"/>
        <vers num="7.0.2" edition="beta"/>
        <vers num="7.0.20"/>
        <vers num="7.0.21"/>
        <vers num="7.0.22"/>
        <vers num="7.0.23"/>
        <vers num="7.0.25"/>
        <vers num="7.0.28"/>
        <vers num="7.0.3"/>
        <vers num="7.0.30"/>
        <vers num="7.0.32"/>
        <vers num="7.0.4" edition="beta"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8"/>
        <vers num="7.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2094" published="2013-05-14" name="CVE-2013-2094" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://twitter.com/djrbliss/statuses/334301992648331267" source="MISC" patch="1">http://twitter.com/djrbliss/statuses/334301992648331267</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8176cced706b5e5d15887584150764894e94e02f" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8176cced706b5e5d15887584150764894e94e02f</ref>
      <ref url="https://github.com/torvalds/linux/commit/8176cced706b5e5d15887584150764894e94e02f" source="CONFIRM">https://github.com/torvalds/linux/commit/8176cced706b5e5d15887584150764894e94e02f</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=962792" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=962792</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1828-1" source="UBUNTU">USN-1828-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1827-1" source="UBUNTU">USN-1827-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1826-1" source="UBUNTU">USN-1826-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1825-1" source="UBUNTU">USN-1825-1</ref>
      <ref url="http://www.reddit.com/r/netsec/comments/1eb9iw" source="MISC">http://www.reddit.com/r/netsec/comments/1eb9iw</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/14/6" source="MLIST">[oss-security] 20130514 Re: CVE Request: linux kernel perf out-of-bounds access</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.9" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.9</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0830.html" source="REDHAT">RHSA-2013:0830</ref>
      <ref url="http://packetstormsecurity.com/files/121616/semtex.c" source="MISC">http://packetstormsecurity.com/files/121616/semtex.c</ref>
      <ref url="http://news.ycombinator.com/item?id=5703758" source="MISC">http://news.ycombinator.com/item?id=5703758</ref>
      <ref url="http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/04302.html" source="MLIST">[linux-kernel] 20130413 Re: sw_perf_event_destroy() oops while fuzzing</ref>
      <ref url="http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/03976.html" source="MLIST">[linux-kernel] 20130412 Re: sw_perf_event_destroy() oops while fuzzing</ref>
      <ref url="http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/03652.html" source="MLIST">[linux-kernel] 20130412 sw_perf_event_destroy() oops while fuzzing</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.html" source="SUSE">openSUSE-SU-2013:0847</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00008.html" source="SUSE">SUSE-SU-2013:0819</ref>
      <ref url="http://lists.centos.org/pipermail/centos-announce/2013-May/019733.html" source="MLIST">[CentOS-announce] 20130517 CESA-2013:0830 Important CentOS 6 kernel Update</ref>
      <ref url="http://lists.centos.org/pipermail/centos-announce/2013-May/019729.html" source="MLIST">[CentOS-announce] 20130515 CentOS-6 CVE-2013-2094 Kernel Issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6"/>
        <vers num="3.8.7"/>
        <vers prev="1" num="3.8.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2309" published="2013-06-16" name="CVE-2013-2309" modified="2013-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the management screen in OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before 3.8.5.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the "mobile version color scheme."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.openpne.jp/archives/11096/" source="CONFIRM" patch="1" adv="1">http://www.openpne.jp/archives/11096/</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000038" source="JVNDB">JVNDB-2013-000038</ref>
      <ref url="http://jvn.jp/en/jp/JVN18501376/index.html" source="JVN">JVN#18501376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tejimaya" name="openpne">
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4.0"/>
        <vers num="3.4.0.1"/>
        <vers num="3.4.1"/>
        <vers num="3.4.1.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.11.1"/>
        <vers num="3.4.12"/>
        <vers num="3.4.12.1"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.14.1"/>
        <vers num="3.4.15"/>
        <vers num="3.4.15.1"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.21"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.4.1"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.6.1"/>
        <vers num="3.4.6.2"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.4.9.1"/>
        <vers num="3.4.9.2"/>
        <vers num="3.4b"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-2310" published="2013-06-16" name="CVE-2013-2310" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">SoftBank Wi-Fi Spot Configuration Software, as used on SoftBank SHARP 3G handsets, SoftBank Panasonic 3G handsets, SoftBank NEC 3G handsets, SoftBank Samsung 3G handsets, SoftBank mobile Wi-Fi routers, SoftBank Android smartphones with the Wi-Fi application before 1.7.1, SoftBank Windows Mobile smartphones with the WISPrClient application before 1.3.1, SoftBank Disney Mobile Android smartphones with the Wi-Fi application before 1.7.1, and WILLCOM Android smartphones with the Wi-Fi application before 1.7.1, does not properly connect to access points, which allows remote attackers to obtain sensitive information by leveraging access to an 802.11 network.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000039" source="JVNDB">JVNDB-2013-000039</ref>
      <ref url="http://jvn.jp/en/jp/JVN85371480/index.html" source="JVN">JVN#85371480</ref>
      <ref url="http://jvn.jp/en/jp/JVN85371480/995417/index.html" source="CONFIRM">http://jvn.jp/en/jp/JVN85371480/995417/index.html</ref>
      <ref url="http://jvn.jp/en/jp/JVN85371480/995319/index.html" source="CONFIRM">http://jvn.jp/en/jp/JVN85371480/995319/index.html</ref>
      <ref url="http://jvn.jp/en/jp/JVN85371480/397327/index.html" source="CONFIRM">http://jvn.jp/en/jp/JVN85371480/397327/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softbank" name="wi-fi_application">
        <vers prev="1" num="1.7.0"/>
      </prod>
      <prod vendor="softbank" name="wi-fi_spot_configuration_software">
        <vers num="-"/>
      </prod>
      <prod vendor="softbank" name="wisprclient">
        <vers prev="1" num="1.3.0"/>
      </prod>
      <prod vendor="willcom-inc" name="wi-fi_application">
        <vers prev="1" num="1.7.0"/>
      </prod>
      <prod vendor="softbank" name="android_smartphone">
        <vers num="001dl"/>
        <vers num="001ht"/>
        <vers num="003p"/>
        <vers num="003sh"/>
        <vers num="003z"/>
        <vers num="005sh"/>
        <vers num="006sh"/>
        <vers num="007hw"/>
        <vers num="007sh" edition="j"/>
        <vers num="007sh" edition="kt"/>
        <vers num="008z"/>
        <vers num="009sh" edition="y"/>
        <vers num="009z"/>
        <vers num="101dl"/>
        <vers num="101f"/>
        <vers num="101k"/>
        <vers num="101n"/>
        <vers num="101p"/>
        <vers num="101sh"/>
        <vers num="102p"/>
        <vers num="102sh" edition="ii"/>
        <vers num="103sh"/>
        <vers num="104sh"/>
        <vers num="106sh"/>
        <vers num="107sh"/>
        <vers num="200sh"/>
        <vers num="201hw"/>
        <vers num="201k"/>
        <vers num="201m"/>
        <vers num="x06ht" edition="ii"/>
      </prod>
      <prod vendor="softbank" name="disney_mobile_android_smartphone">
        <vers num="dm009sh"/>
        <vers num="dm010sh"/>
        <vers num="dm011sh"/>
        <vers num="dm012sh"/>
        <vers num="dm013sh"/>
      </prod>
      <prod vendor="softbank" name="mobile_wi-fi_router">
        <vers num="101sb"/>
        <vers num="102hw"/>
        <vers num="102z"/>
      </prod>
      <prod vendor="softbank" name="nec_3g_handset">
        <vers num="001n"/>
        <vers num="931n"/>
        <vers num="940n"/>
      </prod>
      <prod vendor="softbank" name="panasonic_3g_handset">
        <vers num="001p"/>
        <vers num="941p"/>
        <vers num="942p"/>
      </prod>
      <prod vendor="softbank" name="samsung_3g_handset">
        <vers num="941sc"/>
      </prod>
      <prod vendor="softbank" name="sharp_3g_handset">
        <vers num="001n"/>
        <vers num="001p"/>
        <vers num="002sh"/>
        <vers num="004sh"/>
        <vers num="004shp3"/>
        <vers num="931n"/>
        <vers num="940n"/>
        <vers num="940sh"/>
        <vers num="941p"/>
        <vers num="941sc"/>
        <vers num="941sh"/>
        <vers num="942p"/>
        <vers num="943sh"/>
        <vers num="944sh"/>
        <vers num="945sh"/>
        <vers num="945shg"/>
      </prod>
      <prod vendor="softbank" name="windows_mobile_smartphone">
        <vers num="x01sc"/>
        <vers num="x02t"/>
        <vers num="x04ht"/>
        <vers num="x05ht"/>
      </prod>
      <prod vendor="willcom-inc" name="android_smartphone">
        <vers num="wx04k"/>
        <vers num="wx06k"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2336" published="2013-06-14" name="CVE-2013-2336" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HP Service Manager 7.11, 9.21, 9.30, and 9.31, and ServiceCenter 6.2.8, allows remote attackers to obtain sensitive information via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03784101" source="HP" adv="1">HPSBMU02884</ref>
      <ref url="http://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03784101" source="HP" adv="1">SSRT101207</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="service_center">
        <vers num="6.2.8"/>
      </prod>
      <prod vendor="hp" name="service_manager">
        <vers num="7.11"/>
        <vers num="9.21"/>
      </prod>
      <prod vendor="hp" name="service_manager">
        <vers num="9.30"/>
        <vers num="9.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2337" published="2013-06-14" name="CVE-2013-2337" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HP Service Manager 7.11, 9.21, 9.30, and 9.31, and ServiceCenter 6.2.8, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03784101" source="HP" adv="1">HPSBMU02884</ref>
      <ref url="http://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03784101" source="HP" adv="1">SSRT101208</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="service_center">
        <vers num="6.2.8"/>
      </prod>
      <prod vendor="hp" name="service_manager">
        <vers num="7.11"/>
        <vers num="9.21"/>
      </prod>
      <prod vendor="hp" name="service_manager">
        <vers num="9.30"/>
        <vers num="9.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2338" published="2013-06-14" name="CVE-2013-2338" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability on HP Integrated Lights-Out 3 (aka iLO3) cards with firmware before 1.57 and 4 (aka iLO4) cards with firmware before 1.22, when Single-Sign-On (SSO) is used, allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03787836" source="HP" adv="1">HPSBHF02885</ref>
      <ref url="https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03787836" source="HP" adv="1">SSRT101180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="integrated_lights-out_3_firmware">
        <vers num="1.00"/>
        <vers num="1.05"/>
        <vers num="1.20"/>
        <vers num="1.26"/>
        <vers num="1.28"/>
        <vers num="1.50"/>
        <vers prev="1" num="1.55"/>
      </prod>
      <prod vendor="hp" name="integrated_lights-out_4_firmware">
        <vers num="1.11"/>
        <vers num="1.13"/>
        <vers prev="1" num="1.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2400" published="2013-06-18" name="CVE-2013-2400" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-3744.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2407" published="2013-06-18" name="CVE-2013-2407" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality and availability via unknown vectors related to Libraries.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2412" published="2013-06-18" name="CVE-2013-2412" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Serviceability.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2437" published="2013-06-18" name="CVE-2013-2437" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Deployment.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2442" published="2013-06-18" name="CVE-2013-2442" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2466 and CVE-2013-2468.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2443" published="2013-06-18" name="CVE-2013-2443" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2452 and CVE-2013-2455.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2444" published="2013-06-18" name="CVE-2013-2444" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, and JavaFX 2.2.21 and earlier allows remote attackers to affect availability via vectors related to AWT.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="javafx">
        <vers num="2.0"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers prev="1" num="2.2.21"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.7"/>
      </prod>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2445" published="2013-06-18" name="CVE-2013-2445" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect availability via unknown vectors related to Hotspot.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2446" published="2013-06-18" name="CVE-2013-2446" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via vectors related to CORBA.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2447" published="2013-06-18" name="CVE-2013-2447" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Networking.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2448" published="2013-06-18" name="CVE-2013-2448" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2449" published="2013-06-18" name="CVE-2013-2449" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2450" published="2013-06-18" name="CVE-2013-2450" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect availability via unknown vectors related to Serialization.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-2451" published="2013-06-18" name="CVE-2013-2451" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html


'Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2452" published="2013-06-18" name="CVE-2013-2452" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2443 and CVE-2013-2455.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2453" published="2013-06-18" name="CVE-2013-2453" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect integrity via vectors related to JMX.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2454" published="2013-06-18" name="CVE-2013-2454" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality and integrity via vectors related to JDBC.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2455" published="2013-06-18" name="CVE-2013-2455" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2443 and CVE-2013-2452.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2456" published="2013-06-18" name="CVE-2013-2456" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Serialization.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2457" published="2013-06-18" name="CVE-2013-2457" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect integrity via vectors related to JMX.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.'</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2458" published="2013-06-18" name="CVE-2013-2458" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2459" published="2013-06-18" name="CVE-2013-2459" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2460" published="2013-06-18" name="CVE-2013-2460" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2461" published="2013-06-18" name="CVE-2013-2461" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2462" published="2013-06-18" name="CVE-2013-2462" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2463" published="2013-06-18" name="CVE-2013-2463" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2464" published="2013-06-18" name="CVE-2013-2464" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2465" published="2013-06-18" name="CVE-2013-2465" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2466" published="2013-06-18" name="CVE-2013-2466" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2442 and CVE-2013-2468.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2467" published="2013-06-18" name="CVE-2013-2467" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 5.0 Update 45 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Java installer.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to the Java installer only. This issue cannot be exploited through sandboxed Java Web Start applications and sandboxed Java applets. Local access is required to leverage this issue.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2468" published="2013-06-18" name="CVE-2013-2468" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2442 and CVE-2013-2466.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2469" published="2013-06-18" name="CVE-2013-2469" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2470" published="2013-06-18" name="CVE-2013-2470" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2471, CVE-2013-2472, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2471" published="2013-06-18" name="CVE-2013-2471" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2472, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2472" published="2013-06-18" name="CVE-2013-2472" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2473" published="2013-06-18" name="CVE-2013-2473" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2472.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2783" published="2013-06-14" name="CVE-2013-2783" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The DNP3 driver in IOServer drivers 1.0.19.0 allows remote attackers to cause a denial of service (infinite loop) or obtain unspecified control via crafted data to TCP port 20000.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://ics-cert.us-cert.gov/advisories/ICSA-13-161-01" source="MISC" patch="1">http://ics-cert.us-cert.gov/advisories/ICSA-13-161-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ioserver" name="ioserver">
        <vers num="1.0.19.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2864" published="2013-06-04" name="CVE-2013-2864" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The PDF functionality in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://code.google.com/p/chromium/issues/detail?id=239134" source="CONFIRM" adv="1">https://code.google.com/p/chromium/issues/detail?id=239134</ref>
      <ref url="http://googlechromereleases.blogspot.com/2013/06/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2013/06/stable-channel-update.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="27.0.1453.0"/>
        <vers num="27.0.1453.1"/>
        <vers num="27.0.1453.10"/>
        <vers num="27.0.1453.102"/>
        <vers num="27.0.1453.103"/>
        <vers num="27.0.1453.104"/>
        <vers num="27.0.1453.105"/>
        <vers num="27.0.1453.106"/>
        <vers num="27.0.1453.107"/>
        <vers num="27.0.1453.108"/>
        <vers prev="1" num="27.0.1453.109"/>
        <vers num="27.0.1453.11"/>
        <vers num="27.0.1453.12"/>
        <vers num="27.0.1453.13"/>
        <vers num="27.0.1453.15"/>
        <vers num="27.0.1453.2"/>
        <vers num="27.0.1453.3"/>
        <vers num="27.0.1453.34"/>
        <vers num="27.0.1453.35"/>
        <vers num="27.0.1453.36"/>
        <vers num="27.0.1453.37"/>
        <vers num="27.0.1453.38"/>
        <vers num="27.0.1453.39"/>
        <vers num="27.0.1453.4"/>
        <vers num="27.0.1453.40"/>
        <vers num="27.0.1453.41"/>
        <vers num="27.0.1453.42"/>
        <vers num="27.0.1453.43"/>
        <vers num="27.0.1453.44"/>
        <vers num="27.0.1453.45"/>
        <vers num="27.0.1453.46"/>
        <vers num="27.0.1453.47"/>
        <vers num="27.0.1453.49"/>
        <vers num="27.0.1453.5"/>
        <vers num="27.0.1453.50"/>
        <vers num="27.0.1453.51"/>
        <vers num="27.0.1453.52"/>
        <vers num="27.0.1453.54"/>
        <vers num="27.0.1453.55"/>
        <vers num="27.0.1453.56"/>
        <vers num="27.0.1453.57"/>
        <vers num="27.0.1453.58"/>
        <vers num="27.0.1453.59"/>
        <vers num="27.0.1453.6"/>
        <vers num="27.0.1453.60"/>
        <vers num="27.0.1453.61"/>
        <vers num="27.0.1453.62"/>
        <vers num="27.0.1453.63"/>
        <vers num="27.0.1453.64"/>
        <vers num="27.0.1453.65"/>
        <vers num="27.0.1453.66"/>
        <vers num="27.0.1453.67"/>
        <vers num="27.0.1453.68"/>
        <vers num="27.0.1453.69"/>
        <vers num="27.0.1453.7"/>
        <vers num="27.0.1453.70"/>
        <vers num="27.0.1453.71"/>
        <vers num="27.0.1453.72"/>
        <vers num="27.0.1453.73"/>
        <vers num="27.0.1453.74"/>
        <vers num="27.0.1453.75"/>
        <vers num="27.0.1453.76"/>
        <vers num="27.0.1453.77"/>
        <vers num="27.0.1453.78"/>
        <vers num="27.0.1453.79"/>
        <vers num="27.0.1453.8"/>
        <vers num="27.0.1453.80"/>
        <vers num="27.0.1453.81"/>
        <vers num="27.0.1453.82"/>
        <vers num="27.0.1453.83"/>
        <vers num="27.0.1453.84"/>
        <vers num="27.0.1453.85"/>
        <vers num="27.0.1453.86"/>
        <vers num="27.0.1453.87"/>
        <vers num="27.0.1453.88"/>
        <vers num="27.0.1453.89"/>
        <vers num="27.0.1453.9"/>
        <vers num="27.0.1453.90"/>
        <vers num="27.0.1453.91"/>
        <vers num="27.0.1453.93"/>
        <vers num="27.0.1453.94"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2013-2866" published="2013-06-19" name="CVE-2013-2866" modified="2013-06-19">
    <desc>
      <descript source="cve">The Flash plug-in in Google Chrome before 27.0.1453.116 does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's physical environment via a clickjacking attack, as demonstrated by an attack using a crafted Cascading Style Sheets (CSS) opacity property.</descript>
    </desc>
    <refs>
      <ref url="https://src.chromium.org/viewvc/chrome?revision=206188&amp;view=revision" source="CONFIRM">https://src.chromium.org/viewvc/chrome?revision=206188&amp;view=revision</ref>
      <ref url="https://code.google.com/p/chromium/issues/detail?id=249335" source="CONFIRM">https://code.google.com/p/chromium/issues/detail?id=249335</ref>
      <ref url="http://habrahabr.ru/post/182706/" source="MISC">http://habrahabr.ru/post/182706/</ref>
      <ref url="http://googlechromereleases.blogspot.com/2013/06/stable-channel-update_18.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2013/06/stable-channel-update_18.html</ref>
    </refs>
  </entry>
  <entry type="CVE" seq="2013-2968" published="2013-06-19" name="CVE-2013-2968" modified="2013-06-19">
    <desc>
      <descript source="cve">An unspecified buffer-read method in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to cause a denial of service via a large file that lacks end-of-line characters.</descript>
    </desc>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83859" source="XF">sterling-cve20132968-dos(83859)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21640348" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21640348</ref>
    </refs>
  </entry>
  <entry type="CVE" seq="2013-2969" published="2013-06-19" name="CVE-2013-2969" modified="2013-06-19">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters.</descript>
    </desc>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83860" source="XF">sterling-cve20132969-xss(83860)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21640348" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21640348</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2970" published="2013-06-03" name="CVE-2013-2970" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM QRadar Security Information and Event Manager (SIEM) 7.x before 7.1 MR2 Patch 1 allows remote authenticated users to execute operating-system commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/722868" source="CERT-VN">VU#722868</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/83872" source="XF">qradar-siem-command-exec(83872)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21639309" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21639309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="qradar_security_information_and_event_manager">
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2980" published="2013-06-17" name="CVE-2013-2980" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to hijack the authentication of arbitrary users for requests that access monitored database information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/84113" source="XF">datastudio-cve20132980-csrf(84113)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21638733" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21638733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="data_studio">
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2981" published="2013-06-17" name="CVE-2013-2981" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to read arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83973" source="XF">datastudio-cve20132981-dir-traversal(83973)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21638734" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21638734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="data_studio">
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3026" published="2013-06-16" name="CVE-2013-3026" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Lotus Quickr for Domino ActiveX control in qp2.cab in IBM Lotus Quickr 8.1 before FP 8.1.0.32-001a, 8.2 before FP 8.2.0.28-001a, and 8.5.1 before FP 8.5.1.39-002a for Domino allows remote attackers to execute arbitrary code via a crafted web site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/84381" source="XF">quickr-qp2-activex-bo(84381)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21639643" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21639643</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_quickr_for_domino">
        <vers num="8.1.0"/>
        <vers num="8.2.0"/>
        <vers num="8.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3110" published="2013-06-11" name="CVE-2013-3110" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3141.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3111" published="2013-06-11" name="CVE-2013-3111" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3123.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3112" published="2013-06-11" name="CVE-2013-3112" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3113, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3113" published="2013-06-11" name="CVE-2013-3113" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3114" published="2013-06-11" name="CVE-2013-3114" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3119.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3116" published="2013-06-11" name="CVE-2013-3116" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3117" published="2013-06-11" name="CVE-2013-3117" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3122 and CVE-2013-3124.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3118" published="2013-06-11" name="CVE-2013-3118" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3120 and CVE-2013-3125.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3119" published="2013-06-11" name="CVE-2013-3119" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3114.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3120" published="2013-06-11" name="CVE-2013-3120" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3125.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3121" published="2013-06-11" name="CVE-2013-3121" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3139, and CVE-2013-3142.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3122" published="2013-06-11" name="CVE-2013-3122" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3117 and CVE-2013-3124.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3123" published="2013-06-11" name="CVE-2013-3123" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3111.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3124" published="2013-06-11" name="CVE-2013-3124" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3117 and CVE-2013-3122.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3125" published="2013-06-11" name="CVE-2013-3125" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3120.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3126" published="2013-06-11" name="CVE-2013-3126" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 and 10, when script debugging is enabled, does not properly handle objects in memory during the processing of script, which allows remote attackers to execute arbitrary code via a crafted web site, aka "Internet Explorer Script Debug Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3136" published="2013-06-11" name="CVE-2013-3136" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:N/A:N)" CVSS_score="4.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="2.7" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-048" source="MS" patch="1" adv="1">MS13-048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_8">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="-" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3138" published="2013-06-11" name="CVE-2013-3138" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-049" source="MS" patch="1" adv="1">MS13-049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp1:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_8">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x86"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_rt">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3139" published="2013-06-11" name="CVE-2013-3139" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3142.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3141" published="2013-06-11" name="CVE-2013-3141" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3110.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3142" published="2013-06-11" name="CVE-2013-3142" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3139.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3343" published="2013-06-11" name="CVE-2013-3343" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Adobe Flash Player before 10.3.183.90 and 11.x before 11.7.700.224 on Windows, before 10.3.183.90 and 11.x before 11.7.700.225 on Mac OS X, before 10.3.183.90 and 11.x before 11.2.202.291 on Linux, before 11.1.111.59 on Android 2.x and 3.x, and before 11.1.115.63 on Android 4.x; Adobe AIR before 3.7.0.2090 on Windows and Android and before 3.7.0.2100 on Mac OS X; and Adobe AIR SDK &amp; Compiler before 3.7.0.2090 on Windows and before 3.7.0.2100 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb13-16.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb13-16.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="adobe_air">
        <vers num="3.0.0.408"/>
        <vers num="3.0.0.4080"/>
        <vers num="3.1.0.485"/>
        <vers num="3.1.0.488"/>
        <vers num="3.1.0.4880"/>
        <vers num="3.2.0.207"/>
        <vers num="3.2.0.2070"/>
        <vers num="3.3.0.3670"/>
        <vers num="3.4.0.2540"/>
        <vers num="3.4.0.2710"/>
        <vers num="3.5.0.1060"/>
        <vers num="3.5.0.600"/>
        <vers num="3.5.0.880"/>
        <vers num="3.5.0.890"/>
        <vers num="3.6.0.597"/>
        <vers num="3.6.0.6090"/>
        <vers num="3.7.0.1530"/>
        <vers prev="1" num="3.7.0.1860"/>
      </prod>
      <prod vendor="adobe" name="adobe_air_sdk">
        <vers num="3.0.0.4080"/>
        <vers num="3.1.0.488"/>
        <vers num="3.2.0.2070"/>
        <vers num="3.3.0.3650"/>
        <vers num="3.3.0.3690"/>
        <vers num="3.4.0.2540"/>
        <vers num="3.4.0.2710"/>
        <vers num="3.5.0.1060"/>
        <vers num="3.5.0.600"/>
        <vers num="3.5.0.880"/>
        <vers num="3.5.0.890"/>
        <vers num="3.6.0.599"/>
        <vers num="3.6.0.6090"/>
        <vers num="3.7.0.1530"/>
        <vers prev="1" num="3.7.0.1860"/>
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="10.0.0.584"/>
        <vers num="10.0.12.10"/>
        <vers num="10.0.12.36"/>
        <vers num="10.0.15.3"/>
        <vers num="10.0.2.54"/>
        <vers num="10.0.22.87"/>
        <vers num="10.0.32.18"/>
        <vers num="10.0.42.34"/>
        <vers num="10.0.45.2"/>
        <vers num="10.1"/>
        <vers num="10.1.102.64"/>
        <vers num="10.1.105.6"/>
        <vers num="10.1.106.16"/>
        <vers num="10.1.106.17"/>
        <vers num="10.1.52.14"/>
        <vers num="10.1.52.14.1"/>
        <vers num="10.1.52.15"/>
        <vers num="10.1.53.64"/>
        <vers num="10.1.82.76"/>
        <vers num="10.1.85.3"/>
        <vers num="10.1.92.10"/>
        <vers num="10.1.92.8"/>
        <vers num="10.1.95.1"/>
        <vers num="10.1.95.2"/>
        <vers num="10.2.152"/>
        <vers num="10.2.152.26"/>
        <vers num="10.2.152.32"/>
        <vers num="10.2.152.33"/>
        <vers num="10.2.153.1"/>
        <vers num="10.2.154.13"/>
        <vers num="10.2.154.25"/>
        <vers num="10.2.156.12"/>
        <vers num="10.2.157.51"/>
        <vers num="10.2.159.1"/>
        <vers num="10.3.181.14"/>
        <vers num="10.3.181.16"/>
        <vers num="10.3.181.22"/>
        <vers num="10.3.181.23"/>
        <vers num="10.3.181.26"/>
        <vers num="10.3.181.34"/>
        <vers num="10.3.183.10"/>
        <vers num="10.3.183.11"/>
        <vers num="10.3.183.15"/>
        <vers num="10.3.183.16"/>
        <vers num="10.3.183.18"/>
        <vers num="10.3.183.19"/>
        <vers num="10.3.183.20"/>
        <vers num="10.3.183.23"/>
        <vers num="10.3.183.25"/>
        <vers num="10.3.183.29"/>
        <vers num="10.3.183.43"/>
        <vers num="10.3.183.48"/>
        <vers num="10.3.183.5"/>
        <vers num="10.3.183.50"/>
        <vers num="10.3.183.51"/>
        <vers num="10.3.183.61"/>
        <vers num="10.3.183.63"/>
        <vers num="10.3.183.67"/>
        <vers num="10.3.183.68"/>
        <vers num="10.3.183.7"/>
        <vers num="10.3.183.75"/>
        <vers prev="1" num="10.3.183.86"/>
        <vers num="11.0"/>
        <vers num="11.0.1.152"/>
        <vers num="11.0.1.153"/>
        <vers num="11.1"/>
        <vers num="11.1.102.55"/>
        <vers num="11.1.102.59"/>
        <vers num="11.1.102.62"/>
        <vers num="11.1.102.63"/>
        <vers num="11.1.111.44"/>
        <vers num="11.1.111.50"/>
        <vers prev="1" num="11.1.111.54"/>
        <vers num="11.1.111.8"/>
        <vers num="11.1.115.34"/>
        <vers num="11.1.115.48"/>
        <vers num="11.1.115.54"/>
        <vers num="11.1.115.58"/>
        <vers num="11.1.115.7"/>
        <vers num="11.2.202.223"/>
        <vers num="11.2.202.228"/>
        <vers num="11.2.202.233"/>
        <vers num="11.2.202.235"/>
        <vers num="11.2.202.236"/>
        <vers num="11.2.202.238"/>
        <vers num="11.2.202.243"/>
        <vers num="11.2.202.251"/>
        <vers num="11.2.202.258"/>
        <vers num="11.2.202.261"/>
        <vers num="11.2.202.262"/>
        <vers num="11.2.202.270"/>
        <vers num="11.2.202.273"/>
        <vers num="11.2.202.275"/>
        <vers num="11.2.202.280"/>
        <vers num="11.2.202.285"/>
        <vers num="11.3.300.257"/>
        <vers num="11.3.300.262"/>
        <vers num="11.3.300.265"/>
        <vers num="11.3.300.268"/>
        <vers num="11.3.300.270"/>
        <vers num="11.3.300.271"/>
        <vers num="11.3.300.273"/>
        <vers num="11.4.402.265"/>
        <vers num="11.4.402.278"/>
        <vers num="11.4.402.287"/>
        <vers num="11.5.502.110"/>
        <vers num="11.5.502.135"/>
        <vers num="11.5.502.136"/>
        <vers num="11.5.502.146"/>
        <vers num="11.5.502.149"/>
        <vers num="11.6.602.167"/>
        <vers num="11.6.602.168"/>
        <vers num="11.6.602.171"/>
        <vers num="11.6.602.180"/>
        <vers num="11.7.700.169"/>
        <vers prev="1" num="11.7.700.202"/>
        <vers prev="1" num="11.7.700.203"/>
        <vers num="6.0.21.0"/>
        <vers num="6.0.79"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.14.0"/>
        <vers num="7.0.19.0"/>
        <vers num="7.0.24.0"/>
        <vers num="7.0.25"/>
        <vers num="7.0.53.0"/>
        <vers num="7.0.60.0"/>
        <vers num="7.0.61.0"/>
        <vers num="7.0.63"/>
        <vers num="7.0.66.0"/>
        <vers num="7.0.67.0"/>
        <vers num="7.0.68.0"/>
        <vers num="7.0.69.0"/>
        <vers num="7.0.70.0"/>
        <vers num="7.0.73.0"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.2"/>
        <vers num="8.0"/>
        <vers num="8.0.22.0"/>
        <vers num="8.0.24.0"/>
        <vers num="8.0.33.0"/>
        <vers num="8.0.34.0"/>
        <vers num="8.0.35.0"/>
        <vers num="8.0.39.0"/>
        <vers num="8.0.42.0"/>
        <vers num="9.0"/>
        <vers num="9.0.112.0"/>
        <vers num="9.0.114.0"/>
        <vers num="9.0.115.0"/>
        <vers num="9.0.124.0"/>
        <vers num="9.0.125.0"/>
        <vers num="9.0.151.0"/>
        <vers num="9.0.152.0"/>
        <vers num="9.0.155.0"/>
        <vers num="9.0.159.0"/>
        <vers num="9.0.16"/>
        <vers num="9.0.18d60"/>
        <vers num="9.0.20"/>
        <vers num="9.0.20.0"/>
        <vers num="9.0.246.0"/>
        <vers num="9.0.260.0"/>
        <vers num="9.0.262.0"/>
        <vers num="9.0.277.0"/>
        <vers num="9.0.28"/>
        <vers num="9.0.28.0"/>
        <vers num="9.0.280"/>
        <vers num="9.0.283.0"/>
        <vers num="9.0.31"/>
        <vers num="9.0.31.0"/>
        <vers num="9.0.45.0"/>
        <vers num="9.0.47.0"/>
        <vers num="9.0.48.0"/>
        <vers num="9.0.8.0"/>
        <vers num="9.0.9.0"/>
        <vers num="9.125.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3375" published="2013-06-14" name="CVE-2013-3375" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the portal page in Cisco Prime Central for Hosted Collaboration Solution allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCue23798.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3375" source="CISCO" adv="1">20130613 Cisco Prime Central for Hosted Collaboration Solution Cross-Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="prime_central_for_hosted_collaboration_solution">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3376" published="2013-06-14" name="CVE-2013-3376" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCty74490.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3376" source="CISCO" adv="1">20130612 Cisco Video Surveillance Operations Manager Help Page Allows Loading Remote Sites</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="video_surveillance_operations_manager">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3380" published="2013-06-11" name="CVE-2013-3380" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The administrative web interface in the Access Control Server in Cisco Secure Access Control System (ACS) does not properly restrict the report view page, which allows remote authenticated users to obtain sensitive information via a direct request, aka Bug ID CSCue79279.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3380" source="CISCO" adv="1">20130610 Cisco Access Control Server Privilege Escalation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3381" published="2013-06-11" name="CVE-2013-3381" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Hosted Collaboration Mediation allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed UDP packets on port 162, aka Bug ID CSCug85756.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3381" source="CISCO" adv="1">20130610 Cisco Hosted Collaboration Mediation Excessive CPU Utilization Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="hosted_collaboration_solution">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3520" published="2013-06-16" name="CVE-2013-3520" modified="2013-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2013-0008.html" source="CONFIRM" adv="1">http://www.vmware.com/security/advisories/VMSA-2013-0008.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="vcenter_chargeback_manager">
        <vers num="1.5.0"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers prev="1" num="2.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3555" published="2013-05-24" name="CVE-2013-3555" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">epan/dissectors/packet-gtpv2.c in the GTPv2 dissector in Wireshark 1.8.x before 1.8.7 calls incorrect functions in certain contexts related to ciphers, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=48393" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=48393</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-gtpv2.c?r1=48393&amp;r2=48392&amp;pathrev=48393" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-gtpv2.c?r1=48393&amp;r2=48392&amp;pathrev=48393</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8493" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8493</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2013-24.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2013-24.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2700" source="DEBIAN">DSA-2700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3557" published="2013-05-24" name="CVE-2013-3557" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The dissect_ber_choice function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.6.x before 1.6.15 and 1.8.x before 1.8.7 does not properly initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=48944" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=48944</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-ber.c?r1=48944&amp;r2=48943&amp;pathrev=48944" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-ber.c?r1=48944&amp;r2=48943&amp;pathrev=48944</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8599" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8599</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2013-25.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2013-25.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2700" source="DEBIAN">DSA-2700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.10"/>
        <vers num="1.6.11"/>
        <vers num="1.6.12"/>
        <vers num="1.6.13"/>
        <vers num="1.6.14"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6.6"/>
        <vers num="1.6.7"/>
        <vers num="1.6.8"/>
        <vers num="1.6.9"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3558" published="2013-05-24" name="CVE-2013-3558" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP CCP dissector in Wireshark 1.8.x before 1.8.7 does not terminate a bit-field list, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8638" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8638</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2013-26.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2013-26.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2700" source="DEBIAN">DSA-2700</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=49214" source="CONFIRM">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=49214</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-ppp.c?r1=49214&amp;r2=49213&amp;pathrev=49214" source="CONFIRM">http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-ppp.c?r1=49214&amp;r2=49213&amp;pathrev=49214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3559" published="2013-05-24" name="CVE-2013-3559" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (integer overflow, and heap memory corruption or NULL pointer dereference, and application crash) via a malformed packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=48644" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=48644</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8541" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8541</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8540" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8540</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8231" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8231</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2013-27.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2013-27.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2700" source="DEBIAN">DSA-2700</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-dcp-etsi.c?r1=48644&amp;r2=48643&amp;pathrev=48644" source="CONFIRM">http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-dcp-etsi.c?r1=48644&amp;r2=48643&amp;pathrev=48644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3560" published="2013-05-24" name="CVE-2013-3560" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7 uses an incorrect format string, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=48332" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=48332</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-mpeg-dsmcc.c?r1=48332&amp;r2=48331&amp;pathrev=48332" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-mpeg-dsmcc.c?r1=48332&amp;r2=48331&amp;pathrev=48332</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8481" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8481</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2013-28.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2013-28.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2700" source="DEBIAN">DSA-2700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3562" published="2013-05-24" name="CVE-2013-3562" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.c in the Websocket dissector in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (application crash) via a malformed packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=48419" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=48419</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc/trunk-1.8/epan/dissectors/packet-websocket.c?r1=48419&amp;r2=48418&amp;pathrev=48419" source="CONFIRM" patch="1">http://anonsvn.wireshark.org/viewvc/trunk-1.8/epan/dissectors/packet-websocket.c?r1=48419&amp;r2=48418&amp;pathrev=48419</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8499" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8499</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2013-29.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2013-29.html</ref>
      <ref url="http://www.debian.org/security/2013/dsa-2700" source="DEBIAN">DSA-2700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3573" published="2013-06-14" name="CVE-2013-3573" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">HP Insight Diagnostics 9.4.0.4710 allows remote attackers to conduct unspecified injection attacks via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/324668" source="CERT-VN">VU#324668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_diagnostics">
        <vers num="9.4.0.4710"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3574" published="2013-06-14" name="CVE-2013-3574" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full pathname in the argument to the devicePath (aka mount) parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/324668" source="CERT-VN">VU#324668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_diagnostics">
        <vers num="9.4.0.4710"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3575" published="2013-06-14" name="CVE-2013-3575" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows remote attackers to include arbitrary hpdiags/frontend2/help/ .html files via the path parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/324668" source="CERT-VN">VU#324668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_diagnostics">
        <vers num="9.4.0.4710"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3576" published="2013-06-14" name="CVE-2013-3576" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to execute arbitrary commands via shell metacharacters in the PATH_INFO to smhutil/snmpchp.php.en.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/735364" source="CERT-VN">VU#735364</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="system_management_homepage">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3642" published="2013-06-16" name="CVE-2013-3642" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Angel Browser application 1.47b and earlier for Android 1.6 through 2.1, 1.62b and earlier for Android 2.2 through 2.3.4, 1.68b and earlier for Android 3.0 through 4.0.3, and 1.76b and earlier for Android 4.1 through 4.2 does not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000055" source="JVNDB">JVNDB-2013-000055</ref>
      <ref url="http://jvn.jp/en/jp/JVN79301570/index.html" source="JVN">JVN#79301570</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adgjm" name="angel_browser">
        <vers prev="1" num="1.47b"/>
        <vers prev="1" num="1.62b"/>
        <vers prev="1" num="1.68b"/>
        <vers prev="1" num="1.76b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3643" published="2013-06-16" name="CVE-2013-3643" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Galapagos Browser application for Android does not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000056" source="JVNDB">JVNDB-2013-000056</ref>
      <ref url="http://jvn.jp/en/jp/JVN99813183/index.html" source="JVN">JVN#99813183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adgjm" name="galapagos_browser">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3644" published="2013-06-18" name="CVE-2013-3644" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in JustSystems Ichitaro 2006 through 2013; Ichitaro Pro through 2; Ichitaro Government 6, 7, and 2006 through 2010; Ichitaro Portable with oreplug; Ichitaro Viewer; and Ichitaro JUST School through 2010 allows remote attackers to execute arbitrary code via a crafted document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.justsystems.com/jp/info/js13002.html" source="CONFIRM">http://www.justsystems.com/jp/info/js13002.html</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000058" source="JVNDB">JVNDB-2013-000058</ref>
      <ref url="http://jvn.jp/en/jp/JVN98712361/index.html" source="JVN">JVN#98712361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="justsystems" name="ichitaro">
        <vers num="2006" edition="-"/>
        <vers num="2006" edition="-:government"/>
        <vers num="2007" edition="-"/>
        <vers num="2007" edition="-:government"/>
        <vers num="2008" edition="-"/>
        <vers num="2008" edition="-:government"/>
        <vers num="2009" edition="-"/>
        <vers num="2009" edition="-:government"/>
        <vers num="2010" edition="-"/>
        <vers num="2010" edition="-:government"/>
        <vers num="2011"/>
        <vers num="2012"/>
        <vers num="2013"/>
        <vers num="6" edition="-"/>
        <vers num="6" edition="-:government"/>
        <vers num="7" edition="-"/>
        <vers num="7" edition="-:government"/>
      </prod>
      <prod vendor="justsystems" name="ichitaro_just_school">
        <vers num="-"/>
      </prod>
      <prod vendor="justsystems" name="ichitaro_portable">
        <vers num="-" edition="oreplug"/>
      </prod>
      <prod vendor="justsystems" name="ichitaro_viewer">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3645" published="2013-06-14" name="CVE-2013-3645" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Orchard.Comments module in Orchard before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://docs.orchardproject.net/Documentation/Patch-4-30-2013" source="CONFIRM" patch="1" adv="1">http://docs.orchardproject.net/Documentation/Patch-4-30-2013</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000057" source="JVNDB">JVNDB-2013-000057</ref>
      <ref url="http://jvn.jp/en/jp/JVN53622030/index.html" source="JVN">JVN#53622030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orchardproject" name="orchard">
        <vers num="0.1"/>
        <vers num="0.5"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.41"/>
        <vers num="1.42"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers prev="1" num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3646" published="2013-06-18" name="CVE-2013-3646" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Cybozu Live application before 2.0.1 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site. NOTE: this vulnerability exists because of a CVE-2012-4008 regression.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://live.cybozu.co.jp/trouble.html?q=2530" source="CONFIRM" adv="1">https://live.cybozu.co.jp/trouble.html?q=2530</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000059" source="JVNDB">JVNDB-2013-000059</ref>
      <ref url="http://jvn.jp/en/jp/JVN63428218/index.html" source="JVN">JVN#63428218</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cybozu" name="cybozu_live">
        <vers num="1.0.4" edition="-"/>
        <vers num="1.0.4" edition="-:~~~android~~"/>
        <vers prev="1" num="2.0.0" edition="-"/>
        <vers prev="1" num="2.0.0" edition="-:~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3647" published="2013-06-18" name="CVE-2013-3647" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The WebView class in the Cybozu Live application before 2.0.1 for Android allows attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL.  NOTE: this vulnerability exists because of a CVE-2012-4009 regression.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://live.cybozu.co.jp/trouble.html?q=2530" source="CONFIRM" adv="1">https://live.cybozu.co.jp/trouble.html?q=2530</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000060" source="JVNDB">JVNDB-2013-000060</ref>
      <ref url="http://jvn.jp/en/jp/JVN19740283/index.html" source="JVN">JVN#19740283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cybozu" name="cybozu_live">
        <vers num="1.0.4" edition="-"/>
        <vers num="1.0.4" edition="-:~~~android~~"/>
        <vers prev="1" num="2.0.0" edition="-"/>
        <vers prev="1" num="2.0.0" edition="-:~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3675" published="2013-06-09" name="CVE-2013-3675" modified="2013-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The process_frame_obj function in sanm.c in libavcodec in FFmpeg before 1.2.1 does not validate width and height values, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) via crafted LucasArts Smush video data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://git.videolan.org/?p=ffmpeg.git;a=commit;h=9dd04f6d8cdd1c10c28b2cb4252c1a41df581915" source="CONFIRM" patch="1">http://git.videolan.org/?p=ffmpeg.git;a=commit;h=9dd04f6d8cdd1c10c28b2cb4252c1a41df581915</ref>
      <ref url="http://git.videolan.org/?p=ffmpeg.git;a=commit;h=524d0d2cfc7bab1b348f85e7c0369859e63781cf" source="CONFIRM" patch="1">http://git.videolan.org/?p=ffmpeg.git;a=commit;h=524d0d2cfc7bab1b348f85e7c0369859e63781cf</ref>
      <ref url="http://ffmpeg.org/security.html" source="CONFIRM">http://ffmpeg.org/security.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ffmpeg" name="ffmpeg">
        <vers prev="1" num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3743" published="2013-06-18" name="CVE-2013-3743" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 45 and earlier and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3744" published="2013-06-18" name="CVE-2013-3744" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2400.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3927" published="2013-06-18" name="CVE-2013-3927" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the client library in Siemens COMOS 9.2 before 9.2.0.6.10 and 10.0 before 10.0.3.0.4 allows local users to obtain unintended write access to the database by leveraging read access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-194865.pdf" source="CONFIRM" adv="1">http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-194865.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="comos">
        <vers num="10.0"/>
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3957" published="2013-06-14" name="CVE-2013-3957" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf" source="CONFIRM" adv="1">http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="simatic_pcs7">
        <vers prev="1" num="8.0" edition="sp1"/>
      </prod>
      <prod vendor="siemens" name="wincc">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.1" edition="sp1"/>
        <vers prev="1" num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3958" published="2013-06-14" name="CVE-2013-3958" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for remote attackers to obtain access via an unspecified request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf" source="CONFIRM" adv="1">http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="simatic_pcs7">
        <vers prev="1" num="8.0" edition="sp1"/>
      </prod>
      <prod vendor="siemens" name="wincc">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.1" edition="sp1"/>
        <vers prev="1" num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3959" published="2013-06-14" name="CVE-2013-3959" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the user account exists, which allows remote authenticated users to enumerate account names via crafted URL parameters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf" source="CONFIRM" adv="1">http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="simatic_pcs7">
        <vers prev="1" num="8.0" edition="sp1"/>
      </prod>
      <prod vendor="siemens" name="wincc">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.1" edition="sp1"/>
        <vers prev="1" num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3970" published="2013-06-13" name="CVE-2013-3970" modified="2013-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 include a test Certification Authority (CA) certificate in the Trusted Server CAs list, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging control over that test CA.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://kb.juniper.net/JSA10571" source="CONFIRM" patch="1" adv="1">http://kb.juniper.net/JSA10571</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juniper" name="junos_pulse_access_control_service">
        <vers num="4.1r1"/>
        <vers num="4.1r1.1"/>
        <vers num="4.1r2"/>
        <vers num="4.1r3"/>
        <vers num="4.1r4"/>
        <vers num="4.1r5"/>
      </prod>
      <prod vendor="juniper" name="junos_pulse_secure_access_service">
        <vers num="7.0r2"/>
        <vers num="7.0r3"/>
        <vers num="7.0r4"/>
        <vers num="7.0r5"/>
        <vers num="7.0r5.1"/>
        <vers num="7.0r6"/>
        <vers num="7.0r7"/>
        <vers num="7.0r8"/>
        <vers num="7.1r1"/>
        <vers num="7.1r1.1"/>
        <vers num="7.1r2"/>
        <vers num="7.1r3"/>
        <vers num="7.1r4"/>
        <vers num="7.1r5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-4082" published="2013-06-09" name="CVE-2013-4082" modified="2013-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The vwr_read function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before 1.8.8 does not validate the relationship between a record length and a trailer length, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8760" source="CONFIRM" adv="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8760</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2013-40.html" source="CONFIRM">http://www.wireshark.org/security/wnpa-sec-2013-40.html</ref>
      <ref url="http://www.wireshark.org/docs/relnotes/wireshark-1.8.8.html" source="CONFIRM">http://www.wireshark.org/docs/relnotes/wireshark-1.8.8.html</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=49739" source="CONFIRM">http://anonsvn.wireshark.org/viewvc?view=revision&amp;revision=49739</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc/trunk/wiretap/vwr.c?r1=49739&amp;r2=49738&amp;pathrev=49739" source="CONFIRM">http://anonsvn.wireshark.org/viewvc/trunk/wiretap/vwr.c?r1=49739&amp;r2=49738&amp;pathrev=49739</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.8.6"/>
        <vers num="1.8.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-4608" published="2013-06-17" name="CVE-2013-4608" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in REDCap before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving the Graphical Data View &amp; Descriptive Stats page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.13.18"/>
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers num="4.14.4"/>
        <vers num="4.14.5"/>
        <vers num="4.14.6"/>
        <vers num="4.15.0"/>
        <vers num="4.15.1"/>
        <vers num="4.15.2"/>
        <vers num="4.15.3"/>
        <vers num="4.15.4"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-4609" published="2013-06-17" name="CVE-2013-4609" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.13.18"/>
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers num="4.14.4"/>
        <vers num="4.14.5"/>
        <vers num="4.14.6"/>
        <vers num="4.15.0"/>
        <vers num="4.15.1"/>
        <vers num="4.15.2"/>
        <vers num="4.15.3"/>
        <vers num="4.15.4"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers prev="1" num="5.0.3"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="5.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-4610" published="2013-06-17" name="CVE-2013-4610" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.13.18"/>
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers num="4.14.4"/>
        <vers num="4.14.5"/>
        <vers num="4.14.6"/>
        <vers num="4.15.0"/>
        <vers num="4.15.1"/>
        <vers num="4.15.2"/>
        <vers num="4.15.3"/>
        <vers num="4.15.4"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers prev="1" num="5.0.2"/>
        <vers num="5.0.6"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-4611" published="2013-06-17" name="CVE-2013-4611" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the Online Designer page or (2) the Manage Survey Participants page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.13.18"/>
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers num="4.14.4"/>
        <vers num="4.14.5"/>
        <vers num="4.14.6"/>
        <vers num="4.15.0"/>
        <vers num="4.15.1"/>
        <vers num="4.15.2"/>
        <vers num="4.15.3"/>
        <vers num="4.15.4"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers prev="1" num="5.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-4612" published="2013-06-17" name="CVE-2013-4612" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in REDCap before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving different modules.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.13.18"/>
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers num="4.14.4"/>
        <vers num="4.14.5"/>
        <vers num="4.14.6"/>
        <vers num="4.15.0"/>
        <vers num="4.15.1"/>
        <vers num="4.15.2"/>
        <vers num="4.15.3"/>
        <vers num="4.15.4"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers prev="1" num="5.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-4616" published="2013-06-18" name="CVE-2013-4616" modified="2013-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The WifiPasswordController generateDefaultPassword method in Preferences in Apple iOS 6 and earlier relies on the UITextChecker suggestWordInLanguage method for selection of Wi-Fi hotspot WPA2 PSK passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack that leverages the insufficient number of possible passphrases.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www1.cs.fau.de/hotspot" source="MISC">http://www1.cs.fau.de/hotspot</ref>
      <ref url="http://www1.cs.fau.de/filepool/projects/hotspot/hotspot.pdf" source="MISC">http://www1.cs.fau.de/filepool/projects/hotspot/hotspot.pdf</ref>
      <ref url="http://lists.owasp.org/pipermail/owasp-mobile-security-project/2013-June/000640.html" source="MLIST">[owasp-mobile-security-project] 20130617 Cracking iOS personal hotspots using a Scrabble crossword game word list</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-4622" published="2013-06-19" name="CVE-2013-4622" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The 3G Mobile Hotspot feature on the HTC Droid Incredible has a default WPA2 PSK passphrase of 1234567890, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www1.cs.fau.de/filepool/projects/hotspot/hotspot.pdf" source="MISC">http://www1.cs.fau.de/filepool/projects/hotspot/hotspot.pdf</ref>
      <ref url="http://support.verizonwireless.com/clc/devices/knowledge_base.html?id=35523" source="CONFIRM">http://support.verizonwireless.com/clc/devices/knowledge_base.html?id=35523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="htc" name="droid_incredible">
        <vers num="-"/>
        <vers num="frf91"/>
      </prod>
    </vuln_soft>
  </entry>
</nvd>