<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" nvd_xml_version="1.2" pub_date="2009-11-07" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-1999-1395" seq="1999-1395" severity="High" type="CVE" published="1992-11-17" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2009-10-31">
        <desc>
            <descript source="cve">Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-92.16.VMS.Monitor.vulnerability" adv="1">CA-92.16</ref>
            <ref source="CERT" patch="1" url="http://www.cert.org/advisories/CA-1992-18.html" adv="1">CA-1992-18</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/51">51</ref>
            <ref source="XF" url="http://www.iss.net/security_center/static/7136.php">vms-monitor-gain-privileges(7136)</ref>
            <ref source="OSVDB" url="http://osvdb.org/59332">59332</ref>
        </refs>
        <vuln_soft>
            <prod vendor="dec" name="dec_openvms">
                <vers num="5.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.1" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1b" />
                <vers num="5.2" />
                <vers num="5.2.1" />
                <vers num="5.3" />
                <vers num="5.3.1" />
                <vers num="5.3.2" />
                <vers num="5.4" />
                <vers num="5.4.1" />
                <vers num="5.4.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-1999-0593" seq="1999-0593" severity="Low" type="CVE" published="1999-01-01" CVSS_version="2.0" CVSS_score="2.1" modified="2009-10-31">
        <desc>
            <descript source="cve">The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1291">nt-shutdown-without-logon(1291)</ref>
            <ref source="MISC" url="http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true">http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true</ref>
            <ref source="CONFIRM" url="http://technet.microsoft.com/en-us/library/cc722469.aspx">http://technet.microsoft.com/en-us/library/cc722469.aspx</ref>
            <ref source="OSVDB" url="http://osvdb.org/59333">59333</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="windows_nt">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0498" seq="2003-0498" severity="High" type="CVE" published="2003-08-07" CVSS_version="2.0" CVSS_score="7.2" modified="2009-11-07">
        <desc>
            <descript source="cve">Cach�Ã�© Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="intersystems" name="cache_database">
                <vers num="5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0497" seq="2003-0497" severity="High" type="CVE" published="2003-08-07" CVSS_version="2.0" CVSS_score="7.2" modified="2009-11-07">
        <desc>
            <descript source="cve">Cach�Ã�© Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="intersystems" name="cache_database">
                <vers num="5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-1921" seq="2005-1921" severity="High" type="CVE" published="2005-07-05" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2009-11-07">
        <desc>
            <descript source="cve">Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MANDRAKE" patch="1" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:109" adv="1">MDKSA-2005:109</ref>
            <ref source="MISC" patch="1" url="http://www.gulftech.org/?node=research&amp;article_id=00087-07012005" adv="1">http://www.gulftech.org/?node=research&amp;article_id=00087-07012005</ref>
            <ref source="MISC" patch="1" url="http://pear.php.net/package/XML_RPC/download/1.3.1">http://pear.php.net/package/XML_RPC/download/1.3.1</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112008638320145&amp;w=2" adv="1">20050629 Advisory 02/2005: Remote code execution in Serendipity</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/419064/100/0/threaded">HPSBTU02083</ref>
            <ref source="MISC" url="http://www.hardened-php.net/advisory-022005.php" adv="1">http://www.hardened-php.net/advisory-022005.php</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/14088">14088</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/419064/100/0/threaded">SSRT051069</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-564.html">RHSA-2005:564</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_49_php.html">SUSE-SA:2005:049</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_41_php_pear.html">SUSE-SA:2005:041</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/2827">ADV-2005-2827</ref>
            <ref source="CONFIRM" url="http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt">http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-789">DSA-789</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-747">DSA-747</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-746">DSA-746</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-745">DSA-745</ref>
            <ref source="CONFIRM" url="http://www.ampache.org/announce/3_3_1_2.php">http://www.ampache.org/announce/3_3_1_2.php</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=338803">http://sourceforge.net/project/shownotes.php?release_id=338803</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/project/showfiles.php?group_id=87163">http://sourceforge.net/project/showfiles.php?group_id=87163</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015336">1015336</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200507-07.xml">GLSA-200507-07</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200507-06.xml">GLSA-200507-06</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200507-01.xml">GLSA-200507-01</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18003">18003</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17674">17674</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17440">17440</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/16693">16693</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/16339">16339</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/16001">16001</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15957">15957</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15947">15947</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15944">15944</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15922">15922</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15917">15917</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15916">15916</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15904">15904</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15903">15903</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15895">15895</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15884">15884</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15883">15883</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15872">15872</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15861">15861</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15855">15855</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15852">15852</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/15810">15810</ref>
            <ref source="SUSE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2">SUSE-SA:2005:051</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112015336720867&amp;w=2">20050629 [DRUPAL-SA-2005-003] Drupal 4.6.2 / 4.5.4 fixes critical XML-RPC issue</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:350" sig="1">oval:org.mitre.oval:def:350</ref>
        </refs>
        <vuln_soft>
            <prod vendor="pear" name="xml_rpc">
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.1.0" />
                <vers num="1.2.0" />
                <vers num="1.2.0rc1" />
                <vers num="1.2.0rc2" />
                <vers num="1.2.0rc3" />
                <vers num="1.2.0rc4" />
                <vers num="1.2.0rc5" />
                <vers num="1.2.0rc6" />
                <vers num="1.2.0rc7" />
                <vers num="1.2.1" />
                <vers num="1.2.2" />
                <vers num="1.3.0rc1" />
                <vers num="1.3.0rc2" />
                <vers num="1.3.0rc3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-1689" seq="2005-1689" severity="High" type="CVE" published="2005-07-18" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-29">
        <desc>
            <descript source="cve">Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/623332" adv="1">VU#623332</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200507-11.xml" adv="1">GLSA-200507-11</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-757" adv="1">DSA-757</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21055">kerberos-kdc-krb5recvauth-execute-code(21055)</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-224-1">USN-224-1</ref>
            <ref source="TURBO" url="http://www.turbolinux.com/security/2005/TLSA-2005-78.txt">TLSA-2005-78</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0036">2005-0036</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/14239">14239</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-567.html">RHSA-2005:567</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-562.html">RHSA-2005:562</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_17_sr.html">SUSE-SR:2005:017</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3776" adv="1">ADV-2006-3776</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/1066" adv="1">ADV-2005-1066</ref>
            <ref source="CONFIRM" url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txt">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txt</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101810-1">101810</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1014461">1014461</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22090" adv="1">22090</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17899" adv="1">17899</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17135" adv="1">17135</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/16041" adv="1">16041</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112119974704542&amp;w=2">20050712 MITKRB5-SA-2005-003: double-free in krb5_recvauth</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000993">CLA-2005:993</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.asc">20050703-01-U</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mit" name="kerberos">
                <vers num="5-1.3" />
                <vers num="5-1.3.1" />
                <vers num="5-1.3.2" />
                <vers num="5-1.3.3" />
                <vers num="5-1.3.4" />
                <vers num="5-1.3.5" />
                <vers num="5-1.3.6" />
                <vers num="5-1.4" />
                <vers num="5-1.4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-2491" seq="2005-2491" severity="High" type="CVE" published="2005-08-23" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2009-11-01">
        <desc>
            <descript source="cve">Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1014744">1014744</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/14620">14620</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/15647">15647</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</ref>
            <ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427046/100/0/threaded">FLSA:168516</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0197.html">RHSA-2006:0197</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-761.html">RHSA-2005:761</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-358.html">RHSA-2005:358</ref>
            <ref source="CONFIRM" url="http://www.php.net/release_4_4_1.php">http://www.php.net/release_4_4_1.php</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_52_apache2.html">SUSE-SA:2005:052</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_49_php.html">SUSE-SA:2005:049</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_48_pcre.html">SUSE-SA:2005:048</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-19.xml">GLSA-200509-19</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-12.xml">GLSA-200509-12</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-02.xml">GLSA-200509-02</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200508-17.xml">GLSA-200509-08</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4502">ADV-2006-4502</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4320">ADV-2006-4320</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/2659">ADV-2005-2659</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/1511">ADV-2005-1511</ref>
            <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00021.html">http://www.ethereal.com/appnotes/enpa-sa-00021.html</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-821">DSA-821</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-819">DSA-819</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-817">DSA-817</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-800">DSA-800</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-159.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-159.htm</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/604">604</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22875">22875</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22691">22691</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21522">21522</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19532">19532</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19193">19193</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19072">19072</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17813">17813</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17252">17252</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/16679">16679</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/16502">16502</ref>
            <ref source="OPENPKG" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112606064317223&amp;w=2">OpenPKG-SA-2005.018</ref>
            <ref source="SUSE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2">SUSE-SA:2005:051</ref>
            <ref source="TRUSTIX" url="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html">TSLSA-2005-0059</ref>
            <ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522">SSRT061238</ref>
            <ref source="APPLE" url="http://docs.info.apple.com/article.html?artnum=302847">APPLE-SA-2005-11-29</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U">20060401-01-U</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txt">SCOSA-2006.10</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:735" sig="1">oval:org.mitre.oval:def:735</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1659" sig="1">oval:org.mitre.oval:def:1659</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1496" sig="1">oval:org.mitre.oval:def:1496</ref>
        </refs>
        <vuln_soft>
            <prod vendor="pcre" name="pcre">
                <vers num="5.0" />
                <vers num="6.0" />
                <vers num="6.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" name="CVE-2005-4209" seq="2005-4209" severity="High" type="CVE" published="2005-12-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.1" modified="2009-10-31">
        <desc>
            <descript source="cve">WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input />
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23551">mdaemon-worldclient-subject-dos(23551)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/15815">15815</ref>
            <ref source="MISC" url="http://www.ipomonis.com/advisories/mdaemon.zip">http://www.ipomonis.com/advisories/mdaemon.zip</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17990" adv="1">17990</ref>
        </refs>
        <vuln_soft>
            <prod vendor="alt-n" name="mdaemon">
                <vers num="8.1.3" />
            </prod>
            <prod vendor="alt-n" name="worldclient">
                <vers num="8.1.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-3352" seq="2005-3352" severity="Medium" type="CVE" published="2005-12-13" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2009-10-30">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-150A.html">TA08-150A</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1015344">1015344</ref>
            <ref source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:007">MDKSA-2006:007</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/usn/usn-241-1">USN-241-1</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0074/">TSLSA-2005-0074</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/15834">15834</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450321/100/0/threaded">SSRT061265</ref>
            <ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/425399/100/0/threaded">FLSA-2006:175406</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0158.html">RHSA-2006:0158</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00060.html">FEDORA-2006-052</ref>
            <ref source="OPENPKG" url="http://www.openpkg.org/security/OpenPKG-SA-2005.029-apache.txt">OpenPKG-SA-2005.029</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-03.xml">GLSA-200602-03</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/2870">ADV-2005-2870</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK16139&amp;apar=only">PK16139</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19012">19012</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18743">18743</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18585">18585</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18526">18526</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18517">18517</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18429">18429</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18340">18340</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18339">18339</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18333">18333</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18008">18008</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17319">17319</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0159.html">RHSA-2006:0159</ref>
            <ref source="SUSE" url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html">SUSE-SR:2006:004</ref>
            <ref source="CONFIRM" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=37874">http://issues.apache.org/bugzilla/show_bug.cgi?id=37874</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U">20060101-01-U</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450321/100/0/threaded">SSRT061265</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450315/100/0/threaded">HPSBUX02172</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">SSRT061202</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_43_apache.html">SUSE-SA:2006:043</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/1697">ADV-2008-1697</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/1246/references">ADV-2008-1246</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4868">ADV-2006-4868</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4300">ADV-2006-4300</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4015">ADV-2006-4015</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3995">ADV-2006-3995</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/2423">ADV-2006-2423</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1167">DSA-1167</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK25355&amp;apar=only">PK25355</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1">102663</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1">102662</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.685483">SSA:2006-129-01</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.470158">SSA:2006-130-01</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30430">30430</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/29849">29849</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25239">25239</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23260">23260</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22669">22669</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22388">22388</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22368">22368</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22140">22140</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21744">21744</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20670">20670</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20046">20046</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0692.html">RHSA-2006:0692</ref>
            <ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html">SUSE-SR:2007:011</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html">APPLE-SA-2008-05-28</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449">SSRT071293</ref>
            <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="1.3" />
                <vers num="1.3.0" />
                <vers num="1.3.1" />
                <vers num="1.3.10" />
                <vers edition="" num="1.3.11" />
                <vers edition=":win32" num="1.3.11" />
                <vers edition="" num="1.3.12" />
                <vers edition=":win32" num="1.3.12" />
                <vers edition="" num="1.3.13" />
                <vers edition=":win32" num="1.3.13" />
                <vers edition="" num="1.3.14" />
                <vers edition=":mac_os" num="1.3.14" />
                <vers edition=":win32" num="1.3.14" />
                <vers edition="" num="1.3.15" />
                <vers edition=":win32" num="1.3.15" />
                <vers edition="" num="1.3.16" />
                <vers edition=":win32" num="1.3.16" />
                <vers edition="" num="1.3.17" />
                <vers edition=":win32" num="1.3.17" />
                <vers edition="" num="1.3.18" />
                <vers edition=":win32" num="1.3.18" />
                <vers edition="" num="1.3.19" />
                <vers edition=":win32" num="1.3.19" />
                <vers num="1.3.2" />
                <vers edition="" num="1.3.20" />
                <vers edition=":win32" num="1.3.20" />
                <vers edition="" num="1.3.22" />
                <vers edition=":win32" num="1.3.22" />
                <vers edition="" num="1.3.23" />
                <vers edition=":win32" num="1.3.23" />
                <vers edition="" num="1.3.24" />
                <vers edition=":win32" num="1.3.24" />
                <vers edition="" num="1.3.25" />
                <vers edition=":win32" num="1.3.25" />
                <vers edition="" num="1.3.26" />
                <vers edition=":win32" num="1.3.26" />
                <vers num="1.3.27" />
                <vers num="1.3.28" />
                <vers num="1.3.29" />
                <vers num="1.3.3" />
                <vers num="1.3.30" />
                <vers num="1.3.31" />
                <vers num="1.3.32" />
                <vers num="1.3.4" />
                <vers num="1.3.5" />
                <vers num="1.3.6" />
                <vers edition="" num="1.3.7" />
                <vers edition=":dev" num="1.3.7" />
                <vers num="1.3.8" />
                <vers num="1.3.9" />
                <vers num="2.0" />
                <vers edition="beta" num="2.0.28" />
                <vers edition="beta:win32" num="2.0.28" />
                <vers edition="beta" num="2.0.32" />
                <vers edition="beta:win32" num="2.0.32" />
                <vers edition="beta" num="2.0.34" />
                <vers edition="beta:win32" num="2.0.34" />
                <vers num="2.0.35" />
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.43" />
                <vers num="2.0.44" />
                <vers num="2.0.45" />
                <vers num="2.0.46" />
                <vers num="2.0.47" />
                <vers num="2.0.48" />
                <vers num="2.0.49" />
                <vers num="2.0.50" />
                <vers num="2.0.51" />
                <vers num="2.0.52" />
                <vers num="2.0.53" />
                <vers num="2.0.54" />
                <vers num="2.0.55" />
                <vers num="2.0.9" />
            </prod>
            <prod vendor="apache" name="mod_imap">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry reject="1" name="CVE-2005-4265" seq="2005-4265" type="CVE" published="2005-12-15" modified="2009-10-31">
        <desc>
            <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4209.  Reason: This candidate is a duplicate of CVE-2005-4209.  Notes: All CVE users should reference CVE-2005-4209 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
        </desc>
        <vuln_types>
            <design />
        </vuln_types>
        <refs />
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-3918" seq="2006-3918" severity="Medium" type="CVE" published="2006-07-27" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.3" modified="2009-10-31">
        <desc>
            <descript source="cve">http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/2964" adv="1">ADV-2006-2964</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/2963" adv="1">ADV-2006-2963</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/21174" adv="1">21174</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/21172" adv="1">21172</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0619.html">RHSA-2006:0619</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3264">ADV-2006-3264</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg24013080">PK27875</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK24631">PK24631</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc?view=rev&amp;revision=394965">http://svn.apache.org/viewvc?view=rev&amp;revision=394965</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1016569">1016569</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21478">21478</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21399">21399</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0618.html">RHSA-2006:0618</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-07/0425.html">20060724 Write-up by Amit Klein: "Forging HTTP request headers with Flash"</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-05/0151.html">20060508 Unfiltered Header Injection in Apache 1.3.34/2.0.57/2.2.1</ref>
            <ref source="CONFIRM" url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-575-1">USN-575-1</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/19661">19661</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_51_apache.html">SUSE-SA:2006:051</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/5089">ADV-2006-5089</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4207">ADV-2006-4207</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1167">DSA-1167</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-194.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-194.htm</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/1294">1294</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/29640">29640</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28749">28749</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22523">22523</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22317">22317</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22140">22140</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21986">21986</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21848">21848</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21744">21744</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21598">21598</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0692.html">RHSA-2006:0692</ref>
            <ref source="OPENBSD" url="http://openbsd.org/errata.html#httpd2">[3.9] 012: SECURITY FIX: October 7, 2006</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html">SUSE-SA:2008:021</ref>
            <ref source="CONFIRM" url="http://kb.vmware.com/KanisaPlatform/Publishing/466/5915871_f.SAL_Public.html">http://kb.vmware.com/KanisaPlatform/Publishing/466/5915871_f.SAL_Public.html</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P">20060801-01-P</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="1.3" />
                <vers num="1.3.1" />
                <vers edition="" num="1.3.11" />
                <vers edition=":win32" num="1.3.11" />
                <vers edition="" num="1.3.12" />
                <vers edition=":win32" num="1.3.12" />
                <vers num="1.3.17" />
                <vers num="1.3.18" />
                <vers num="1.3.19" />
                <vers num="1.3.20" />
                <vers num="1.3.22" />
                <vers num="2.0" />
                <vers num="2.0.57" />
                <vers num="2.2" />
                <vers num="2.2.1" />
            </prod>
            <prod vendor="ibm" name="http_server">
                <vers num="6.0" />
                <vers num="6.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" name="CVE-2006-3747" seq="2006-3747" severity="High" type="CVE" published="2006-07-28" CVSS_version="2.0" CVSS_score="7.6" modified="2009-10-27">
        <desc>
            <descript source="cve">Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/395412">VU#395412</ref>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-150A.html">TA08-150A</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2006/dsa-1132">DSA-1132</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2006/dsa-1131">DSA-1131</ref>
            <ref source="CONFIRM" patch="1" url="http://www.apache.org/dist/httpd/Announcement2.0.html" adv="1">http://www.apache.org/dist/httpd/Announcement2.0.html</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-538">https://issues.rpath.com/browse/RPL-538</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28063">apache-modrewrite-offbyone-bo(28063)</ref>
            <ref source="CONFIRM" url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-328-1">USN-328-1</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/19204">19204</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450321/100/0/threaded">HPSBUX02164</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/445206/100/0/threaded">HPSBUX02145</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/443870/100/0/threaded">20060820 POC &amp; exploit for Apache mod_rewrite off-by-one</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/441526/100/200/threaded">20060728 rPSA-2006-0139-1 httpd mod_ssl</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/441487/100/0/threaded">20060728 Apache mod_rewrite Buffer Overflow Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/441485/100/0/threaded">20060728 [Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/27588">27588</ref>
            <ref source="OPENPKG" url="http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.015-apache.html">OpenPKG-SA-2006.015</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_43_apache.html">SUSE-SA:2006:043</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4015" adv="1">ADV-2006-4015</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3995" adv="1">ADV-2006-3995</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3884" adv="1">ADV-2006-3884</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3282" adv="1">ADV-2006-3282</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3264" adv="1">ADV-2006-3264</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3017" adv="1">ADV-2006-3017</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg24013080">PK27875</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK29156">PK29156</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK29154">PK29154</ref>
            <ref source="MISC" url="http://svn.apache.org/viewvc?view=rev&amp;revision=426144">http://svn.apache.org/viewvc?view=rev&amp;revision=426144</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1">102663</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1">102662</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1016601">1016601</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200608-01.xml">GLSA-200608-01</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22388" adv="1">22388</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22368" adv="1">22368</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22262" adv="1">22262</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21509" adv="1">21509</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21478" adv="1">21478</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21315" adv="1">21315</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21313" adv="1">21313</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21307" adv="1">21307</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21284" adv="1">21284</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21273" adv="1">21273</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21266" adv="1">21266</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21247" adv="1">21247</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21245" adv="1">21245</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21241" adv="1">21241</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21197" adv="1">21197</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048271.html">20060728 [Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048267.html">20060728 Apache 1.3.29/2.X mod_rewrite Buffer Overflow Vulnerability CVE-2006-3747</ref>
            <ref source="MISC" url="http://kbase.redhat.com/faq/FAQ_68_8653.shtm">http://kbase.redhat.com/faq/FAQ_68_8653.shtm</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:133">MDKSA-2006:133</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450321/100/0/threaded">HPSBUX02164</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:133">MDKSA-2006:133</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/1697">ADV-2008-1697</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/1246/references">ADV-2008-1246</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/2783">ADV-2007-2783</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4868">ADV-2006-4868</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4300">ADV-2006-4300</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4207">ADV-2006-4207</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007951">http://www-1.ibm.com/support/docview.wss?uid=swg27007951</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/1312">1312</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30430">30430</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/29849">29849</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26329">26329</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23260">23260</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23028">23028</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22523">22523</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21346">21346</ref>
            <ref source="TRUSTIX" url="http://lwn.net/Alerts/194228/">2006-0044</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html">APPLE-SA-2008-05-28</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449">HPSBMA02328</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771">SSRT061275</ref>
            <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="1.3.28" />
                <vers num="1.3.29" />
                <vers num="1.3.3" />
                <vers num="1.3.30" />
                <vers num="1.3.31" />
                <vers num="1.3.32" />
                <vers num="1.3.33" />
                <vers num="1.3.4" />
                <vers num="1.3.5" />
                <vers num="1.3.6" />
                <vers edition="" num="1.3.7" />
                <vers edition=":dev" num="1.3.7" />
                <vers num="1.3.8" />
                <vers num="1.3.9" />
                <vers num="2.0.46" />
                <vers num="2.0.47" />
                <vers num="2.0.48" />
                <vers num="2.0.49" />
                <vers num="2.0.50" />
                <vers num="2.0.51" />
                <vers num="2.0.52" />
                <vers num="2.0.53" />
                <vers num="2.0.54" />
                <vers num="2.0.55" />
                <vers num="2.0.56" />
                <vers num="2.0.57" />
                <vers num="2.0.58" />
            </prod>
            <prod vendor="ubuntu" name="ubuntu_linux">
                <vers num="5.04" />
                <vers num="5.10" />
                <vers num="6.06_lts" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-2006-4339" seq="2006-4339" severity="Medium" type="CVE" published="2006-09-05" CVSS_version="2.0" CVSS_score="5.1" modified="2009-11-03">
        <desc>
            <descript source="cve">OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/845620">VU#845620</ref>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-333A.html">TA06-333A</ref>
            <ref source="DEBIAN" patch="1" url="http://www.us.debian.org/security/2006/dsa-1173">DSA-1173</ref>
            <ref source="UBUNTU" patch="1" url="http://www.ubuntu.com/usn/usn-339-1">USN-339-1</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/19849">19849</ref>
            <ref source="CONFIRM" patch="1" url="http://www.openssl.org/news/secadv_20060905.txt" adv="1">http://www.openssl.org/news/secadv_20060905.txt</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/3453" adv="1">ADV-2006-3453</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2006/dsa-1174">DSA-1174</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/21709" adv="1">21709</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-616">https://issues.rpath.com/browse/RPL-616</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28755">openssl-rsa-security-bypass(28755)</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/445822/100/0/threaded">20060912 ERRATA: [ GLSA 200609-05 ] OpenSSL, AMD64 x86 emulation base libraries: RSA signature forgery</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/445231/100/0/threaded">20060905 rPSA-2006-0163-1 openssl openssl-scripts</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0629.html">RHSA-2008:0629</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0661.html">RHSA-2006:0661</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/28549">28549</ref>
            <ref source="CONFIRM" url="http://www.opera.com/support/search/supsearch.dml?index=845">http://www.opera.com/support/search/supsearch.dml?index=845</ref>
            <ref source="OPENBSD" url="http://www.openbsd.org/errata.html">[3.9] 20060908 011: SECURITY FIX: September 8, 2006</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_55_ssl.html">SUSE-SA:2006:055</ref>
            <ref source="MISC" url="http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/">http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:161">MDKSA-2006:161</ref>
            <ref source="MLIST" url="http://www.imc.org/ietf-openpgp/mail-archive/msg14307.html">[ietf-openpgp] 20060827 Bleichenbacher's RSA signature forgery based on implementation error</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3793" adv="1">ADV-2006-3793</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3730" adv="1">ADV-2006-3730</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3566" adv="1">ADV-2006-3566</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-188.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-188.htm</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.605306">SSA:2006-257-02</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1016791">1016791</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200609-18.xml">GLSA-200609-18</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200609-05.xml">GLSA-200609-05</ref>
            <ref source="FREEBSD" url="http://security.freebsd.org/advisories/FreeBSD-SA-06:19.openssl.asc">FreeBSD-SA-06:19</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31492">31492</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22259" adv="1">22259</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22161" adv="1">22161</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22036" adv="1">22036</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21982" adv="1">21982</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21930" adv="1">21930</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21927" adv="1">21927</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21906" adv="1">21906</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21873" adv="1">21873</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21870" adv="1">21870</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21852" adv="1">21852</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21846" adv="1">21846</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21823" adv="1">21823</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21812" adv="1">21812</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21791" adv="1">21791</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21785" adv="1">21785</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21778" adv="1">21778</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21776" adv="1">21776</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21767" adv="1">21767</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771">HPSBMA02250</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495">SSRT061273</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:178">MDKSA-2006:178</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:177">MDKSA-2006:177</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc">20060901-01-P</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT071304</ref>
            <ref source="CONFIRM" url="https://secure-support.novell.com/KanisaPlatform/Publishing/41/3143224_f.SAL_Public.html">https://secure-support.novell.com/KanisaPlatform/Publishing/41/3143224_f.SAL_Public.html</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-1633">https://issues.rpath.com/browse/RPL-1633</ref>
            <ref source="CONFIRM" url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html">http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html">http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/server/doc/releasenotes_server.html">http://www.vmware.com/support/server/doc/releasenotes_server.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/player/doc/releasenotes_player.html">http://www.vmware.com/support/player/doc/releasenotes_player.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html">http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html">http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html">http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html">http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/security/advisories/VMSA-2008-0005.html">http://www.vmware.com/security/advisories/VMSA-2008-0005.html</ref>
            <ref source="CONFIRM" url="http://www.sybase.com/detail?id=1047991">http://www.sybase.com/detail?id=1047991</ref>
            <ref source="CONFIRM" url="http://www.serv-u.com/releasenotes/">http://www.serv-u.com/releasenotes/</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/28276">28276</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489739/100/0/threaded">20080318 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456546/100/200/threaded">20070110 VMware ESX server security updates</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0073.html">RHSA-2007:0073</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0072.html">RHSA-2007:0072</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0062.html">RHSA-2007:0062</ref>
            <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
            <ref source="OPENPKG" url="http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.029-bind.html">OpenPKG-SA-2006.029</ref>
            <ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.018.html">OpenPKG-SA-2006.018</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_10_ibmjava.html">SUSE-SA:2007:010</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_61_opera.html">SUSE-SA:2006:061</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_26_sr.html">SUSE-SR:2006:026</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:207">MDKSA-2006:207</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:178">MDKSA-2006:178</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:177">MDKSA-2006:177</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200610-06.xml">GLSA-200610-06</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/0905/references">ADV-2008-0905</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/4224">ADV-2007-4224</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/2783">ADV-2007-2783</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/2315">ADV-2007-2315</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/2163">ADV-2007-2163</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/1945">ADV-2007-1945</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/1815">ADV-2007-1815</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/1401">ADV-2007-1401</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/0343">ADV-2007-0343</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/0254">ADV-2007-0254</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/5146">ADV-2006-5146</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4750">ADV-2006-4750</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4744">ADV-2006-4744</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4586">ADV-2006-4586</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4417">ADV-2006-4417</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4366">ADV-2006-4366</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4329">ADV-2006-4329</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4327">ADV-2006-4327</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4216">ADV-2006-4216</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4207">ADV-2006-4207</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4206">ADV-2006-4206</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4205">ADV-2006-4205</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3936">ADV-2006-3936</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3899">ADV-2006-3899</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref>
            <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtml">20061108 Multiple Vulnerabilities in OpenSSL library</ref>
            <ref source="CISCO" url="http://www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_response09186a008077af1b.html">20061108 Multiple Vulnerabilities in OpenSSL Library</ref>
            <ref source="CONFIRM" url="http://www.bluecoat.com/support/knowledge/openSSL_RSA_Signature_forgery.html">http://www.bluecoat.com/support/knowledge/openSSL_RSA_Signature_forgery.html</ref>
            <ref source="CONFIRM" url="http://www.arkoon.fr/upload/alertes/40AK-2006-04-FR-1.1_SSL360_OPENSSL_RSA.pdf">http://www.arkoon.fr/upload/alertes/40AK-2006-04-FR-1.1_SSL360_OPENSSL_RSA.pdf</ref>
            <ref source="CONFIRM" url="http://support.attachmate.com/techdocs/2137.html">http://support.attachmate.com/techdocs/2137.html</ref>
            <ref source="CONFIRM" url="http://support.attachmate.com/techdocs/2128.html">http://support.attachmate.com/techdocs/2128.html</ref>
            <ref source="CONFIRM" url="http://support.attachmate.com/techdocs/2127.html">http://support.attachmate.com/techdocs/2127.html</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201534-1">201534</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201247-1">201247</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200708-1">200708</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102759-1">102759</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102744-1">102744</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102722-1">102722</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102696-1">102696</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102686-1">102686</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102657-1">102657</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102656-1">102656</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1">102648</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.566955">SSA:2006-310-01</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28115">28115</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26893">26893</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26329">26329</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25649">25649</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25399">25399</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25284">25284</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24950">24950</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24930">24930</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24099">24099</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23915">23915</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23841">23841</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23680">23680</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23455">23455</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23155">23155</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22949">22949</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22948">22948</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22940">22940</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22939">22939</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22938">22938</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22937">22937</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22936">22936</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22934">22934</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22932">22932</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22799">22799</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22758">22758</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22733">22733</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22711">22711</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22689">22689</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22671">22671</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22585">22585</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22545">22545</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22523">22523</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22513">22513</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22509">22509</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22446">22446</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22325">22325</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22284">22284</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22260">22260</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22232">22232</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22226">22226</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22044">22044</ref>
            <ref source="CONFIRM" url="http://openvpn.net/changelog.html">http://openvpn.net/changelog.html</ref>
            <ref source="MLIST" url="http://marc.theaimsgroup.com/?l=bind-announce&amp;m=116253119512445&amp;w=2">[bind-announce] 20061103 Internet Systems Consortium Security Advisory. [revised]</ref>
            <ref source="MLIST" url="http://lists.vmware.com/pipermail/security-announce/2008/000008.html">[security-announce] 20080317 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html">APPLE-SA-2007-12-14</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html">APPLE-SA-2006-11-28</ref>
            <ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540">HPSBUX02186</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771">HPSBMA02250</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495">SSRT061273</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:207">MDKSA-2006:207</ref>
            <ref source="MISC" url="http://docs.info.apple.com/article.html?artnum=307177">http://docs.info.apple.com/article.html?artnum=307177</ref>
            <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=304829">http://docs.info.apple.com/article.html?artnum=304829</ref>
            <ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/238">BEA07-169.00</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openssl" name="openssl">
                <vers num="0.9.1c" />
                <vers num="0.9.2b" />
                <vers num="0.9.3" />
                <vers num="0.9.3a" />
                <vers num="0.9.4" />
                <vers edition="beta1" num="0.9.5" />
                <vers edition="beta2" num="0.9.5" />
                <vers edition="beta1" num="0.9.5a" />
                <vers edition="beta2" num="0.9.5a" />
                <vers edition="beta1" num="0.9.6" />
                <vers edition="beta2" num="0.9.6" />
                <vers edition="beta3" num="0.9.6" />
                <vers edition="beta1" num="0.9.6a" />
                <vers edition="beta2" num="0.9.6a" />
                <vers edition="beta3" num="0.9.6a" />
                <vers num="0.9.6b" />
                <vers num="0.9.6c" />
                <vers num="0.9.6d" />
                <vers num="0.9.6e" />
                <vers num="0.9.6f" />
                <vers num="0.9.6g" />
                <vers num="0.9.6h" />
                <vers num="0.9.6i" />
                <vers num="0.9.6j" />
                <vers num="0.9.6k" />
                <vers num="0.9.6l" />
                <vers num="0.9.6m" />
                <vers num="0.9.7" prev="1" />
                <vers num="0.9.7a" />
                <vers num="0.9.7b" />
                <vers num="0.9.7c" />
                <vers num="0.9.7d" />
                <vers num="0.9.7e" />
                <vers num="0.9.7f" />
                <vers num="0.9.7g" />
                <vers num="0.9.7h" />
                <vers num="0.9.7i" />
                <vers num="0.9.7j" />
                <vers num="0.9.8" />
                <vers num="0.9.8a" />
                <vers num="0.9.8b" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2007-0099" seq="2007-0099" severity="High" type="CVE" published="2007-01-08" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-05">
        <desc>
            <descript source="cve">Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <race />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-316A.html">TA08-316A</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/21872">21872</ref>
            <ref source="MS" patch="1" url="http://www.microsoft.com/technet/security/Bulletin/MS08-069.mspx" adv="1">MS08-069</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2008/3111" adv="1">ADV-2008-3111</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456343/100/0/threaded">20070104 Re: RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455986/100/0/threaded">20070104 RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455965/100/0/threaded">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1021164">1021164</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23655" adv="1">23655</ref>
            <ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2007/Jan/0110.html">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5793">oval:org.mitre.oval:def:5793</ref>
            <ref source="OSVDB" url="http://osvdb.org/32627">32627</ref>
            <ref source="MISC" url="http://isc.sans.org/diary.php?storyid=2004">http://isc.sans.org/diary.php?storyid=2004</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0113.html">20070104 Re: Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="internet_explorer">
                <vers num="6" />
            </prod>
            <prod vendor="microsoft" name="xml_core_services">
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_base_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" severity="Medium" CVSS_version="2.0" type="CVE" modified="2009-11-02" name="CVE-2007-0243" seq="2007-0243" published="2007-01-17" discovered="2006-06-16" CVSS_score="6.8">
        <desc>
            <descript source="cve">Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-022A.html">TA07-022A</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/388289">VU#388289</ref>
            <ref source="MISC" patch="1" url="http://www.zerodayinitiative.com/advisories/ZDI-07-005.html" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-005.html</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1">102760</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31537">jre-gif-bo(31537)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/22085">22085</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457638/100/0/threaded">20070121 Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability Prove Of Concept Exploit</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457159/100/0/threaded">20070117 ZDI-07-005: Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0956.html">RHSA-2007:0956</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0167.html">RHSA-2007:0167</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0166.html">RHSA-2007:0166</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_45_java.html">SUSE-SA:2007:045</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200702-07.xml">GLSA-200702-07</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/4224">ADV-2007-4224</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/1814">ADV-2007-1814</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/0936">ADV-2007-0936</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/0211">ADV-2007-0211</ref>
            <ref source="CONFIRM" url="http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html">http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html</ref>
            <ref source="CONFIRM" url="http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html">http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1017520">1017520</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/2158">2158</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200702-08.xml">GLSA-200702-08</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28115">28115</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27203">27203</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26645">26645</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26119">26119</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26049">26049</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25283">25283</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24993">24993</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24468">24468</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24202">24202</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24189">24189</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23757">23757</ref>
            <ref source="OSVDB" url="http://osvdb.org/32834">32834</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html">APPLE-SA-2007-12-14</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">SSRT071318</ref>
            <ref source="MISC" url="http://docs.info.apple.com/article.html?artnum=307177">http://docs.info.apple.com/article.html?artnum=307177</ref>
            <ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/242">BEA07-172.00</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update3" num="1.5.0" prev="1" />
                <vers edition="update4" num="1.5.0" prev="1" />
                <vers edition="update5" num="1.5.0" prev="1" />
                <vers edition="update7" num="1.5.0" prev="1" />
                <vers edition="update8" num="1.5.0" prev="1" />
                <vers edition="update9" num="1.5.0" prev="1" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update16" num="1.3.1" prev="1" />
                <vers edition="update18" num="1.3.1" prev="1" />
                <vers edition="update1" num="1.4.2" />
                <vers edition="update10" num="1.4.2" />
                <vers edition="update11" num="1.4.2" />
                <vers edition="update12" num="1.4.2" />
                <vers edition="update2" num="1.4.2" />
                <vers edition="update3" num="1.4.2" />
                <vers edition="update4" num="1.4.2" />
                <vers edition="update5" num="1.4.2" />
                <vers edition="update6" num="1.4.2" />
                <vers edition="update7" num="1.4.2" />
                <vers edition="update8" num="1.4.2" />
                <vers edition="update9" num="1.4.2" />
                <vers edition="update3" num="1.5.0" />
                <vers edition="update4" num="1.5.0" />
                <vers edition="update5" num="1.5.0" />
                <vers edition="update6" num="1.5.0" />
                <vers edition="update7" num="1.5.0" />
                <vers edition="update8" num="1.5.0" />
                <vers edition="update9" num="1.5.0" />
            </prod>
            <prod vendor="sun" name="sdk">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_18" />
                <vers num="1.4.2" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_12" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2007-2872" seq="2007-2872" severity="Medium" type="CVE" published="2007-06-04" CVSS_version="2.0" CVSS_score="6.8" modified="2009-11-01">
        <desc>
            <descript source="cve">Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.php.net/releases/5_2_3.php">http://www.php.net/releases/5_2_3.php</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.html">FEDORA-2007-2215</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00354.html">FEDORA-2007-709</ref>
            <ref source="CONFIRM" url="https://launchpad.net/bugs/173043">https://launchpad.net/bugs/173043</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-1702">https://issues.rpath.com/browse/RPL-1702</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-1693">https://issues.rpath.com/browse/RPL-1693</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39398">php-chunksplit-security-bypass(39398)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2008/0059">ADV-2008-0059</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-549-1">USN-549-1</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-549-2">USN-549-2</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0023/">2007-0023</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1018186">1018186</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/24261">24261</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470244/100/0/threaded">20070601 SEC Consult SA-20070601-0 :: PHP chunk_split() integer overflow</ref>
            <ref source="MISC" url="http://www.sec-consult.com/291.html">http://www.sec-consult.com/291.html</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0891.html">RHSA-2007:0891</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0890.html">RHSA-2007:0890</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0888.html">RHSA-2007:0888</ref>
            <ref source="CONFIRM" url="http://www.php.net/releases/4_4_8.php">http://www.php.net/releases/4_4_8.php</ref>
            <ref source="CONFIRM" url="http://www.php.net/ChangeLog-4.php">http://www.php.net/ChangeLog-4.php</ref>
            <ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.020.html">OpenPKG-SA-2007.020</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:187">MDKSA-2007:187</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml">GLSA-200710-02</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/3386" adv="1">ADV-2007-3386</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/2061" adv="1">ADV-2007-2061</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm">http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.482863">SSA:2007-152-01</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28318" adv="1">28318</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27864" adv="1">27864</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27545" adv="1">27545</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27377" adv="1">27377</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27351" adv="1">27351</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27110" adv="1">27110</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27102" adv="1">27102</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27037" adv="1">27037</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26967" adv="1">26967</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26930" adv="1">26930</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26895" adv="1">26895</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26871" adv="1">26871</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26838" adv="1">26838</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26231" adv="1">26231</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26048" adv="1">26048</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25535" adv="1">25535</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25456" adv="1">25456</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0889.html">RHSA-2007:0889</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html">SUSE-SA:2007:044</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501">HPSBUX02308</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/491693/100/0/threaded">SSRT080056</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/0398">ADV-2008-0398</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.335136">SSA:2008-045-03</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30040">30040</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28936">28936</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28750">28750</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28658">28658</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html">SUSE-SA:2008:004</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501">HPSBUX02308</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="4.4.7" prev="1" />
                <vers num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.1" />
                <vers num="5.1.0" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1.3" />
                <vers num="5.1.4" />
                <vers num="5.1.5" />
                <vers num="5.1.6" />
                <vers num="5.2.0" />
                <vers num="5.2.1" />
                <vers num="5.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2007-3285" seq="2007-3285" severity="Medium" type="CVE" published="2007-06-20" CVSS_version="2.0" CVSS_score="6.8" modified="2009-10-26">
        <desc>
            <descript source="cve">Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=383478">https://bugzilla.mozilla.org/show_bug.cgi?id=383478</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-490-1">USN-490-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1018413">1018413</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/24447">24447</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_49_mozilla.html">SUSE-SA:2007:049</ref>
            <ref source="CONFIRM" url="http://www.mozilla.org/security/announce/2007/mfsa2007-22.html">http://www.mozilla.org/security/announce/2007/mfsa2007-22.html</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:152">MDKSA-2007:152</ref>
            <ref source="MISC" url="http://www.0x000000.com/?i=333">http://www.0x000000.com/?i=333</ref>
            <ref source="CONFIRM" url="http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html">http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26271" adv="1">26271</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26258" adv="1">26258</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26216" adv="1">26216</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26204" adv="1">26204</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26149" adv="1">26149</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26072" adv="1">26072</ref>
            <ref source="OSVDB" url="http://osvdb.org/38032">38032</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">SSRT061181</ref>
            <ref source="CONFIRM" url="ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt">ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/4256">ADV-2007-4256</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1">201516</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1">103177</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28135">28135</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">SSRT061181</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="0.10" />
                <vers num="0.10.1" />
                <vers num="0.8" />
                <vers num="0.9" />
                <vers num="0.9.1" />
                <vers num="0.9.2" />
                <vers num="0.9.3" />
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.5" />
                <vers num="1.5.0.1" />
                <vers num="1.5.0.10" />
                <vers num="1.5.0.11" />
                <vers num="1.5.0.2" />
                <vers num="1.5.0.3" />
                <vers num="1.5.0.4" />
                <vers num="1.5.0.5" />
                <vers num="1.5.0.6" />
                <vers num="1.5.0.7" />
                <vers num="1.5.0.8" />
                <vers num="1.5.0.9" />
                <vers num="1.5.1" />
                <vers num="1.5.2" />
                <vers num="1.5.3" />
                <vers num="1.5.4" />
                <vers num="1.5.5" />
                <vers num="1.5.6" />
                <vers num="1.5.7" />
                <vers num="1.5.8" />
                <vers edition="beta1" num="2.0" />
                <vers edition="rc2" num="2.0" />
                <vers edition="rc3" num="2.0" />
                <vers num="2.0.0.1" />
                <vers num="2.0.0.2" />
                <vers num="2.0.0.3" />
                <vers num="2.0.0.4" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2007-4465" seq="2007-4465" severity="Medium" type="CVE" published="2007-09-13" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-31">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset.  NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-150A.html">TA08-150A</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/25653">25653</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/479237/100/0/threaded">20070912 Apache2 Undefined Charset UTF-7 XSS Vulnerability</ref>
            <ref source="CONFIRM" url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html</ref>
            <ref source="CONFIRM" url="http://www.apache.org/dist/httpd/CHANGES_2.2.6">http://www.apache.org/dist/httpd/CHANGES_2.2.6</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/3113">3113</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/46">20070912 Apache2 Undefined Charset UTF-7 XSS Vulnerability</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33105">33105</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31651">31651</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6089">oval:org.mitre.oval:def:6089</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">HPSBUX02365</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">HPSBUX02365</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00353.html">FEDORA-2007-707</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/36586">apache-utf7-xss(36586)</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-575-1">USN-575-1</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0008.html">RHSA-2008:0008</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0006.html">RHSA-2008:0006</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0005.html">RHSA-2008:0005</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0004.html">RHSA-2008:0004</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0911.html">RHSA-2007:0911</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html">FEDORA-2007-2214</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_61_apache2.html">SUSE-SA:2007:061</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:014">MDVSA-2008:014</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/1697">ADV-2008-1697</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm">http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1019194">1019194</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-06.xml">GLSA-200711-06</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30430">30430</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28749">28749</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28607">28607</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28471">28471</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28467">28467</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27732">27732</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27563">27563</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26952">26952</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26842">26842</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html">APPLE-SA-2008-05-28</ref>
            <ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=186219">http://bugs.gentoo.org/show_bug.cgi?id=186219</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="2.0" />
                <vers edition="beta" num="2.0.28" />
                <vers edition="beta" num="2.0.32" />
                <vers edition="beta" num="2.0.34" />
                <vers num="2.0.35" />
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.43" />
                <vers num="2.0.44" />
                <vers num="2.0.45" />
                <vers num="2.0.46" />
                <vers num="2.0.47" />
                <vers num="2.0.48" />
                <vers num="2.0.49" />
                <vers num="2.0.50" />
                <vers num="2.0.51" />
                <vers num="2.0.52" />
                <vers num="2.0.53" />
                <vers num="2.0.54" />
                <vers num="2.0.55" />
                <vers num="2.0.56" />
                <vers num="2.0.57" />
                <vers num="2.0.58" />
                <vers num="2.0.59" />
                <vers num="2.0.60" />
                <vers num="2.0.61" />
                <vers num="2.0.9" />
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.7" />
                <vers num="2.1.8" />
                <vers num="2.2" />
                <vers num="2.2.1" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2007-6203" seq="2007-6203" severity="Medium" type="CVE" published="2007-12-03" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-31">
        <desc>
            <descript source="cve">Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/38800">apache-413error-xss(38800)</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-731-1">USN-731-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1019030">1019030</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/26663">26663</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/484410/100/0/threaded">20071130 PR07-37: XSS on Apache HTTP Server 413 error pages via malformed HTTP method</ref>
            <ref source="CONFIRM" url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/1875/references">ADV-2008-1875</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/4301">ADV-2007-4301</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/4060" adv="1">ADV-2007-4060</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK57952">PK57952</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34219">34219</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33105">33105</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30732">30732</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28196">28196</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27906" adv="1">27906</ref>
            <ref source="MISC" url="http://procheckup.com/Vulnerability_PR07-37.php">http://procheckup.com/Vulnerability_PR07-37.php</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/1623/references">ADV-2008-1623</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg24019245">PK65782</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/3411">3411</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200803-19.xml">GLSA-200803-19</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30356">30356</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/29640">29640</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/29348">29348</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html">SUSE-SA:2008:021</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref>
            <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="2.0.46" />
                <vers num="2.0.47" />
                <vers num="2.0.48" />
                <vers num="2.0.49" />
                <vers num="2.0.50" />
                <vers num="2.0.51" />
                <vers num="2.0.52" />
                <vers num="2.0.53" />
                <vers num="2.0.54" />
                <vers num="2.0.55" />
                <vers num="2.0.57" />
                <vers num="2.0.58" />
                <vers num="2.0.59" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.7" />
                <vers num="2.1.8" />
                <vers num="2.2.0" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2008-0005" seq="2008-0005" severity="Medium" type="CVE" published="2008-01-11" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-31">
        <desc>
            <descript source="cve">mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html">FEDORA-2008-1695</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html">FEDORA-2008-1711</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39615">apache-modproxyftp-utf7-xss(39615)</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-575-1">USN-575-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1019185">1019185</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/27234">27234</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/505990/100/0/threaded">20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486167/100/0/threaded">20080110 SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0009.html">RHSA-2008:0009</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0008.html">RHSA-2008:0008</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0007.html">RHSA-2008:0007</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0006.html">RHSA-2008:0006</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0005.html">RHSA-2008:0005</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0004.html">RHSA-2008:0004</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:016">MDVSA-2008:016</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:015">MDVSA-2008:015</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:014">MDVSA-2008:014</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/1875/references">ADV-2008-1875</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm">http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/3526">3526</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/49">20080110 Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200803-19.xml">GLSA-200803-19</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30732">30732</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/29640">29640</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/29348">29348</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28977">28977</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28749">28749</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28607">28607</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28526">28526</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28471">28471</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28467">28467</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</ref>
            <ref source="MLIST" url="http://lists.vmware.com/pipermail/security-announce/2009/000062.html">[security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html">SUSE-SA:2008:021</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref>
            <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=307562">http://docs.info.apple.com/article.html?artnum=307562</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="1.3" />
                <vers num="2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2008-0599" seq="2008-0599" severity="High" type="CVE" published="2008-05-05" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-31">
        <desc>
            <descript source="cve">The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/147027">VU#147027</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00779.html">FEDORA-2008-3606</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00773.html">FEDORA-2008-3864</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-2503">https://issues.rpath.com/browse/RPL-2503</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42137">php-vector-unspecified(42137)</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-628-1">USN-628-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1019958">1019958</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/29009">29009</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/492535/100/0/threaded">20080523 rPSA-2008-0176-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0505.html">RHSA-2008:0505</ref>
            <ref source="CONFIRM" url="http://www.php.net/ChangeLog-5.php">http://www.php.net/ChangeLog-5.php</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/05/02/2">[oss-security] 20080502 CVE Request (PHP)</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:128">MDVSA-2008:128</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:127">MDVSA-2008:127</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/2268">ADV-2008-2268</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/1810/references">ADV-2008-1810</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/1412" adv="1">ADV-2008-1412</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0176">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0176</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31326">31326</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31200">31200</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30828">30828</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30757">30757</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30616">30616</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30345" adv="1">30345</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30083">30083</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30048" adv="1">30048</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5510">oval:org.mitre.oval:def:5510</ref>
            <ref source="SLACKWARE" url="http://marc.info/?l=slackware-security&amp;m=121022465827871&amp;w=2">SSA:2008-128-01</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html">APPLE-SA-2008-07-31</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01476437">SSRT080063</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01476437">SSRT080063</ref>
            <ref source="CONFIRM" url="http://cvs.php.net/viewvc.cgi/php-src/sapi/cgi/cgi_main.c?r1=1.267.2.15.2.50.2.12&amp;r2=1.267.2.15.2.50.2.13&amp;diff_format=u">http://cvs.php.net/viewvc.cgi/php-src/sapi/cgi/cgi_main.c?r1=1.267.2.15.2.50.2.12&amp;r2=1.267.2.15.2.50.2.13&amp;diff_format=u</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="beta4" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="rc3" num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.1.0" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1.3" />
                <vers num="5.1.4" />
                <vers num="5.1.5" />
                <vers num="5.1.6" />
                <vers num="5.2.0" />
                <vers num="5.2.1" />
                <vers num="5.2.2" />
                <vers num="5.2.3" />
                <vers num="5.2.4" />
                <vers num="5.2.5" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2008-2168" seq="2008-2168" severity="Medium" type="CVE" published="2008-05-13" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-31">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42303">apache-403-xss(42303)</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-731-1">USN-731-1</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/29112">29112</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/491967/100/0/threaded">20080512 Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/491930/100/0/threaded">20080510 Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/491901/100/0/threaded">20080510 Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/491862/100/0/threaded">20080508 Apache Server HTML Injection and UTF-7 XSS Vulnerability</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/3889">3889</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34219">34219</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31651">31651</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5143">oval:org.mitre.oval:def:5143</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">SSRT080118</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">SSRT080118</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="2.0" />
                <vers edition="beta" num="2.0.28" />
                <vers edition="beta" num="2.0.32" />
                <vers edition="beta" num="2.0.34" />
                <vers num="2.0.35" />
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.43" />
                <vers num="2.0.44" />
                <vers num="2.0.45" />
                <vers num="2.0.46" />
                <vers num="2.0.47" />
                <vers num="2.0.48" />
                <vers num="2.0.49" />
                <vers num="2.0.50" />
                <vers num="2.0.51" />
                <vers num="2.0.52" />
                <vers num="2.0.53" />
                <vers num="2.0.54" />
                <vers num="2.0.55" />
                <vers num="2.0.56" />
                <vers num="2.0.57" />
                <vers num="2.0.58" />
                <vers num="2.0.59" />
                <vers num="2.0.60" />
                <vers num="2.0.61" />
                <vers num="2.0.9" />
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.7" />
                <vers num="2.1.8" />
                <vers num="2.2" />
                <vers num="2.2.1" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2008-2364" seq="2008-2364" severity="Medium" type="CVE" published="2008-06-13" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/29653">29653</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2008/1798" adv="1">ADV-2008-1798</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00153.html">FEDORA-2008-6314</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00055.html">FEDORA-2008-6393</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42987">apache-modproxy-module-dos(42987)</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-731-1">USN-731-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1020267">1020267</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/31681">31681</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/498567/100/0/threaded">20081122 rPSA-2008-0328-1 httpd mod_ssl</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/494858/100/0/threaded">20080729 rPSA-2008-0236-1 httpd mod_ssl</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0966.html">RHSA-2008:0966</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:237">MDVSA-2008:237</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:195">MDVSA-2008:195</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2009/0320">ADV-2009-0320</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/2780">ADV-2008-2780</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK67579">PK67579</ref>
            <ref source="CONFIRM" url="http://www-01.ibm.com/support/docview.wss?uid=swg27008517">http://www-01.ibm.com/support/docview.wss?uid=swg27008517</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=666154&amp;r2=666153&amp;pathrev=666154">http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=666154&amp;r2=666153&amp;pathrev=666154</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3216">http://support.apple.com/kb/HT3216</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1">247666</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200807-06.xml">GLSA-200807-06</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34418">34418</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34259">34259</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34219">34219</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33797">33797</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33156">33156</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32838">32838</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32685">32685</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32222">32222</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31904">31904</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31651">31651</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31416">31416</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31404">31404</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31026">31026</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30621" adv="1">30621</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2008-0967.html">RHSA-2008:0967</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6084">oval:org.mitre.oval:def:6084</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=123376588623823&amp;w=2">SSRT090005</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=123376588623823&amp;w=2">SSRT090005</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html">SUSE-SR:2009:007</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html">SUSE-SR:2009:006</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html">APPLE-SA-2008-10-09</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">HPSBUX02365</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432">HPSBUX02365</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache_software_foundation" name="apache_http_server">
                <vers num="2.0.63" />
                <vers num="2.2.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2008-2666" seq="2008-2666" severity="Medium" type="CVE" published="2008-06-19" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a subdirectory named http: and then placing ../ (dot dot slash) sequences in an http URL argument to the (1) chdir or (2) ftok function.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43198">php-chdir-ftoc-security-bypass(43198)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1020328">1020328</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/29796">29796</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/3942">3942</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/55">20080617 PHP 5.2.6 chdir(),ftok() (standard ext) safe_mode bypass</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35074">35074</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers edition="rc1" num="5.0" />
                <vers edition="rc2" num="5.0" />
                <vers edition="rc3" num="5.0" />
                <vers num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.1.0" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1.3" />
                <vers num="5.1.4" />
                <vers num="5.1.5" />
                <vers num="5.1.6" />
                <vers num="5.2.0" />
                <vers num="5.2.1" />
                <vers num="5.2.2" />
                <vers num="5.2.3" />
                <vers num="5.2.4" />
                <vers num="5.2.5" />
                <vers num="5.2.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2008-2665" seq="2008-2665" severity="Medium" type="CVE" published="2008-06-19" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">Directory traversal vulnerability in the posix_access function in PHP 5.2.6 and earlier allows remote attackers to bypass safe_mode restrictions via a .. (dot dot) in an http URL, which results in the URL being canonicalized to a local filename after the safe_mode check has successfully run.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43196">php-posixaccess-security-bypass(43196)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1020327">1020327</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/29797">29797</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/3941">3941</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/54">20080617 PHP 5.2.6 posix_access() (posix ext) safe_mode bypass</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35074">35074</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="5.2.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2008-2829" seq="2008-2829" severity="Medium" type="CVE" published="2008-06-23" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/1297" adv="1">ADV-2009-1297</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/29829">29829</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html">FEDORA-2009-3848</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html">FEDORA-2009-3768</ref>
            <ref source="CONFIRM" url="https://bugs.gentoo.org/show_bug.cgi?id=221969">https://bugs.gentoo.org/show_bug.cgi?id=221969</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43357">php-phpimap-dos(43357)</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-628-1">USN-628-1</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/06/24/2">[oss-security] 20080624 Re: CVE request: php 5.2.6 ext/imap buffer overflows</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/06/19/6">[oss-security] 20080619 CVE request: php 5.2.6 ext/imap buffer overflows</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:128">MDVSA-2008:128</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:127">MDVSA-2008:127</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:126">MDVSA-2008:126</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650" adv="1">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35306" adv="1">35306</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35074" adv="1">35074</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31200" adv="1">31200</ref>
            <ref source="OSVDB" url="http://osvdb.org/46641">46641</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html">SUSE-SR:2008:027</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</ref>
            <ref source="MISC" url="http://bugs.php.net/bug.php?id=42862">http://bugs.php.net/bug.php?id=42862</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="4.0" prev="1" />
                <vers num="5.2.5" prev="1" />
                <vers num="5.2.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2008-2371" seq="2008-2371" severity="High" type="CVE" published="2008-07-07" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-31">
        <desc>
            <descript source="cve">Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00123.html">FEDORA-2008-6048</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00105.html">FEDORA-2008-6025</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2008/2336">ADV-2008-2336</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-628-1">USN-628-1</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-624-1">USN-624-1</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/31681">31681</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/30087">30087</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/497828/100/0/threaded">20081027 rPSA-2008-0305-1 pcre</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:023">MDVSA-2009:023</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:147">MDVSA-2008:147</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200807-03.xml">GLSA-200807-03</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/2780">ADV-2008-2780</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/2006" adv="1">ADV-2008-2006</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/2005" adv="1">ADV-2008-2005</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1602">DSA-1602</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0305">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0305</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3216">http://support.apple.com/kb/HT3216</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35074">35074</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32454">32454</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32222">32222</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31200">31200</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30990">30990</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30972">30972</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30967">30967</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30961" adv="1">30961</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30958" adv="1">30958</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30945">30945</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30944" adv="1">30944</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30916" adv="1">30916</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html">SUSE-SR:2008:014</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html">APPLE-SA-2008-10-09</ref>
            <ref source="CONFIRM" url="http://ftp.gnome.org/pub/GNOME/sources/glib/2.16/glib-2.16.4.changes">http://ftp.gnome.org/pub/GNOME/sources/glib/2.16/glib-2.16.4.changes</ref>
            <ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=228091">http://bugs.gentoo.org/show_bug.cgi?id=228091</ref>
        </refs>
        <vuln_soft>
            <prod vendor="pcre" name="pcre">
                <vers num="7.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2008-2939" seq="2008-2939" severity="Medium" type="CVE" published="2008-08-06" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-31">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/663763">VU#663763</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44223">apache-modproxyftp-xss(44223)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-731-1">USN-731-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1020635">1020635</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/30560">30560</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/498567/100/0/threaded">20081122 rPSA-2008-0328-1 httpd mod_ssl</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/498566/100/0/threaded">20081122 rPSA-2008-0327-1 httpd mod_ssl</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/495180/100/0/threaded">20080806 Apache HTTP Server mod_proxy_ftp Wildcard Characters Cross-Site Scripting</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0966.html">RHSA-2008:0966</ref>
            <ref source="MISC" url="http://www.rapid7.com/advisories/R7-0033">http://www.rapid7.com/advisories/R7-0033</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:124">MDVSA-2009:124</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:195">MDVSA-2008:195</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:194">MDVSA-2008:194</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2009/0320">ADV-2009-0320</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/2461">ADV-2008-2461</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/2315">ADV-2008-2315</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK70937">PK70937</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK70197">PK70197</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2008-0327">http://wiki.rpath.com/Advisories:rPSA-2008-0327</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc?view=rev&amp;revision=682871">http://svn.apache.org/viewvc?view=rev&amp;revision=682871</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc?view=rev&amp;revision=682870">http://svn.apache.org/viewvc?view=rev&amp;revision=682870</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc?view=rev&amp;revision=682868">http://svn.apache.org/viewvc?view=rev&amp;revision=682868</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1">247666</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35074">35074</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34219">34219</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33797">33797</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33156">33156</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32838">32838</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32685">32685</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31673">31673</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31384" adv="1">31384</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2008-0967.html">RHSA-2008:0967</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=123376588623823&amp;w=2">SSRT090005</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=123376588623823&amp;w=2">SSRT090005</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.html">SUSE-SR:2008:024</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="2.0" />
                <vers num="2.0.28" />
                <vers num="2.0.32" />
                <vers num="2.0.35" />
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.43" />
                <vers num="2.0.44" />
                <vers num="2.0.45" />
                <vers num="2.0.46" />
                <vers num="2.0.47" />
                <vers num="2.0.48" />
                <vers num="2.0.49" />
                <vers num="2.0.50" />
                <vers num="2.0.51" />
                <vers num="2.0.52" />
                <vers num="2.0.53" />
                <vers num="2.0.54" />
                <vers num="2.0.55" />
                <vers num="2.0.57" />
                <vers num="2.0.58" />
                <vers num="2.0.59" />
                <vers num="2.2" />
                <vers num="2.2.1" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
            </prod>
            <prod vendor="apache_software_foundation" name="apache">
                <vers edition="a1" num="2.0" />
                <vers edition="a2" num="2.0" />
                <vers edition="a3" num="2.0" />
                <vers edition="a4" num="2.0" />
                <vers edition="a5" num="2.0" />
                <vers edition="a6" num="2.0" />
                <vers edition="a7" num="2.0" />
                <vers edition="a8" num="2.0" />
                <vers edition="a9" num="2.0" />
                <vers num="2.0.11" />
                <vers num="2.0.12" />
                <vers num="2.0.13" />
                <vers num="2.0.14" />
                <vers num="2.0.15" />
                <vers num="2.0.16" />
                <vers num="2.0.17" />
                <vers num="2.0.18" />
                <vers num="2.0.19" />
                <vers num="2.0.20" />
                <vers num="2.0.21" />
                <vers num="2.0.22" />
                <vers num="2.0.23" />
                <vers num="2.0.24" />
                <vers num="2.0.25" />
                <vers num="2.0.26" />
                <vers num="2.0.27" />
                <vers num="2.0.29" />
                <vers num="2.0.30" />
                <vers num="2.0.31" />
                <vers num="2.0.33" />
                <vers num="2.0.34" />
                <vers num="2.0.61" />
                <vers num="2.0.63" prev="1" />
                <vers num="2.2.6" />
                <vers num="2.2.8" />
                <vers num="2.2.9" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2008-3660" seq="2008-3660" severity="Medium" type="CVE" published="2008-08-14" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.</descript>
            <descript source="nvd">Overview contains a typo, should read "PHP 5.2 through 5.2.6" not "5.6 through 5.2.6".</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html">FEDORA-2009-3848</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html">FEDORA-2009-3768</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44402">php-curl-unspecified(44402)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2008/2336">ADV-2008-2336</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1020994">1020994</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0350.html">RHSA-2009:0350</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/13/8">[oss-security] 20080813 Re: CVE request: php-5.2.6 overflow issues</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/08/2">[oss-security] 20080808 CVE request: php-5.2.6 overflow issues</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:024">MDVSA-2009:024</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:023">MDVSA-2009:023</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:022">MDVSA-2009:022</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:021">MDVSA-2009:021</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1647">DSA-1647</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35306">35306</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35074">35074</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32148">32148</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31982">31982</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html">SUSE-SR:2008:018</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</ref>
            <ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=234102">http://bugs.gentoo.org/show_bug.cgi?id=234102</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="4.4.0" />
                <vers num="4.4.1" />
                <vers num="4.4.2" />
                <vers num="4.4.3" />
                <vers num="4.4.4" />
                <vers num="4.4.5" />
                <vers num="4.4.6" />
                <vers num="4.4.7" />
                <vers num="4.4.8" />
                <vers num="5.2.0" />
                <vers num="5.2.1" />
                <vers num="5.2.2" />
                <vers num="5.2.3" />
                <vers num="5.2.4" />
                <vers num="5.2.5" />
                <vers num="5.2.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-2008-3659" seq="2008-3659" severity="Medium" type="CVE" published="2008-08-14" CVSS_version="2.0" CVSS_score="6.4" modified="2009-10-31">
        <desc>
            <descript source="cve">Buffer overflow in the memnstr function in PHP 4.4.x before 4.4.9 and PHP 5.6 through 5.2.6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via the delimiter argument to the explode function.  NOTE: the scope of this issue is limited since most applications would not use an attacker-controlled delimiter, but local attacks against safe_mode are feasible.</descript>
            <descript source="nvd">Overview contains a typo, should read "PHP 5.2 through 5.2.6" not "5.6 through 5.2.6".</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</ref>
            <ref source="CONFIRM" patch="1" url="http://www.php.net/archive/2008.php#id2008-08-07-1">http://www.php.net/archive/2008.php#id2008-08-07-1</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44405">php-memnstr-bo(44405)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2008/2336">ADV-2008-2336</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1020995">1020995</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/13/8">[oss-security] 20080813 Re: CVE request: php-5.2.6 overflow issues</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/08/4">[oss-security] 20080808 Re: CVE request: php-5.2.6 overflow issues</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/08/3">[oss-security] 20080808 Re: CVE request: php-5.2.6 overflow issues</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/08/2">[oss-security] 20080808 CVE request: php-5.2.6 overflow issues</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:024">MDVSA-2009:024</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:023">MDVSA-2009:023</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:022">MDVSA-2009:022</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:021">MDVSA-2009:021</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1647">DSA-1647</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35074">35074</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32316">32316</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32148">32148</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31982">31982</ref>
            <ref source="OSVDB" url="http://osvdb.org/47483">47483</ref>
            <ref source="CONFIRM" url="http://news.php.net/php.cvs/52002">http://news.php.net/php.cvs/52002</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.html">SUSE-SR:2008:021</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html">SUSE-SR:2008:018</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</ref>
            <ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=234102">http://bugs.gentoo.org/show_bug.cgi?id=234102</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="4.4.0" />
                <vers num="4.4.1" />
                <vers num="4.4.2" />
                <vers num="4.4.3" />
                <vers num="4.4.4" />
                <vers num="4.4.5" />
                <vers num="4.4.6" />
                <vers num="4.4.7" />
                <vers num="4.4.8" />
                <vers num="5.2.0" />
                <vers num="5.2.1" />
                <vers num="5.2.2" />
                <vers num="5.2.3" />
                <vers num="5.2.4" />
                <vers num="5.2.5" />
                <vers num="5.2.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2008-3658" seq="2008-3658" severity="High" type="CVE" published="2008-08-14" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-31">
        <desc>
            <descript source="cve">Buffer overflow in the imageloadfont function in ext/gd/gd.c in PHP 4.4.x before 4.4.9 and PHP 5.2 before 5.2.6-r6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.</descript>
            <descript source="nvd">Mitre Description references "PHP 5.6 through 5.2.6" -- however research to the changelog for PHP 5 does not reflect a 5.6 release  

changelog: http://www.php.net/ChangeLog-5.php


However, http://www.openwall.com/lists/oss-security/2008/08/08/2:
"Those issues are fixed by the recent php-4.4.9 release, but they affect 
php-5.2.6 as well and the fixes are not part of any released version in 
case of 5.2."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html">FEDORA-2009-3848</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html">FEDORA-2009-3768</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44401">php-imageloadfont-dos(44401)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2008/2336">ADV-2008-2336</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/30649">30649</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/498647/100/0/threaded">HPSBTU02382</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/498647/100/0/threaded">HPSBTU02382</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0350.html">RHSA-2009:0350</ref>
            <ref source="CONFIRM" url="http://www.php.net/archive/2008.php#id2008-08-07-1">http://www.php.net/archive/2008.php#id2008-08-07-1</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/13/8">[oss-security] 20080813 Re: CVE request: php-5.2.6 overflow issues</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/08/08/2">[oss-security] 20080808 CVE request: php-5.2.6 overflow issues</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:024">MDVSA-2009:024</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:023">MDVSA-2009:023</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:022">MDVSA-2009:022</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:021">MDVSA-2009:021</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2009/0320">ADV-2009-0320</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/3275">ADV-2008-3275</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1647">DSA-1647</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35306">35306</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35074">35074</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33797">33797</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32884">32884</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32316">32316</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32148">32148</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31982">31982</ref>
            <ref source="OSVDB" url="http://osvdb.org/47484">47484</ref>
            <ref source="MISC" url="http://news.php.net/php.cvs/51219">http://news.php.net/php.cvs/51219</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=123376588623823&amp;w=2">HPSBUX02401</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=123376588623823&amp;w=2">HPSBUX02401</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00006.html">SUSE-SR:2008:021</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.html">SUSE-SR:2008:018</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</ref>
            <ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=234102">http://bugs.gentoo.org/show_bug.cgi?id=234102</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="4.4.0" />
                <vers num="4.4.1" />
                <vers num="4.4.2" />
                <vers num="4.4.3" />
                <vers num="4.4.4" />
                <vers num="4.4.5" />
                <vers num="4.4.6" />
                <vers num="4.4.7" />
                <vers num="4.4.8" />
                <vers num="5.2.0" />
                <vers num="5.2.1" />
                <vers num="5.2.2" />
                <vers num="5.2.3" />
                <vers num="5.2.4" />
                <vers num="5.2.5" />
                <vers num="5.2.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" name="CVE-2008-5029" seq="2008-5029" severity="Medium" type="CVE" published="2008-11-10" CVSS_version="2.0" CVSS_score="4.9" modified="2009-11-06">
        <desc>
            <descript source="cve">The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/32154">32154</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1550.html">RHSA-2009:1550</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=470201">https://bugzilla.redhat.com/show_bug.cgi?id=470201</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-679-1">USN-679-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1021511">1021511</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1021292">1021292</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/33079">33079</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/499700/100/0/threaded">20090101 Linux Kernel 2.6.18/2.6.24/2.6.20/2.6.22/2.6.21 denial of service exploit</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0225.html">RHSA-2009:0225</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0014.html">RHSA-2009:0014</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0009.html">RHSA-2009:0009</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/11/06/1">[oss-security] 20081106 CVE request: kernel: Unix sockets kernel panic</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:234">MDVSA-2008:234</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1687">DSA-1687</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1681">DSA-1681</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/4573">4573</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33704">33704</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33641">33641</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33623">33623</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33586">33586</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33556">33556</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33180">33180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32998">32998</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32918">32918</ref>
            <ref source="MLIST" url="http://marc.info/?l=linux-netdev&amp;m=122593044330973&amp;w=2">[linux-netdev] 20081106 UNIX sockets kernel panic</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00010.html">SUSE-SA:2009:008</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00006.html">SUSE-SA:2009:004</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html">SUSE-SA:2008:057</ref>
            <ref source="MISC" url="http://darkircop.org/unix.c">http://darkircop.org/unix.c</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.6" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.22_rc1" />
                <vers num="2.6.22_rc7" />
                <vers num="2.6.23" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers num="2.6.23_rc1" />
                <vers num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers num="2.6.24_rc1" />
                <vers num="2.6.24_rc4" />
                <vers num="2.6.24_rc5" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers edition="rc4" num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.4" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" name="CVE-2008-5300" seq="2008-5300" severity="Medium" type="CVE" published="2008-12-01" CVSS_version="2.0" CVSS_score="4.9" modified="2009-11-06">
        <desc>
            <descript source="cve">Linux kernel 2.6.28 allows local users to cause a denial of service ("soft lockup" and process loss) via a large number of sendmsg function calls, which does not block during AF_UNIX garbage collection and triggers an OOM condition, a different vulnerability than CVE-2008-5029.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01358.html">FEDORA-2008-11618</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1550.html">RHSA-2009:1550</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-2915">https://issues.rpath.com/browse/RPL-2915</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=470201" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=470201</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/46943">linux-kernel-sendmsg-dos(46943)</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-714-1">USN-714-1</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-715-1">USN-715-1</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/32516">32516</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/499044/100/0/threaded">20081209 rPSA-2008-0332-1 kernel</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0053.html">RHSA-2009:0053</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0014.html">RHSA-2009:0014</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:032">MDVSA-2009:032</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1681">DSA-1681</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0332">http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0332</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/4673">4673</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33854">33854</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33756">33756</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33706">33706</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33556">33556</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33348">33348</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33083">33083</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32998">32998</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32913">32913</ref>
            <ref source="OSVDB" url="http://osvdb.org/50272">50272</ref>
            <ref source="MLIST" url="http://marc.info/?l=linux-netdev&amp;m=122765505415944&amp;w=2">[linux-netdev] 20081125 [PATCH] Fix soft lockups/OOM issues w/ unix garbage collector</ref>
            <ref source="MLIST" url="http://marc.info/?l=linux-netdev&amp;m=122721862313564&amp;w=2">[linux-netdev] 20081120 soft lockups/OOM after unix socket fixes</ref>
            <ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=473259">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=473259</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers edition="rc1" num="2.6.28" />
                <vers edition="rc2" num="2.6.28" />
                <vers edition="rc3" num="2.6.28" />
                <vers edition="rc4" num="2.6.28" />
                <vers edition="rc5" num="2.6.28" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" name="CVE-2008-5349" seq="2008-5349" severity="High" type="CVE" published="2008-12-05" CVSS_version="2.0" CVSS_score="7.1" modified="2009-10-27">
        <desc>
            <descript source="cve">Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows remote attackers to cause a denial of service (CPU consumption) via a crafted RSA public key.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-340A.html">TA08-340A</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-246286-1" adv="1">246286</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-0466.html">RHSA-2009:0466</ref>
            <ref source="CONFIRM" url="http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdf">http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdf</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1426">ADV-2009-1426</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1021309">1021309</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/32608">32608</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/504010/100/0/threaded">HPSBUX02429</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0016.html">RHSA-2009:0016</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/3339">ADV-2008-3339</ref>
            <ref source="CONFIRM" url="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=829914&amp;poid=">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=829914&amp;poid=</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2009-012.htm">http://support.avaya.com/elmodocs2/security/ASA-2009-012.htm</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35255">35255</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34972">34972</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34259">34259</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33709">33709</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33015">33015</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32991">32991</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2008-1025.html">RHSA-2008:1025</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2008-1018.html">RHSA-2008:1018</ref>
            <ref source="OSVDB" url="http://osvdb.org/50504">50504</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html">SUSE-SR:2009:006</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133">HPSBMA02429</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133">HPSBMA02429</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="5.0" prev="1" />
                <vers edition="update_10" num="5.0" prev="1" />
                <vers edition="update_11" num="5.0" prev="1" />
                <vers edition="update_12" num="5.0" prev="1" />
                <vers edition="update_13" num="5.0" prev="1" />
                <vers edition="update_14" num="5.0" prev="1" />
                <vers edition="update_15" num="5.0" prev="1" />
                <vers edition="update_16" num="5.0" prev="1" />
                <vers edition="update_2" num="5.0" prev="1" />
                <vers edition="update_3" num="5.0" prev="1" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update_1" num="5.0" prev="1" />
                <vers edition="update_10" num="5.0" prev="1" />
                <vers edition="update_11" num="5.0" prev="1" />
                <vers edition="update_12" num="5.0" prev="1" />
                <vers edition="update_13" num="5.0" prev="1" />
                <vers edition="update_14" num="5.0" prev="1" />
                <vers edition="update_15" num="5.0" prev="1" />
                <vers edition="update_16" num="5.0" prev="1" />
                <vers edition="update_2" num="5.0" prev="1" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2008-5624" seq="2008-5624" severity="High" type="CVE" published="2008-12-17" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-31">
        <desc>
            <descript source="cve">PHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function, which allows context-dependent attackers to bypass safe_mode restrictions via variable settings that are intended to be restricted to root, as demonstrated by a setting of /etc for the error_log variable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/47318">php-getuid-safemode-bypass(47318)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/32688">32688</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/498985/100/0/threaded">20081206 SecurityReason: PHP 5.2.6 SAPI php_getuid() overload</ref>
            <ref source="CONFIRM" url="http://www.php.net/ChangeLog-5.php#5.2.7">http://www.php.net/ChangeLog-5.php#5.2.7</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:045">MDVSA-2009:045</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1789">DSA-1789</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/59">20081205 PHP 5.2.6 SAPI php_getuid() overload</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35003">35003</ref>
            <ref source="OSVDB" url="http://osvdb.org/52207">52207</ref>
            <ref source="OSVDB" url="http://osvdb.org/50483">50483</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">HPSBUX02431</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="beta4" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="rc3" num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.1.0" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1.3" />
                <vers num="5.1.4" />
                <vers num="5.1.5" />
                <vers num="5.1.6" />
                <vers num="5.2.0" />
                <vers num="5.2.1" />
                <vers num="5.2.2" />
                <vers num="5.2.3" />
                <vers num="5.2.4" />
                <vers num="5.2.5" />
                <vers num="5.2.6" />
                <vers num="5.2.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2008-5625" seq="2008-5625" severity="High" type="CVE" published="2008-12-17" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-31">
        <desc>
            <descript source="cve">PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows context-dependent attackers to write to arbitrary files by placing a "php_value error_log" entry in a .htaccess file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/47314">php-error-safemode-bypass(47314)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/32383">32383</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</ref>
            <ref source="CONFIRM" url="http://www.php.net/ChangeLog-5.php#5.2.7">http://www.php.net/ChangeLog-5.php#5.2.7</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/7171">7171</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:045">MDVSA-2009:045</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/57">20081120 PHP 5.2.6 (error_log) safe_mode bypass</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="OSVDB" url="http://osvdb.org/52205">52205</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2008-11/0152.html">20081120 SecurityReason : PHP 5.2.6 (error_log) safe_mode bypass</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="beta4" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="rc3" num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.1.0" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1.3" />
                <vers num="5.1.4" />
                <vers num="5.1.5" />
                <vers num="5.1.6" />
                <vers num="5.2.0" />
                <vers num="5.2.1" />
                <vers num="5.2.2" />
                <vers num="5.2.3" />
                <vers num="5.2.4" />
                <vers num="5.2.5" />
                <vers num="5.2.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2008-5658" seq="2008-5658" severity="High" type="CVE" published="2008-12-17" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-31">
        <desc>
            <descript source="cve">Directory traversal vulnerability in the ZipArchive::extractTo function in PHP 5.2.6 and earlier allows context-dependent attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html">FEDORA-2009-3848</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html">FEDORA-2009-3768</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/47079">php-ziparchive-directory-traversal(47079)</ref>
            <ref source="MISC" url="http://www.sektioneins.de/advisories/SE-2008-06.txt">http://www.sektioneins.de/advisories/SE-2008-06.txt</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1021303">1021303</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/32625">32625</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0350.html">RHSA-2009:0350</ref>
            <ref source="CONFIRM" url="http://www.php.net/ChangeLog-5.php#5.2.7">http://www.php.net/ChangeLog-5.php#5.2.7</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/12/04/3">[oss-security] 20081204 CVE for SE-2008-06 in PHP 5.2.7 (ZipArchive)</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:045">MDVSA-2009:045</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1789">DSA-1789</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35306">35306</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35003">35003</ref>
            <ref source="OSVDB" url="http://osvdb.org/50480">50480</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html">SUSE-SR:2009:004</ref>
            <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2008-12/0039.html">20081204 Advisory 06/2008: PHP ZipArchive::extractTo() Directory Traversal Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="beta4" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="rc3" num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.1.0" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1.3" />
                <vers num="5.1.4" />
                <vers num="5.1.5" />
                <vers num="5.1.6" />
                <vers num="5.2.0" />
                <vers num="5.2.1" />
                <vers num="5.2.2" />
                <vers num="5.2.3" />
                <vers num="5.2.4" />
                <vers num="5.2.5" />
                <vers num="5.2.6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2008-5557" seq="2008-5557" severity="High" type="CVE" published="2008-12-23" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-31">
        <desc>
            <descript source="cve">Heap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilter_htmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an HTML entity, which is not properly handled during Unicode conversion, related to the (1) mb_convert_encoding, (2) mb_check_encoding, (3) mb_convert_variables, and (4) mb_parse_str functions.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html">FEDORA-2009-3848</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html">FEDORA-2009-3768</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/47525">php-multibyte-bo(47525)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/32948">32948</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/501376/100/0/threaded">20090302 rPSA-2009-0035-1 php php-cgi php-imap php-mcrypt php-mysql php-mysqli php-pgsql php-soap php-xsl php5 php5-cgi php5-imap php5-mcrypt php5-mysql php5-mysqli php5-pear php5-pgsql php5-soap php5-xsl</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0350.html">RHSA-2009:0350</ref>
            <ref source="CONFIRM" url="http://www.php.net/ChangeLog-5.php#5.2.7">http://www.php.net/ChangeLog-5.php#5.2.7</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:045">MDVSA-2009:045</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1789">DSA-1789</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0035">http://wiki.rpath.com/Advisories:rPSA-2009-0035</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1021482">1021482</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35306">35306</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35074">35074</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35003">35003</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34642">34642</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">HPSBUX02465</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html">SUSE-SR:2009:008</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html">SUSE-SR:2009:004</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</ref>
            <ref source="CONFIRM" url="http://cvs.php.net/viewvc.cgi/php-src/ext/mbstring/libmbfl/filters/mbfilter_htmlent.c?r1=1.7&amp;r2=1.8">http://cvs.php.net/viewvc.cgi/php-src/ext/mbstring/libmbfl/filters/mbfilter_htmlent.c?r1=1.7&amp;r2=1.8</ref>
            <ref source="CONFIRM" url="http://bugs.php.net/bug.php?id=45722">http://bugs.php.net/bug.php?id=45722</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2008-12/0477.html">20081221 CVE-2008-5557 - PHP mbstring buffer overflow</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="4.3.0" />
                <vers num="4.3.1" />
                <vers num="4.3.10" />
                <vers num="4.3.11" />
                <vers num="4.3.2" />
                <vers num="4.3.3" />
                <vers num="4.3.4" />
                <vers num="4.3.5" />
                <vers num="4.3.6" />
                <vers num="4.3.7" />
                <vers num="4.3.8" />
                <vers num="4.3.9" />
                <vers num="4.4.0" />
                <vers num="4.4.1" />
                <vers num="4.4.2" />
                <vers num="4.4.3" />
                <vers num="4.4.4" />
                <vers num="4.4.5" />
                <vers num="4.4.6" />
                <vers num="4.4.7" />
                <vers num="4.4.8" />
                <vers num="4.4.9" />
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="beta4" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="rc3" num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.1.0" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1.3" />
                <vers num="5.1.4" />
                <vers num="5.1.5" />
                <vers num="5.1.6" />
                <vers num="5.2.0" />
                <vers num="5.2.1" />
                <vers num="5.2.2" />
                <vers num="5.2.3" />
                <vers num="5.2.4" />
                <vers num="5.2.5" />
                <vers num="5.2.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2008-5498" seq="2008-5498" severity="Medium" type="CVE" published="2008-12-26" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html">FEDORA-2009-3848</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html">FEDORA-2009-3768</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/47635">php-imagerotate-info-disclosure(47635)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/33002">33002</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0350.html">RHSA-2009:0350</ref>
            <ref source="CONFIRM" url="http://www.php.net/releases/5_2_9.php">http://www.php.net/releases/5_2_9.php</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:023">MDVSA-2009:023</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:022">MDVSA-2009:022</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:021">MDVSA-2009:021</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3865">http://support.apple.com/kb/HT3865</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1021494">1021494</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36701">36701</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35650">35650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35306">35306</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34642">34642</ref>
            <ref source="OSVDB" url="http://osvdb.org/51031">51031</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=125631037611762&amp;w=2">SSRT090192</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=124654546101607&amp;w=2">SSRT090085</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html">SUSE-SR:2009:008</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html">APPLE-SA-2009-09-10-2</ref>
            <ref source="MISC" url="http://downloads.securityfocus.com/vulnerabilities/exploits/33002.php">http://downloads.securityfocus.com/vulnerabilities/exploits/33002.php</ref>
            <ref source="MISC" url="http://downloads.securityfocus.com/vulnerabilities/exploits/33002-2.php">http://downloads.securityfocus.com/vulnerabilities/exploits/33002-2.php</ref>
            <ref source="CONFIRM" url="http://cvs.php.net/viewvc.cgi/php-src/NEWS?r1=1.2027.2.547.2.1360&amp;r2=1.2027.2.547.2.1361&amp;diff_format=u">http://cvs.php.net/viewvc.cgi/php-src/NEWS?r1=1.2027.2.547.2.1360&amp;r2=1.2027.2.547.2.1361&amp;diff_format=u</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="5" />
                <vers edition="rc1" num="5.0" />
                <vers edition="rc2" num="5.0" />
                <vers edition="rc3" num="5.0" />
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="beta4" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="rc3" num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.1" />
                <vers num="5.1.0" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1.3" />
                <vers num="5.1.4" />
                <vers num="5.1.5" />
                <vers num="5.1.6" />
                <vers num="5.2.0" />
                <vers num="5.2.1" />
                <vers num="5.2.2" />
                <vers num="5.2.3" />
                <vers num="5.2.4" />
                <vers num="5.2.5" />
                <vers num="5.2.6" />
                <vers num="5.2.7" />
                <vers num="5.2.8" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-0755" seq="2009-0755" severity="Medium" type="CVE" published="2009-03-03" CVSS_version="2.0" CVSS_score="5.0" modified="2009-11-04">
        <desc>
            <descript source="cve">The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-850-1">USN-850-1</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/33749">33749</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/502761/100/0/threaded">20090417 rPSA-2009-0059-1 poppler</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/02/19/2">[oss-security] 20090219 Re: CVE Request: Poppler -Two Denial of Service Vulnerabilities</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/02/13/1">[oss-security] 20090213 CVE Request: Poppler -Two Denial of Service Vulnerabilities</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0059">http://wiki.rpath.com/Advisories:rPSA-2009-0059</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37114">37114</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35685">35685</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33853" adv="1">33853</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html">SUSE-SR:2009:012</ref>
            <ref source="MLIST" url="http://lists.freedesktop.org/archives/poppler/2009-January/004406.html">[poppler] 20090128 poppler/Form.cc</ref>
            <ref source="CONFIRM" url="http://bugs.freedesktop.org/show_bug.cgi?id=19790">http://bugs.freedesktop.org/show_bug.cgi?id=19790</ref>
        </refs>
        <vuln_soft>
            <prod vendor="poppler" name="poppler">
                <vers num="0.1" />
                <vers num="0.1.1" />
                <vers num="0.1.2" />
                <vers num="0.10.1" />
                <vers num="0.10.2" />
                <vers num="0.10.3" prev="1" />
                <vers num="0.2.0" />
                <vers num="0.3.0" />
                <vers num="0.3.1" />
                <vers num="0.3.2" />
                <vers num="0.3.3" />
                <vers num="0.4.0" />
                <vers num="0.4.1" />
                <vers num="0.4.2" />
                <vers num="0.4.3" />
                <vers num="0.4.4" />
                <vers num="0.5.0" />
                <vers num="0.5.1" />
                <vers num="0.5.2" />
                <vers num="0.5.3" />
                <vers num="0.5.4" />
                <vers num="0.5.9" />
                <vers num="0.5.90" />
                <vers num="0.5.91" />
                <vers num="0.6.0" />
                <vers num="0.6.1" />
                <vers num="0.6.2" />
                <vers num="0.6.3" />
                <vers num="0.6.4" />
                <vers num="0.7.0" />
                <vers num="0.7.1" />
                <vers num="0.7.2" />
                <vers num="0.7.3" />
                <vers num="0.8.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-0839" seq="2009-0839" severity="High" type="CVE" published="2009-03-31" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-27">
        <desc>
            <descript source="cve">Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter in a query action.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html">FEDORA-2009-3383</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html">FEDORA-2009-3357</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1021952">1021952</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/34306">34306</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/502271/100/0/threaded">20090330 Positron Security Advisory #2009-000: Multiple Vulnerabilities in MapServer v5.2.1 and v4.10.3</ref>
            <ref source="MISC" url="http://www.positronsecurity.com/advisories/2009-000.html">http://www.positronsecurity.com/advisories/2009-000.html</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1914">DSA-1914</ref>
            <ref source="CONFIRM" url="http://trac.osgeo.org/mapserver/ticket/2944" adv="1">http://trac.osgeo.org/mapserver/ticket/2944</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34603">34603</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34520">34520</ref>
            <ref source="MLIST" url="http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html">[mapserver-users] 20090326 MapServer 5.2.2 and 4.10.4 released with security fixes</ref>
        </refs>
        <vuln_soft>
            <prod vendor="umn" name="mapserver">
                <vers edition="beta1" num="4.0" />
                <vers edition="beta2" num="4.0" />
                <vers edition="beta1" num="4.10" />
                <vers edition="beta2" num="4.10" />
                <vers edition="beta3" num="4.10" />
                <vers edition="rc1" num="4.10" />
                <vers num="4.10.0" />
                <vers num="4.10.1" />
                <vers num="4.10.2" />
                <vers num="4.10.3" />
                <vers edition="beta1" num="4.2" />
                <vers edition="beta1" num="4.4.0" />
                <vers edition="beta2" num="4.4.0" />
                <vers edition="beta3" num="4.4.0" />
                <vers edition="beta1" num="4.6.0" />
                <vers edition="beta2" num="4.6.0" />
                <vers edition="beta3" num="4.6.0" />
                <vers edition="rc1" num="4.6.0" />
                <vers edition="beta1" num="4.8" />
                <vers edition="beta2" num="4.8" />
                <vers edition="beta3" num="4.8" />
                <vers edition="rc1" num="4.8" />
                <vers edition="rc2" num="4.8" />
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="beta4" num="5.0.0" />
                <vers edition="beta5" num="5.0.0" />
                <vers edition="beta6" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="beta1" num="5.2.0" />
                <vers edition="beta2" num="5.2.0" />
                <vers edition="beta3" num="5.2.0" />
                <vers edition="beta4" num="5.2.0" />
                <vers edition="rc1" num="5.2.0" />
                <vers num="5.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-0840" seq="2009-0840" severity="High" type="CVE" published="2009-03-31" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-27">
        <desc>
            <descript source="cve">Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to have an unknown impact via a negative value in the Content-Length HTTP header.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MLIST" patch="1" url="http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html">[mapserver-users] 20090326 MapServer 5.2.2 and 4.10.4 released with security fixes</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html">FEDORA-2009-3383</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html">FEDORA-2009-3357</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/49545">mapserver-contentlength-bo(49545)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1021952">1021952</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/34306">34306</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/502271/100/0/threaded">20090330 Positron Security Advisory #2009-000: Multiple Vulnerabilities in MapServer v5.2.1 and v4.10.3</ref>
            <ref source="MISC" url="http://www.positronsecurity.com/advisories/2009-000.html">http://www.positronsecurity.com/advisories/2009-000.html</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1914">DSA-1914</ref>
            <ref source="CONFIRM" url="http://trac.osgeo.org/mapserver/ticket/2943" adv="1">http://trac.osgeo.org/mapserver/ticket/2943</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34603">34603</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34520">34520</ref>
        </refs>
        <vuln_soft>
            <prod vendor="umn" name="mapserver">
                <vers edition="beta1" num="4.0" />
                <vers edition="beta2" num="4.0" />
                <vers edition="beta1" num="4.10" />
                <vers edition="beta2" num="4.10" />
                <vers edition="beta3" num="4.10" />
                <vers edition="rc1" num="4.10" />
                <vers num="4.10.0" />
                <vers num="4.10.1" />
                <vers num="4.10.2" />
                <vers num="4.10.3" />
                <vers edition="beta1" num="4.2" />
                <vers edition="beta1" num="4.4.0" />
                <vers edition="beta2" num="4.4.0" />
                <vers edition="beta3" num="4.4.0" />
                <vers edition="beta1" num="4.6.0" />
                <vers edition="beta2" num="4.6.0" />
                <vers edition="beta3" num="4.6.0" />
                <vers edition="rc1" num="4.6.0" />
                <vers edition="beta1" num="4.8" />
                <vers edition="beta2" num="4.8" />
                <vers edition="beta3" num="4.8" />
                <vers edition="rc1" num="4.8" />
                <vers edition="rc2" num="4.8" />
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="beta4" num="5.0.0" />
                <vers edition="beta5" num="5.0.0" />
                <vers edition="beta6" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="beta1" num="5.2.0" />
                <vers edition="beta2" num="5.2.0" />
                <vers edition="beta3" num="5.2.0" />
                <vers edition="beta4" num="5.2.0" />
                <vers edition="rc1" num="5.2.0" />
                <vers num="5.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-0841" seq="2009-0841" severity="High" type="CVE" published="2009-03-31" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-27">
        <desc>
            <descript source="cve">Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MLIST" patch="1" url="http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html">[mapserver-users] 20090326 MapServer 5.2.2 and 4.10.4 released with security fixes</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html">FEDORA-2009-3383</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html">FEDORA-2009-3357</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/49548">mapserver-mapserv-dir-traversal(49548)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1021952">1021952</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/34306">34306</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/502271/100/0/threaded">20090330 Positron Security Advisory #2009-000: Multiple Vulnerabilities in MapServer v5.2.1 and v4.10.3</ref>
            <ref source="MISC" url="http://www.positronsecurity.com/advisories/2009-000.html">http://www.positronsecurity.com/advisories/2009-000.html</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1914">DSA-1914</ref>
            <ref source="CONFIRM" url="http://trac.osgeo.org/mapserver/ticket/2942" adv="1">http://trac.osgeo.org/mapserver/ticket/2942</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34603">34603</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34520">34520</ref>
        </refs>
        <vuln_soft>
            <prod vendor="umn" name="mapserver">
                <vers edition="beta1" num="4.0" />
                <vers edition="beta2" num="4.0" />
                <vers edition="beta1" num="4.10" />
                <vers edition="beta2" num="4.10" />
                <vers edition="beta3" num="4.10" />
                <vers edition="rc1" num="4.10" />
                <vers num="4.10.0" />
                <vers num="4.10.1" />
                <vers num="4.10.2" />
                <vers num="4.10.3" />
                <vers edition="beta1" num="4.2" />
                <vers edition="beta1" num="4.4.0" />
                <vers edition="beta2" num="4.4.0" />
                <vers edition="beta3" num="4.4.0" />
                <vers edition="beta1" num="4.6.0" />
                <vers edition="beta2" num="4.6.0" />
                <vers edition="beta3" num="4.6.0" />
                <vers edition="rc1" num="4.6.0" />
                <vers edition="beta1" num="4.8" />
                <vers edition="beta2" num="4.8" />
                <vers edition="beta3" num="4.8" />
                <vers edition="rc1" num="4.8" />
                <vers edition="rc2" num="4.8" />
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="beta4" num="5.0.0" />
                <vers edition="beta5" num="5.0.0" />
                <vers edition="beta6" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="beta1" num="5.2.0" />
                <vers edition="beta2" num="5.2.0" />
                <vers edition="beta3" num="5.2.0" />
                <vers edition="beta4" num="5.2.0" />
                <vers edition="rc1" num="5.2.0" />
                <vers num="5.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-0842" seq="2009-0842" severity="Medium" type="CVE" published="2009-03-31" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-27">
        <desc>
            <descript source="cve">mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MLIST" patch="1" url="http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html" adv="1">[mapserver-users] 20090326 MapServer 5.2.2 and 4.10.4 released with security fixes</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html">FEDORA-2009-3383</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html">FEDORA-2009-3357</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1021952">1021952</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/34306">34306</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/502271/100/0/threaded">20090330 Positron Security Advisory #2009-000: Multiple Vulnerabilities in MapServer v5.2.1 and v4.10.3</ref>
            <ref source="MISC" url="http://www.positronsecurity.com/advisories/2009-000.html">http://www.positronsecurity.com/advisories/2009-000.html</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1914">DSA-1914</ref>
            <ref source="CONFIRM" url="http://trac.osgeo.org/mapserver/ticket/2941">http://trac.osgeo.org/mapserver/ticket/2941</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34603">34603</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34520">34520</ref>
        </refs>
        <vuln_soft>
            <prod vendor="umn" name="mapserver">
                <vers edition="beta1" num="4.0" />
                <vers edition="beta2" num="4.0" />
                <vers edition="beta1" num="4.10" />
                <vers edition="beta2" num="4.10" />
                <vers edition="beta3" num="4.10" />
                <vers edition="rc1" num="4.10" />
                <vers num="4.10.0" />
                <vers num="4.10.1" />
                <vers num="4.10.2" />
                <vers num="4.10.3" />
                <vers edition="beta1" num="4.2" />
                <vers edition="beta1" num="4.4.0" />
                <vers edition="beta2" num="4.4.0" />
                <vers edition="beta3" num="4.4.0" />
                <vers edition="beta1" num="4.6.0" />
                <vers edition="beta2" num="4.6.0" />
                <vers edition="beta3" num="4.6.0" />
                <vers edition="rc1" num="4.6.0" />
                <vers edition="beta1" num="4.8" />
                <vers edition="beta2" num="4.8" />
                <vers edition="beta3" num="4.8" />
                <vers edition="rc1" num="4.8" />
                <vers edition="rc2" num="4.8" />
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="beta4" num="5.0.0" />
                <vers edition="beta5" num="5.0.0" />
                <vers edition="beta6" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="beta1" num="5.2.0" />
                <vers edition="beta2" num="5.2.0" />
                <vers edition="beta3" num="5.2.0" />
                <vers edition="beta4" num="5.2.0" />
                <vers edition="rc1" num="5.2.0" />
                <vers num="5.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" name="CVE-2009-0843" seq="2009-0843" severity="High" type="CVE" published="2009-03-31" CVSS_version="2.0" CVSS_score="7.8" modified="2009-10-27">
        <desc>
            <descript source="cve">The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depending on whether this pathname exists.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MLIST" patch="1" url="http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html">[mapserver-users] 20090326 MapServer 5.2.2 and 4.10.4 released with security fixes</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html">FEDORA-2009-3383</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html">FEDORA-2009-3357</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1021952">1021952</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/34306">34306</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/502271/100/0/threaded">20090330 Positron Security Advisory #2009-000: Multiple Vulnerabilities in MapServer v5.2.1 and v4.10.3</ref>
            <ref source="MISC" url="http://www.positronsecurity.com/advisories/2009-000.html">http://www.positronsecurity.com/advisories/2009-000.html</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1914">DSA-1914</ref>
            <ref source="CONFIRM" url="http://trac.osgeo.org/mapserver/ticket/2939">http://trac.osgeo.org/mapserver/ticket/2939</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34603">34603</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34520">34520</ref>
        </refs>
        <vuln_soft>
            <prod vendor="umn" name="mapserver">
                <vers edition="beta1" num="4.0" />
                <vers edition="beta2" num="4.0" />
                <vers edition="beta1" num="4.10" />
                <vers edition="beta2" num="4.10" />
                <vers edition="beta3" num="4.10" />
                <vers edition="rc1" num="4.10" />
                <vers num="4.10.0" />
                <vers num="4.10.1" />
                <vers num="4.10.2" />
                <vers num="4.10.3" />
                <vers edition="beta1" num="4.2" />
                <vers edition="beta1" num="4.4.0" />
                <vers edition="beta2" num="4.4.0" />
                <vers edition="beta3" num="4.4.0" />
                <vers edition="beta1" num="4.6.0" />
                <vers edition="beta2" num="4.6.0" />
                <vers edition="beta3" num="4.6.0" />
                <vers edition="rc1" num="4.6.0" />
                <vers edition="beta1" num="4.8" />
                <vers edition="beta2" num="4.8" />
                <vers edition="beta3" num="4.8" />
                <vers edition="rc1" num="4.8" />
                <vers edition="rc2" num="4.8" />
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="beta4" num="5.0.0" />
                <vers edition="beta5" num="5.0.0" />
                <vers edition="beta6" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="beta1" num="5.2.0" />
                <vers edition="beta2" num="5.2.0" />
                <vers edition="beta3" num="5.2.0" />
                <vers edition="beta4" num="5.2.0" />
                <vers edition="rc1" num="5.2.0" />
                <vers num="5.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-0946" seq="2009-0946" severity="High" type="CVE" published="2009-04-16" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-31">
        <desc>
            <descript source="cve">Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html">TA09-133A</ref>
            <ref source="CONFIRM" patch="1" url="http://git.savannah.gnu.org/cgit/freetype/freetype2.git/tree/ChangeLog">http://git.savannah.gnu.org/cgit/freetype/freetype2.git/tree/ChangeLog</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=491384">https://bugzilla.redhat.com/show_bug.cgi?id=491384</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1621">ADV-2009-1621</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1522">ADV-2009-1522</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1297">ADV-2009-1297</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1058">ADV-2009-1058</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-767-1">USN-767-1</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/34550">34550</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1062.html">RHSA-2009:1062</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1061.html">RHSA-2009:1061</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0329.html">RHSA-2009:0329</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1784">DSA-1784</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3639">http://support.apple.com/kb/HT3639</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3613">http://support.apple.com/kb/HT3613</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3549">http://support.apple.com/kb/HT3549</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270268-1">270268</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200905-05.xml">GLSA-200905-05</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35379">35379</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35210">35210</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35204">35204</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35200">35200</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35198">35198</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35074">35074</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35065">35065</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34967">34967</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34913">34913</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34723" adv="1">34723</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html">SUSE-SR:2009:010</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html">APPLE-SA-2009-05-12</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html">APPLE-SA-2009-06-17-1</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html">APPLE-SA-2009-06-08-1</ref>
            <ref source="CONFIRM" url="http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=a18788b14db60ae3673f932249cd02d33a227c4e">http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=a18788b14db60ae3673f932249cd02d33a227c4e</ref>
            <ref source="CONFIRM" url="http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=79972af4f0485a11dcb19551356c45245749fc5b">http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=79972af4f0485a11dcb19551356c45245749fc5b</ref>
            <ref source="CONFIRM" url="http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=0545ec1ca36b27cb928128870a83e5f668980bc5">http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=0545ec1ca36b27cb928128870a83e5f668980bc5</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freetype" name="freetype">
                <vers num="1.3.1" />
                <vers num="2.0.6" />
                <vers num="2.0.9" />
                <vers num="2.1" />
                <vers num="2.1.10" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.7" />
                <vers num="2.1.8" />
                <vers num="2.1.8_rc1" />
                <vers num="2.1.9" />
                <vers num="2.2" />
                <vers num="2.2.1" />
                <vers num="2.2.10" />
                <vers num="2.3.3" />
                <vers num="2.3.4" />
                <vers num="2.3.5" />
                <vers num="2.3.9" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" name="CVE-2009-1337" seq="2009-1337" severity="Medium" type="CVE" published="2009-04-22" CVSS_version="2.0" CVSS_score="4.4" modified="2009-11-06">
        <desc>
            <descript source="cve">The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://patchwork.kernel.org/patch/16544/">http://patchwork.kernel.org/patch/16544/</ref>
            <ref source="CONFIRM" patch="1" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=432870dab85a2f69dc417022646cb9a70acf7f94" adv="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=432870dab85a2f69dc417022646cb9a70acf7f94</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01126.html">FEDORA-2009-5356</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1550.html">RHSA-2009:1550</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=493771">https://bugzilla.redhat.com/show_bug.cgi?id=493771</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022141">1022141</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/34405">34405</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/503610/100/0/threaded">20090516 rPSA-2009-0084-1 kernel</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1077.html">RHSA-2009:1077</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1024.html">RHSA-2009:1024</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-0451.html">RHSA-2009:0451</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/04/17/3">[oss-security] 20090417 Re: CVE request: kernel: exit_notify: kill the wrong capable(CAP_KILL) check</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/04/07/1">[oss-security] 20090407 CVE request: kernel: exit_notify: kill the wrong capable(CAP_KILL) check</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135">MDVSA-2009:135</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:119">MDVSA-2009:119</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc1" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc1</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1800">DSA-1800</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1794">DSA-1794</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1787">DSA-1787</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0084">http://wiki.rpath.com/Advisories:rPSA-2009-0084</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35394">35394</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35390">35390</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35387">35387</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35226">35226</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35185">35185</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35160">35160</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35121">35121</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35120">35120</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35015">35015</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35011">35011</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34981">34981</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/34917">34917</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2009-0473.html">RHSA-2009:0473</ref>
            <ref source="MLIST" url="http://marc.info/?l=linux-kernel&amp;m=123560588713763&amp;w=2">[linux-kernel] 20090225 Re: [PATCH 2/2] exit_notify: kill the wrong capable(CAP_KILL) check</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html">SUSE-SA:2009:032</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html">SUSE-SA:2009:031</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html">SUSE-SA:2009:030</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html">SUSE-SA:2009:028</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.6" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.22_rc1" />
                <vers num="2.6.22_rc7" />
                <vers edition="rc1" num="2.6.23" />
                <vers edition="rc2" num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers edition="rc1" num="2.6.24" />
                <vers edition="rc2" num="2.6.24" />
                <vers edition="rc3" num="2.6.24" />
                <vers edition="rc4" num="2.6.24" />
                <vers edition="rc5" num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers edition="rc4" num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers edition="rc1" num="2.6.27" />
                <vers edition="rc2" num="2.6.27" />
                <vers edition="rc3" num="2.6.27" />
                <vers edition="rc4" num="2.6.27" />
                <vers edition="rc5" num="2.6.27" />
                <vers edition="rc6" num="2.6.27" />
                <vers edition="rc7" num="2.6.27" />
                <vers edition="rc8" num="2.6.27" />
                <vers edition="rc9" num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers edition="git7" num="2.6.28" />
                <vers edition="rc1" num="2.6.28" />
                <vers edition="rc2" num="2.6.28" />
                <vers edition="rc3" num="2.6.28" />
                <vers edition="rc4" num="2.6.28" />
                <vers edition="rc5" num="2.6.28" />
                <vers edition="rc6" num="2.6.28" />
                <vers edition="rc7" num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers edition="git1" num="2.6.29" prev="1" />
                <vers edition="rc1" num="2.6.29" prev="1" />
                <vers edition="rc2" num="2.6.29" prev="1" />
                <vers edition="rc2_git7" num="2.6.29" prev="1" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-1377" seq="2009-1377" severity="Medium" type="CVE" published="2009-05-19" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://rt.openssl.org/Ticket/Display.html?id=1930&amp;user=guest&amp;pass=guest">http://rt.openssl.org/Ticket/Display.html?id=1930&amp;user=guest&amp;pass=guest</ref>
            <ref source="MLIST" patch="1" url="http://marc.info/?l=openssl-dev&amp;m=124247675613888&amp;w=2">[openssl-dev] 20090516 [openssl.org #1930] [PATCH] DTLS record buffer limitation bug</ref>
            <ref source="CONFIRM" patch="1" url="http://cvs.openssl.org/chngview?cn=18187">http://cvs.openssl.org/chngview?cn=18187</ref>
            <ref source="MISC" url="https://launchpad.net/bugs/cve/2009-1377">https://launchpad.net/bugs/cve/2009-1377</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1377">ADV-2009-1377</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-792-1">USN-792-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022241">1022241</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35001">35001</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/05/18/1">[oss-security] 20090518 Two OpenSSL DTLS remote DoS</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:120">MDVSA-2009:120</ref>
            <ref source="CONFIRM" url="http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html">http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net">http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37003">37003</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35729">35729</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35571">35571</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35461">35461</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35416">35416</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35128" adv="1">35128</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html">SUSE-SR:2009:011</ref>
            <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc">NetBSD-SA2009-009</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openssl" name="openssl">
                <vers num="0.9.8a" />
                <vers num="0.9.8b" />
                <vers num="0.9.8c" />
                <vers num="0.9.8d" />
                <vers num="0.9.8e" />
                <vers num="0.9.8f" />
                <vers num="0.9.8g" />
                <vers num="0.9.8h" />
                <vers num="0.9.8i" />
                <vers num="0.9.8j" />
                <vers num="0.9.8k" prev="1" />
            </prod>
            <prod vendor="openssl_project" name="openssl">
                <vers num="0.9.8c-1" />
                <vers num="0.9.8c-2" />
                <vers num="0.9.8c-3" />
                <vers num="0.9.8c-4" />
                <vers num="0.9.8c-5" />
                <vers num="0.9.8c-6" />
                <vers num="0.9.8c-7" />
                <vers num="0.9.8c-8" />
                <vers num="0.9.8c-9" />
                <vers num="0.9.8d-1" />
                <vers num="0.9.8d-2" />
                <vers num="0.9.8d-3" />
                <vers num="0.9.8d-4" />
                <vers num="0.9.8d-5" />
                <vers num="0.9.8d-6" />
                <vers num="0.9.8d-7" />
                <vers num="0.9.8d-8" />
                <vers num="0.9.8d-9" />
                <vers num="0.9.8e-1" />
                <vers num="0.9.8e-2" />
                <vers num="0.9.8e-3" />
                <vers num="0.9.8e-4" />
                <vers num="0.9.8e-5" />
                <vers num="0.9.8e-6" />
                <vers num="0.9.8e-7" />
                <vers num="0.9.8e-8" />
                <vers num="0.9.8e-9" />
                <vers num="0.9.8f" />
                <vers num="0.9.8f-1" />
                <vers num="0.9.8f-2" />
                <vers num="0.9.8f-3" />
                <vers num="0.9.8f-4" />
                <vers num="0.9.8f-5" />
                <vers num="0.9.8f-6" />
                <vers num="0.9.8f-7" />
                <vers num="0.9.8f-8" />
                <vers num="0.9.8f-9" />
                <vers num="0.9.8g" />
                <vers num="0.9.8g-1" />
                <vers num="0.9.8g-2" />
                <vers num="0.9.8g-3" />
                <vers num="0.9.8g-4" />
                <vers num="0.9.8g-5" />
                <vers num="0.9.8g-6" />
                <vers num="0.9.8g-7" />
                <vers num="0.9.8g-8" />
                <vers num="0.9.8g-9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-1378" seq="2009-1378" severity="Medium" type="CVE" published="2009-05-19" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than current sequence numbers, aka "DTLS fragment handling memory leak."</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://rt.openssl.org/Ticket/Display.html?id=1931&amp;user=guest&amp;pass=guest">http://rt.openssl.org/Ticket/Display.html?id=1931&amp;user=guest&amp;pass=guest</ref>
            <ref source="MLIST" patch="1" url="http://marc.info/?l=openssl-dev&amp;m=124247679213944&amp;w=2">[openssl-dev] 20090516 [openssl.org #1931] [PATCH] DTLS fragment handling memory leak</ref>
            <ref source="CONFIRM" patch="1" url="http://cvs.openssl.org/chngview?cn=18188">http://cvs.openssl.org/chngview?cn=18188</ref>
            <ref source="MISC" url="https://launchpad.net/bugs/cve/2009-1378">https://launchpad.net/bugs/cve/2009-1378</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1377">ADV-2009-1377</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-792-1">USN-792-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022241">1022241</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35001">35001</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/05/18/1">[oss-security] 20090518 Two OpenSSL DTLS remote DoS</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/8720">8720</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:120">MDVSA-2009:120</ref>
            <ref source="CONFIRM" url="http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html">http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net">http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37003">37003</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35729">35729</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35571">35571</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35461">35461</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35416">35416</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35128" adv="1">35128</ref>
            <ref source="MLIST" url="http://marc.info/?l=openssl-dev&amp;m=124263491424212&amp;w=2">[openssl-dev] 20090518 Re: [openssl.org #1931] [PATCH] DTLS fragment handling memory leak</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html">SUSE-SR:2009:011</ref>
            <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc">NetBSD-SA2009-009</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openssl" name="openssl">
                <vers num="0.9.8a" />
                <vers num="0.9.8b" />
                <vers num="0.9.8c" />
                <vers num="0.9.8d" />
                <vers num="0.9.8e" />
                <vers num="0.9.8f" />
                <vers num="0.9.8g" />
                <vers num="0.9.8h" />
                <vers num="0.9.8i" />
                <vers num="0.9.8j" />
                <vers num="0.9.8k" prev="1" />
            </prod>
            <prod vendor="openssl_project" name="openssl">
                <vers num="0.9.8c-1" />
                <vers num="0.9.8c-2" />
                <vers num="0.9.8c-3" />
                <vers num="0.9.8c-4" />
                <vers num="0.9.8c-5" />
                <vers num="0.9.8c-6" />
                <vers num="0.9.8c-7" />
                <vers num="0.9.8c-8" />
                <vers num="0.9.8c-9" />
                <vers num="0.9.8d-1" />
                <vers num="0.9.8d-2" />
                <vers num="0.9.8d-3" />
                <vers num="0.9.8d-4" />
                <vers num="0.9.8d-5" />
                <vers num="0.9.8d-6" />
                <vers num="0.9.8d-7" />
                <vers num="0.9.8d-8" />
                <vers num="0.9.8d-9" />
                <vers num="0.9.8e-1" />
                <vers num="0.9.8e-2" />
                <vers num="0.9.8e-3" />
                <vers num="0.9.8e-4" />
                <vers num="0.9.8e-5" />
                <vers num="0.9.8e-6" />
                <vers num="0.9.8e-7" />
                <vers num="0.9.8e-8" />
                <vers num="0.9.8e-9" />
                <vers num="0.9.8f" />
                <vers num="0.9.8f-1" />
                <vers num="0.9.8f-2" />
                <vers num="0.9.8f-3" />
                <vers num="0.9.8f-4" />
                <vers num="0.9.8f-5" />
                <vers num="0.9.8f-6" />
                <vers num="0.9.8f-7" />
                <vers num="0.9.8f-8" />
                <vers num="0.9.8f-9" />
                <vers num="0.9.8g" />
                <vers num="0.9.8g-1" />
                <vers num="0.9.8g-2" />
                <vers num="0.9.8g-3" />
                <vers num="0.9.8g-4" />
                <vers num="0.9.8g-5" />
                <vers num="0.9.8g-6" />
                <vers num="0.9.8g-7" />
                <vers num="0.9.8g-8" />
                <vers num="0.9.8g-9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-1379" seq="2009-1379" severity="Medium" type="CVE" published="2009-05-19" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS packet, as demonstrated by a packet from a server that uses a crafted server certificate.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="https://launchpad.net/bugs/cve/2009-1379">https://launchpad.net/bugs/cve/2009-1379</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/50661">openssl-dtls1retrievebufferedfragment-dos(50661)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1377">ADV-2009-1377</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-792-1">USN-792-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022241">1022241</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35138">35138</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/05/18/4">[oss-security] 20090518 Re: Two OpenSSL DTLS remote DoS</ref>
            <ref source="CONFIRM" url="http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html">http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net">http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37003">37003</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35729">35729</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35571">35571</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35461">35461</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35416">35416</ref>
            <ref source="CONFIRM" url="http://rt.openssl.org/Ticket/Display.html?id=1923&amp;user=guest&amp;pass=guest">http://rt.openssl.org/Ticket/Display.html?id=1923&amp;user=guest&amp;pass=guest</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html">SUSE-SR:2009:011</ref>
            <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc">NetBSD-SA2009-009</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openssl" name="openssl">
                <vers edition="beta2" num="1.0.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" name="CVE-2009-1195" seq="2009-1195" severity="Medium" type="CVE" published="2009-05-28" CVSS_version="2.0" CVSS_score="4.9" modified="2009-10-31">
        <desc>
            <descript source="cve">The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=489436">https://bugzilla.redhat.com/show_bug.cgi?id=489436</ref>
            <ref source="CONFIRM" patch="1" url="http://svn.apache.org/viewvc?view=rev&amp;revision=772997" adv="1">http://svn.apache.org/viewvc?view=rev&amp;revision=772997</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html">FEDORA-2009-8812</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/50808">apache-allowoverrides-security-bypass(50808)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1444">ADV-2009-1444</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-787-1">USN-787-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022296">1022296</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35115">35115</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1156.html">RHSA-2009:1156</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1075.html">RHSA-2009:1075</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:124">MDVSA-2009:124</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1816">DSA-1816</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200907-04.xml">GLSA-200907-04</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37152">37152</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35721">35721</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35453">35453</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35395">35395</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35264" adv="1">35264</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35261">35261</ref>
            <ref source="OSVDB" url="http://osvdb.org/54733">54733</ref>
            <ref source="MLIST" url="http://marc.info/?l=apache-httpd-dev&amp;m=124048996106302&amp;w=2">[apache-httpd-dev] 20090423 Includes vs IncludesNoExec security issue - help needed</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html">SUSE-SA:2009:050</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="2.2" />
                <vers num="2.2.0" />
                <vers num="2.2.1" />
                <vers num="2.2.10" />
                <vers num="2.2.11" prev="1" />
                <vers edition="" num="2.2.2" />
                <vers edition=":windows" num="2.2.2" />
                <vers edition="" num="2.2.3" />
                <vers edition=":windows" num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.8" />
                <vers num="2.2.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" name="CVE-2009-1385" seq="2009-1385" severity="High" type="CVE" published="2009-06-04" CVSS_version="2.0" CVSS_score="7.8" modified="2009-11-06">
        <desc>
            <descript source="cve">Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=502981">https://bugzilla.redhat.com/show_bug.cgi?id=502981</ref>
            <ref source="CONFIRM" patch="1" url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc8" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc8</ref>
            <ref source="CONFIRM" patch="1" url="http://sourceforge.net/project/shownotes.php?release_id=504022&amp;group_id=42302">http://sourceforge.net/project/shownotes.php?release_id=504022&amp;group_id=42302</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01193.html">FEDORA-2009-6846</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01094.html">FEDORA-2009-6768</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01048.html">FEDORA-2009-6883</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1550.html">RHSA-2009:1550</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35185">35185</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/505254/100/0/threaded">20090724 rPSA-2009-0111-1 kernel</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1193.html">RHSA-2009:1193</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1157.html">RHSA-2009:1157</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/06/03/2">[oss-security] 20090603 CVE-2009-1385 kernel: e1000_clean_rx_irq() denial of service</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:148">MDVSA-2009:148</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135">MDVSA-2009:135</ref>
            <ref source="CONFIRM" url="http://www.intel.com/support/network/sb/CS-030543.htm">http://www.intel.com/support/network/sb/CS-030543.htm</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1865">DSA-1865</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1844">DSA-1844</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0111">http://wiki.rpath.com/Advisories:rPSA-2009-0111</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36327">36327</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36131">36131</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36051">36051</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35847">35847</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35623">35623</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35566">35566</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35265" adv="1">35265</ref>
            <ref source="OSVDB" url="http://osvdb.org/54892">54892</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html">SUSE-SA:2009:038</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ea30e11970a96cfe5e32c03a29332554573b4a10" adv="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ea30e11970a96cfe5e32c03a29332554573b4a10</ref>
        </refs>
        <vuln_soft>
            <prod vendor="intel" name="e1000">
                <vers num="5.2.22" />
                <vers num="5.2.30.1" />
                <vers num="5.2.52" />
                <vers num="5.3.19" />
                <vers num="5.4.11" />
                <vers num="5.5.4" />
                <vers num="5.6.10" />
                <vers num="5.6.10.1" />
                <vers num="5.7.6" />
                <vers num="6.0.54" />
                <vers num="6.0.60" />
                <vers num="6.1.16" />
                <vers num="6.2.15" />
                <vers num="6.3.9" />
                <vers num="7.0.33" />
                <vers num="7.0.41" />
                <vers num="7.1.9" />
                <vers num="7.2.7" />
                <vers num="7.2.9" />
                <vers num="7.3.15" />
                <vers num="7.3.20" />
                <vers num="7.4.27" />
                <vers num="7.4.35" prev="1" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.24.7" />
                <vers num="2.6.25.15" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.6" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.22_rc1" />
                <vers num="2.6.22_rc7" />
                <vers num="2.6.23" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers num="2.6.23_rc1" />
                <vers num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24_rc1" />
                <vers num="2.6.24_rc4" />
                <vers num="2.6.24_rc5" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.27" />
                <vers num="2.6.28" prev="1" />
                <vers edition="git1" num="2.6.29" />
                <vers edition="rc1" num="2.6.29" />
                <vers edition="rc2" num="2.6.29" />
                <vers edition="rc2_git7" num="2.6.29" />
                <vers edition="rc8-kk" num="2.6.29" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.rc1" />
                <vers num="2.6.29.rc2" />
                <vers num="2.6.29.rc2-git1" />
                <vers edition="rc1" num="2.6.30" prev="1" />
                <vers edition="rc2" num="2.6.30" prev="1" />
                <vers edition="rc3" num="2.6.30" prev="1" />
                <vers edition="rc7-git6" num="2.6.30" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-1387" seq="2009-1387" severity="Medium" type="CVE" published="2009-06-04" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://rt.openssl.org/Ticket/Display.html?id=1838&amp;user=guest&amp;pass=guest">http://rt.openssl.org/Ticket/Display.html?id=1838&amp;user=guest&amp;pass=guest</ref>
            <ref source="CONFIRM" patch="1" url="http://cvs.openssl.org/chngview?cn=17958">http://cvs.openssl.org/chngview?cn=17958</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-792-1">USN-792-1</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/06/02/1">[oss-security] 20090602 Re: Two OpenSSL DTLS remote DoS</ref>
            <ref source="CONFIRM" url="http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html">http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net">http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37003">37003</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35729">35729</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35685">35685</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35571">35571</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html">SUSE-SR:2009:012</ref>
            <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc">NetBSD-SA2009-009</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openssl" name="openssl">
                <vers num="0.9.1c" />
                <vers num="0.9.2b" />
                <vers num="0.9.3" />
                <vers num="0.9.3a" />
                <vers num="0.9.4" />
                <vers edition="beta1" num="0.9.5" />
                <vers edition="beta1" num="0.9.5a" />
                <vers edition="beta2" num="0.9.5a" />
                <vers edition="beta1" num="0.9.6" />
                <vers edition="beta2" num="0.9.6" />
                <vers edition="beta3" num="0.9.6" />
                <vers edition="beta1" num="0.9.6a" />
                <vers edition="beta2" num="0.9.6a" />
                <vers edition="beta3" num="0.9.6a" />
                <vers num="0.9.6b" />
                <vers num="0.9.6c" />
                <vers num="0.9.6d" />
                <vers num="0.9.6e" />
                <vers num="0.9.6f" />
                <vers num="0.9.6g" />
                <vers num="0.9.6h" />
                <vers num="0.9.6i" />
                <vers num="0.9.6j" />
                <vers num="0.9.6k" />
                <vers num="0.9.6l" />
                <vers num="0.9.6m" />
                <vers edition="beta1" num="0.9.7" />
                <vers edition="beta2" num="0.9.7" />
                <vers edition="beta3" num="0.9.7" />
                <vers edition="beta4" num="0.9.7" />
                <vers edition="beta5" num="0.9.7" />
                <vers edition="beta6" num="0.9.7" />
                <vers num="0.9.7a" />
                <vers num="0.9.7b" />
                <vers num="0.9.7c" />
                <vers num="0.9.7d" />
                <vers num="0.9.7e" />
                <vers num="0.9.7f" />
                <vers num="0.9.7g" />
                <vers num="0.9.7h" />
                <vers num="0.9.7i" />
                <vers num="0.9.7j" />
                <vers num="0.9.7k" />
                <vers num="0.9.7l" />
                <vers num="0.9.7m" />
                <vers num="0.9.8" />
                <vers num="0.9.8a" />
                <vers num="0.9.8b" />
                <vers num="0.9.8c" />
                <vers num="0.9.8d" />
                <vers num="0.9.8e" />
                <vers num="0.9.8f" />
                <vers num="0.9.8g" />
                <vers num="0.9.8h" />
                <vers num="0.9.8i" />
                <vers num="0.9.8j" />
                <vers num="0.9.8k" />
                <vers edition="" num="1.0" prev="1" />
                <vers edition=":openvms" num="1.0" prev="1" />
            </prod>
            <prod vendor="openssl_project" name="openssl">
                <vers num="0.9.8c-1" />
                <vers num="0.9.8c-2" />
                <vers num="0.9.8c-3" />
                <vers num="0.9.8c-4" />
                <vers num="0.9.8c-5" />
                <vers num="0.9.8c-6" />
                <vers num="0.9.8c-7" />
                <vers num="0.9.8c-8" />
                <vers num="0.9.8c-9" />
                <vers num="0.9.8d-1" />
                <vers num="0.9.8d-2" />
                <vers num="0.9.8d-3" />
                <vers num="0.9.8d-4" />
                <vers num="0.9.8d-5" />
                <vers num="0.9.8d-6" />
                <vers num="0.9.8d-7" />
                <vers num="0.9.8d-8" />
                <vers num="0.9.8d-9" />
                <vers num="0.9.8e-1" />
                <vers num="0.9.8e-2" />
                <vers num="0.9.8e-3" />
                <vers num="0.9.8e-4" />
                <vers num="0.9.8e-5" />
                <vers num="0.9.8e-6" />
                <vers num="0.9.8e-7" />
                <vers num="0.9.8e-8" />
                <vers num="0.9.8e-9" />
                <vers num="0.9.8f" />
                <vers num="0.9.8f-1" />
                <vers num="0.9.8f-2" />
                <vers num="0.9.8f-3" />
                <vers num="0.9.8f-4" />
                <vers num="0.9.8f-5" />
                <vers num="0.9.8f-6" />
                <vers num="0.9.8f-7" />
                <vers num="0.9.8f-8" />
                <vers num="0.9.8f-9" />
                <vers num="0.9.8g" prev="1" />
                <vers num="0.9.8g-1" />
                <vers num="0.9.8g-2" />
                <vers num="0.9.8g-3" />
                <vers num="0.9.8g-4" />
                <vers num="0.9.8g-5" />
                <vers num="0.9.8g-6" />
                <vers num="0.9.8g-7" />
                <vers num="0.9.8g-8" />
                <vers num="0.9.8g-9" />
            </prod>
            <prod vendor="redhat" name="openssl">
                <vers edition="" num="0.9.6-15" />
                <vers edition=":i386" num="0.9.6-15" />
                <vers edition="" num="0.9.6b-3" />
                <vers edition=":i386" num="0.9.6b-3" />
                <vers edition="" num="0.9.7a-2" />
                <vers edition=":i386_perl" num="0.9.7a-2" />
                <vers edition=":i386" num="0.9.7a-2" />
                <vers edition=":i386_dev" num="0.9.7a-2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-1890" seq="2009-1890" severity="Medium" type="CVE" published="2009-07-05" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=790587&amp;r2=790586&amp;pathrev=790587" adv="1">http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=790587&amp;r2=790586&amp;pathrev=790587</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html">FEDORA-2009-8812</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1148.html">RHSA-2009:1148</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-802-1">USN-802-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022509">1022509</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35565">35565</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1156.html">RHSA-2009:1156</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:149">MDVSA-2009:149</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1834">DSA-1834</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc?view=rev&amp;revision=790587" adv="1">http://svn.apache.org/viewvc?view=rev&amp;revision=790587</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?revision=790587" adv="1">http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?revision=790587</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=790587&amp;r2=790586&amp;pathrev=790587" adv="1">http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=790587&amp;r2=790586&amp;pathrev=790587</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200907-04.xml">GLSA-200907-04</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37152">37152</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35865">35865</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35793">35793</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35721">35721</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35691" adv="1">35691</ref>
            <ref source="OSVDB" url="http://osvdb.org/55553">55553</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html">SUSE-SA:2009:050</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers edition=":win32" num="" />
                <vers num="0.8.11" />
                <vers num="0.8.14" />
                <vers num="1.0" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.5" />
                <vers num="1.1" />
                <vers num="1.1.1" />
                <vers num="1.2" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
                <vers num="1.2.6" />
                <vers num="1.2.9" />
                <vers num="1.3" />
                <vers num="1.3.0" />
                <vers num="1.3.1" />
                <vers num="1.3.1.1" />
                <vers num="1.3.10" />
                <vers edition="" num="1.3.11" />
                <vers edition=":win32" num="1.3.11" />
                <vers edition="" num="1.3.12" />
                <vers edition=":win32" num="1.3.12" />
                <vers edition="" num="1.3.13" />
                <vers edition=":win32" num="1.3.13" />
                <vers edition="" num="1.3.14" />
                <vers edition=":mac_os" num="1.3.14" />
                <vers edition=":win32" num="1.3.14" />
                <vers edition="" num="1.3.15" />
                <vers edition=":win32" num="1.3.15" />
                <vers edition="" num="1.3.16" />
                <vers edition=":win32" num="1.3.16" />
                <vers edition="" num="1.3.17" />
                <vers edition=":win32" num="1.3.17" />
                <vers edition="" num="1.3.18" />
                <vers edition=":win32" num="1.3.18" />
                <vers edition="" num="1.3.19" />
                <vers edition=":win32" num="1.3.19" />
                <vers num="1.3.2" />
                <vers edition="" num="1.3.20" />
                <vers edition=":win32" num="1.3.20" />
                <vers edition="" num="1.3.22" />
                <vers edition=":win32" num="1.3.22" />
                <vers edition="" num="1.3.23" />
                <vers edition=":win32" num="1.3.23" />
                <vers edition="" num="1.3.24" />
                <vers edition=":win32" num="1.3.24" />
                <vers edition="" num="1.3.25" />
                <vers edition=":win32" num="1.3.25" />
                <vers edition="" num="1.3.26" />
                <vers edition=":win32" num="1.3.26" />
                <vers num="1.3.27" />
                <vers num="1.3.28" />
                <vers num="1.3.29" />
                <vers num="1.3.3" />
                <vers num="1.3.30" />
                <vers num="1.3.31" />
                <vers num="1.3.32" />
                <vers num="1.3.33" />
                <vers num="1.3.34" />
                <vers num="1.3.35" />
                <vers num="1.3.36" />
                <vers num="1.3.37" />
                <vers num="1.3.38" />
                <vers num="1.3.39" />
                <vers num="1.3.4" />
                <vers num="1.3.5" />
                <vers edition="" num="1.3.6" />
                <vers edition=":win32" num="1.3.6" />
                <vers num="1.3.65" />
                <vers num="1.3.68" />
                <vers edition="" num="1.3.7" />
                <vers edition=":dev" num="1.3.7" />
                <vers num="1.3.8" />
                <vers edition="" num="1.3.9" />
                <vers edition=":win32" num="1.3.9" />
                <vers num="1.4.0" />
                <vers num="1.99" />
                <vers num="2.0" />
                <vers edition="beta" num="2.0.28" />
                <vers edition="beta:win32" num="2.0.28" />
                <vers edition="beta" num="2.0.32" />
                <vers edition="beta:win32" num="2.0.32" />
                <vers edition="beta" num="2.0.34" />
                <vers edition="beta:win32" num="2.0.34" />
                <vers num="2.0.35" />
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.43" />
                <vers num="2.0.44" />
                <vers num="2.0.45" />
                <vers edition="" num="2.0.46" />
                <vers edition=":win32" num="2.0.46" />
                <vers num="2.0.47" />
                <vers num="2.0.48" />
                <vers num="2.0.49" />
                <vers num="2.0.50" />
                <vers num="2.0.51" />
                <vers num="2.0.52" />
                <vers num="2.0.53" />
                <vers num="2.0.54" />
                <vers num="2.0.55" />
                <vers num="2.0.56" />
                <vers num="2.0.57" />
                <vers edition="" num="2.0.58" />
                <vers edition=":win32" num="2.0.58" />
                <vers num="2.0.59" />
                <vers num="2.0.60" />
                <vers num="2.0.61" />
                <vers num="2.0.9" />
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.7" />
                <vers num="2.1.8" />
                <vers num="2.1.9" />
                <vers num="2.2" />
                <vers num="2.2.0" />
                <vers num="2.2.1" />
                <vers num="2.2.10" />
                <vers num="2.2.11" />
                <vers edition="" num="2.2.2" />
                <vers edition=":windows" num="2.2.2" />
                <vers edition="" num="2.2.3" />
                <vers edition=":windows" num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.8" />
                <vers num="2.2.9" />
                <vers num="2.3.0" />
                <vers num="2.3.1" />
                <vers num="2.3.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-1891" seq="2009-1891" severity="Medium" type="CVE" published="2009-07-10" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-31">
        <desc>
            <descript source="cve">The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="https://rhn.redhat.com/errata/RHSA-2009-1148.html">RHSA-2009:1148</ref>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=509125">https://bugzilla.redhat.com/show_bug.cgi?id=509125</ref>
            <ref source="MANDRIVA" patch="1" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:149">MDVSA-2009:149</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html">FEDORA-2009-8812</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1841">ADV-2009-1841</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-802-1">USN-802-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022529">1022529</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1156.html">RHSA-2009:1156</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1834">DSA-1834</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200907-04.xml">GLSA-200907-04</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37152">37152</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35865">35865</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35793">35793</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35781">35781</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35721">35721</ref>
            <ref source="OSVDB" url="http://osvdb.org/55782">55782</ref>
            <ref source="MLIST" url="http://marc.info/?l=apache-httpd-dev&amp;m=124661528519546&amp;w=2">[apache-httpd-dev] 20090703 Re: mod_deflate DoS</ref>
            <ref source="MLIST" url="http://marc.info/?l=apache-httpd-dev&amp;m=124621326524824&amp;w=2">[apache-httpd-dev] 20090628 mod_deflate DoS</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html">SUSE-SA:2009:050</ref>
            <ref source="MISC" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534712">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534712</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="0.8.11" />
                <vers num="0.8.14" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.5" />
                <vers num="1.1" />
                <vers num="1.1.1" />
                <vers num="1.2" />
                <vers num="1.2.4" />
                <vers num="1.2.9" />
                <vers num="1.3.13" />
                <vers num="1.3.14" />
                <vers num="1.3.18" />
                <vers num="1.3.19" />
                <vers num="1.3.20" />
                <vers num="1.3.22" />
                <vers num="1.3.23" />
                <vers num="1.3.27" />
                <vers num="1.3.29" />
                <vers num="1.3.3" />
                <vers num="1.3.31" />
                <vers num="1.3.33" />
                <vers num="1.3.38" />
                <vers num="1.3.6" />
                <vers num="1.3.7" />
                <vers num="1.3.9" />
                <vers num="1.99" />
                <vers num="2.0.28" />
                <vers edition="beta" num="2.0.34" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.45" />
                <vers num="2.0.46" />
                <vers num="2.0.47" />
                <vers num="2.0.48" />
                <vers num="2.0.49" />
                <vers num="2.0.50" />
                <vers num="2.0.51" />
                <vers num="2.0.52" />
                <vers num="2.0.53" />
                <vers num="2.0.54" />
                <vers num="2.0.55" />
                <vers num="2.0.56" />
                <vers num="2.0.57" />
                <vers num="2.0.58" />
                <vers num="2.0.59" />
                <vers num="2.0.60" />
                <vers num="2.0.61" />
                <vers num="2.0.9" />
                <vers num="2.1" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.7" />
                <vers num="2.1.8" />
                <vers num="2.1.9" />
                <vers num="2.2" />
                <vers num="2.2.0" />
                <vers num="2.2.1" />
                <vers num="2.2.10" />
                <vers num="2.2.11" prev="1" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.8" />
                <vers num="2.2.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-0217" seq="2009-0217" severity="Medium" type="CVE" published="2009-07-14" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-27">
        <desc>
            <descript source="cve">The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html">TA09-294A</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/466161">VU#466161</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/1911" adv="1">ADV-2009-1911</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/1909" adv="1">ADV-2009-1909</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/1908" adv="1">ADV-2009-1908</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/1900" adv="1">ADV-2009-1900</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/35671">35671</ref>
            <ref source="CONFIRM" patch="1" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www-01.ibm.com/support/docview.wss?rs=180&amp;uid=swg21384925" adv="1">http://www-01.ibm.com/support/docview.wss?rs=180&amp;uid=swg21384925</ref>
            <ref source="AIXAPAR" patch="1" url="http://www-01.ibm.com/support/docview.wss?rs=180&amp;context=SSEQTP&amp;dc=D400&amp;uid=swg24023723&amp;loc=en_US&amp;cs=UTF-8&amp;lang=en&amp;rss=ct180websphere" adv="1">PK80627</ref>
            <ref source="AIXAPAR" patch="1" url="http://www-01.ibm.com/support/docview.wss?rs=180&amp;context=SSEQTP&amp;dc=D400&amp;uid=swg24023545&amp;loc=en_US&amp;cs=UTF-8&amp;lang=en&amp;rss=ct180websphere" adv="1">PK80596</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00505.html">FEDORA-2009-8473</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00494.html">FEDORA-2009-8456</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html">FEDORA-2009-8337</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html">FEDORA-2009-8329</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1201.html">RHSA-2009:1201</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1200.html">RHSA-2009:1200</ref>
            <ref source="CONFIRM" url="https://issues.apache.org/bugzilla/show_bug.cgi?id=47527">https://issues.apache.org/bugzilla/show_bug.cgi?id=47527</ref>
            <ref source="CONFIRM" url="https://issues.apache.org/bugzilla/show_bug.cgi?id=47526">https://issues.apache.org/bugzilla/show_bug.cgi?id=47526</ref>
            <ref source="MISC" url="http://www.w3.org/QA/2009/07/hmac_truncation_in_xml_signatu.html" adv="1">http://www.w3.org/QA/2009/07/hmac_truncation_in_xml_signatu.html</ref>
            <ref source="CONFIRM" url="http://www.w3.org/2008/06/xmldsigcore-errata.html#e03" adv="1">http://www.w3.org/2008/06/xmldsigcore-errata.html#e03</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2543">ADV-2009-2543</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-826-1">USN-826-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022661">1022661</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022567">1022567</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022561">1022561</ref>
            <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</ref>
            <ref source="CONFIRM" url="http://www.mono-project.com/Vulnerabilities" adv="1">http://www.mono-project.com/Vulnerabilities</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209">MDVSA-2009:209</ref>
            <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/WDON-7TY529">http://www.kb.cert.org/vuls/id/WDON-7TY529</ref>
            <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/MAPG-7TSKXQ">http://www.kb.cert.org/vuls/id/MAPG-7TSKXQ</ref>
            <ref source="CONFIRM" url="http://www.aleksey.com/xmlsec/">http://www.aleksey.com/xmlsec/</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263429-1">263429</ref>
            <ref source="CONFIRM" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36494" adv="1">36494</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36180" adv="1">36180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36176" adv="1">36176</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36162" adv="1">36162</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35858" adv="1">35858</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35855" adv="1">35855</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35854" adv="1">35854</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35853" adv="1">35853</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35852" adv="1">35852</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35776" adv="1">35776</ref>
            <ref source="OSVDB" url="http://osvdb.org/55907">55907</ref>
            <ref source="OSVDB" url="http://osvdb.org/55895">55895</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html">APPLE-SA-2009-09-03-1</ref>
            <ref source="CONFIRM" url="http://blogs.sun.com/security/entry/cert_vulnerability_note_vu_466161">http://blogs.sun.com/security/entry/cert_vulnerability_note_vu_466161</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="websphere_application_server">
                <vers num="6.0" />
                <vers num="6.0.0.1" />
                <vers num="6.0.0.2" />
                <vers num="6.0.0.3" />
                <vers num="6.0.1" />
                <vers num="6.0.1.1" />
                <vers num="6.0.1.11" />
                <vers num="6.0.1.13" />
                <vers num="6.0.1.15" />
                <vers num="6.0.1.17" />
                <vers num="6.0.1.2" />
                <vers num="6.0.1.3" />
                <vers num="6.0.1.5" />
                <vers num="6.0.1.7" />
                <vers num="6.0.1.9" />
                <vers edition="" num="6.0.2" />
                <vers edition=":fp17" num="6.0.2" />
                <vers num="6.0.2.1" />
                <vers num="6.0.2.10" />
                <vers num="6.0.2.11" />
                <vers num="6.0.2.12" />
                <vers num="6.0.2.13" />
                <vers num="6.0.2.14" />
                <vers num="6.0.2.15" />
                <vers num="6.0.2.16" />
                <vers num="6.0.2.17" />
                <vers num="6.0.2.18" />
                <vers num="6.0.2.19" />
                <vers num="6.0.2.2" />
                <vers num="6.0.2.20" />
                <vers num="6.0.2.21" />
                <vers num="6.0.2.22" />
                <vers num="6.0.2.23" />
                <vers num="6.0.2.24" />
                <vers num="6.0.2.25" />
                <vers num="6.0.2.28" />
                <vers num="6.0.2.29" />
                <vers num="6.0.2.3" />
                <vers num="6.0.2.30" />
                <vers num="6.0.2.31" />
                <vers num="6.0.2.32" />
                <vers num="6.0.2.33" />
                <vers num="6.1" />
                <vers num="6.1.0" />
                <vers num="6.1.0.0" />
                <vers num="6.1.0.1" />
                <vers num="6.1.0.10" />
                <vers num="6.1.0.11" />
                <vers num="6.1.0.12" />
                <vers num="6.1.0.13" />
                <vers num="6.1.0.14" />
                <vers num="6.1.0.15" />
                <vers num="6.1.0.16" />
                <vers num="6.1.0.17" />
                <vers num="6.1.0.18" />
                <vers num="6.1.0.19" />
                <vers num="6.1.0.2" />
                <vers num="6.1.0.20" />
                <vers num="6.1.0.21" />
                <vers num="6.1.0.22" />
                <vers num="6.1.0.23" />
                <vers num="6.1.0.3" />
                <vers num="6.1.0.4" />
                <vers num="6.1.0.5" />
                <vers num="6.1.0.6" />
                <vers num="6.1.0.7" />
                <vers num="6.1.0.8" />
                <vers num="6.1.0.9" />
                <vers num="7.0" />
                <vers num="7.0.0.1" />
            </prod>
            <prod vendor="mono_project" name="mono">
                <vers num="1.2.1" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
                <vers num="1.2.6" />
                <vers num="1.9" />
                <vers num="2.0" />
            </prod>
            <prod vendor="oracle" name="application_server">
                <vers num="10.1.2.3" />
                <vers num="10.1.3.4" />
                <vers num="10.1.4.3im" />
            </prod>
            <prod vendor="oracle" name="bea_product_suite">
                <vers edition="mp1" num="10.0" />
                <vers num="10.3" />
                <vers edition="sp6" num="8.1" />
                <vers num="9.0" />
                <vers num="9.1" />
                <vers edition="mp3" num="9.2" />
            </prod>
            <prod vendor="oracle" name="weblogic_server_component">
                <vers edition="mp1" num="10.0" />
                <vers num="10.3" />
                <vers edition="sp6" num="8.1" />
                <vers num="9.0" />
                <vers num="9.1" />
                <vers edition="mp3" num="9.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2009-1895" seq="2009-1895" severity="High" type="CVE" published="2009-07-16" CVSS_version="2.0" CVSS_score="7.2" modified="2009-11-06">
        <desc>
            <descript source="cve">The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/1866" adv="1">ADV-2009-1866</ref>
            <ref source="CONFIRM" patch="1" url="http://patchwork.kernel.org/patch/32598/" adv="1">http://patchwork.kernel.org/patch/32598/</ref>
            <ref source="MISC" patch="1" url="http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html">http://blog.cr0.org/2009/06/bypassing-linux-null-pointer.html</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00223.html">FEDORA-2009-8144</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00166.html">FEDORA-2009-8264</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1550.html">RHSA-2009:1550</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1540.html">RHSA-2009:1540</ref>
            <ref source="CONFIRM" url="https://bugs.launchpad.net/bugs/cve/2009-1895">https://bugs.launchpad.net/bugs/cve/2009-1895</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-807-1">USN-807-1</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35647">35647</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/505254/100/0/threaded">20090724 rPSA-2009-0111-1 kernel</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1438.html">RHSA-2009:1438</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1193.html">RHSA-2009:1193</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/55807">55807</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc3" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc3</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1845">DSA-1845</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1844">DSA-1844</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0111">http://wiki.rpath.com/Advisories:rPSA-2009-0111</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36759">36759</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36131">36131</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36116">36116</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36054">36054</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36051">36051</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36045">36045</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35801" adv="1">35801</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f9fabcb58a6d26d6efde842d1703ac7cfa9427b6" adv="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f9fabcb58a6d26d6efde842d1703ac7cfa9427b6</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.6" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.22_rc1" />
                <vers num="2.6.22_rc7" />
                <vers edition="rc1" num="2.6.23" />
                <vers edition="rc2" num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers edition="rc1" num="2.6.24" />
                <vers edition="rc2" num="2.6.24" />
                <vers edition="rc3" num="2.6.24" />
                <vers edition="rc4" num="2.6.24" />
                <vers edition="rc5" num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers edition="rc4" num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers edition="rc1" num="2.6.27" />
                <vers edition="rc2" num="2.6.27" />
                <vers edition="rc3" num="2.6.27" />
                <vers edition="rc4" num="2.6.27" />
                <vers edition="rc5" num="2.6.27" />
                <vers edition="rc6" num="2.6.27" />
                <vers edition="rc7" num="2.6.27" />
                <vers edition="rc8" num="2.6.27" />
                <vers edition="rc9" num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers edition="rc1" num="2.6.28" />
                <vers edition="rc2" num="2.6.28" />
                <vers edition="rc3" num="2.6.28" />
                <vers edition="rc4" num="2.6.28" />
                <vers edition="rc5" num="2.6.28" />
                <vers edition="rc6" num="2.6.28" />
                <vers edition="rc7" num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" prev="1" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers edition="git1" num="2.6.29" />
                <vers edition="rc1" num="2.6.29" />
                <vers edition="rc2" num="2.6.29" />
                <vers edition="rc2_git7" num="2.6.29" />
                <vers edition="rc8-kk" num="2.6.29" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.5" />
                <vers edition="rc1" num="2.6.30" />
                <vers edition="rc2" num="2.6.30" />
                <vers edition="rc3" num="2.6.30" />
                <vers edition="rc5" num="2.6.30" />
                <vers edition="rc6" num="2.6.30" />
                <vers edition="rc7-git6" num="2.6.30" />
                <vers edition="rc1" num="2.6.31" prev="1" />
                <vers edition="rc2" num="2.6.31" prev="1" />
            </prod>
            <prod vendor="linux" name="linux_kernel">
                <vers edition="rc4" num="2.6.30" />
                <vers edition="rc4:x86_32" num="2.6.30" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-2560" seq="2009-2560" severity="Medium" type="CVE" published="2009-07-21" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace and is processed by the (1) Bluetooth L2CAP, (2) RADIUS, or (3) MIOP dissector. NOTE: it was later reported that the RADIUS issue also affects 0.10.13 through 1.0.9.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.wireshark.org/security/wnpa-sec-2009-04.html" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-04.html</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/35748">35748</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54019">wireshark-radius-dissector-dos(54019)</ref>
            <ref source="CONFIRM" url="http://www.wireshark.org/security/wnpa-sec-2009-08.html">http://www.wireshark.org/security/wnpa-sec-2009-08.html</ref>
            <ref source="CONFIRM" url="http://www.wireshark.org/docs/relnotes/wireshark-1.0.10.html">http://www.wireshark.org/docs/relnotes/wireshark-1.0.10.html</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3061">ADV-2009-3061</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1970" adv="1">ADV-2009-1970</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36846">36846</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/07/22/2">[oss-security] 20090722 Re: CVE request: Wireshark &lt;1.2.1 Multiple DoS</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:194">MDVSA-2009:194</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37175">37175</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35884" adv="1">35884</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wireshark" name="wireshark">
                <vers num="1.0.8" />
                <vers num="1.2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-2562" seq="2009-2562" severity="Medium" type="CVE" published="2009-07-21" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-31">
        <desc>
            <descript source="cve">Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.wireshark.org/security/wnpa-sec-2009-04.html" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-04.html</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/35748">35748</ref>
            <ref source="MISC" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3564">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3564</ref>
            <ref source="CONFIRM" url="http://www.wireshark.org/security/wnpa-sec-2009-05.html">http://www.wireshark.org/security/wnpa-sec-2009-05.html</ref>
            <ref source="CONFIRM" url="http://www.wireshark.org/docs/relnotes/wireshark-1.0.9.html">http://www.wireshark.org/docs/relnotes/wireshark-1.0.9.html</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1970" adv="1">ADV-2009-1970</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/09/18/2">[oss-security] Re: Wireshark - wnpa-sec-2009-05.html &amp;&amp; wnpa-sec-2009-06.html -- CVE confirmation and CVE Request</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/09/17/15">[oss-security] Wireshark - wnpa-sec-2009-05.html &amp;&amp; wnpa-sec-2009-06.html -- CVE confirmation and CVE Request</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:194">MDVSA-2009:194</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35884" adv="1">35884</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wireshark" name="wireshark">
                <vers num="0.10.9" />
                <vers num="0.9.10" />
                <vers num="0.9.14" />
                <vers num="0.9.2" />
                <vers num="0.9.5" />
                <vers num="0.9.6" />
                <vers num="0.9.7" />
                <vers num="0.9.8" />
                <vers num="0.99" />
                <vers num="0.99.0" />
                <vers num="0.99.1" />
                <vers num="0.99.2" />
                <vers num="0.99.3" />
                <vers num="0.99.4" />
                <vers num="0.99.5" />
                <vers num="0.99.6" />
                <vers num="0.99.6a" />
                <vers num="0.99.7" />
                <vers num="0.99.8" />
                <vers num="1.0" />
                <vers num="1.0.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" name="CVE-2009-2563" seq="2009-2563" severity="High" type="CVE" published="2009-07-21" CVSS_version="2.0" CVSS_score="7.1" modified="2009-10-31">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.wireshark.org/security/wnpa-sec-2009-04.html" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-04.html</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/1970" adv="1">ADV-2009-1970</ref>
            <ref source="CONFIRM" url="http://www.wireshark.org/security/wnpa-sec-2009-05.html">http://www.wireshark.org/security/wnpa-sec-2009-05.html</ref>
            <ref source="CONFIRM" url="http://www.wireshark.org/docs/relnotes/wireshark-1.0.9.html">http://www.wireshark.org/docs/relnotes/wireshark-1.0.9.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35748">35748</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/09/18/2">[oss-security] 20090917 Re: Wireshark - wnpa-sec-2009-05.html &amp;&amp; wnpa-sec-2009-06.html -- CVE confirmation and CVE Request</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/09/17/15">[oss-security] 20090917 Wireshark - wnpa-sec-2009-05.html &amp;&amp; wnpa-sec-2009-06.html -- CVE confirmation and CVE Request</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:194">MDVSA-2009:194</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35884" adv="1">35884</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wireshark" name="wireshark">
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.2.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-2408" seq="2009-2408" severity="High" type="CVE" published="2009-07-30" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-27">
        <desc>
            <descript source="cve">Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=510251">https://bugzilla.redhat.com/show_bug.cgi?id=510251</ref>
            <ref source="MISC" url="http://www.wired.com/threatlevel/2009/07/kaminsky/">http://www.wired.com/threatlevel/2009/07/kaminsky/</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2085" adv="1">ADV-2009-2085</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-810-2">USN-810-2</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-810-1">USN-810-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022632">1022632</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1432.html">RHSA-2009:1432</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1207.html">RHSA-2009:1207</ref>
            <ref source="CONFIRM" url="http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_m.c.diff?r1=1.8&amp;r2=1.11&amp;f=h">http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_m.c.diff?r1=1.8&amp;r2=1.11&amp;f=h</ref>
            <ref source="CONFIRM" url="http://www.mozilla.org/security/announce/2009/mfsa2009-42.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-42.html</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:197">MDVSA-2009:197</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1874">DSA-1874</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36434">36434</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36157" adv="1">36157</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36139" adv="1">36139</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36125" adv="1">36125</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36088" adv="1">36088</ref>
            <ref source="OSVDB" url="http://osvdb.org/56723">56723</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125198917018936&amp;w=2">[oss-security] 20090903 More CVE-2009-2408 like issues</ref>
            <ref source="MISC" url="http://isc.sans.org/diary.html?storyid=7003">http://isc.sans.org/diary.html?storyid=7003</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="0.1" />
                <vers num="0.10" />
                <vers num="0.10.1" />
                <vers num="0.2" />
                <vers num="0.3" />
                <vers num="0.4" />
                <vers num="0.5" />
                <vers num="0.6" />
                <vers num="0.6.1" />
                <vers num="0.7" />
                <vers num="0.7.1" />
                <vers num="0.8" />
                <vers edition="rc" num="0.9" />
                <vers num="0.9.1" />
                <vers num="0.9.2" />
                <vers num="0.9.3" />
                <vers num="0.9_rc" />
                <vers edition="preview_release" num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers edition="" num="1.0.6" />
                <vers edition=":linux" num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.4.1" />
                <vers edition="beta1" num="1.5" />
                <vers edition="beta2" num="1.5" />
                <vers num="1.5.0.1" />
                <vers num="1.5.0.10" />
                <vers num="1.5.0.11" />
                <vers num="1.5.0.12" />
                <vers num="1.5.0.2" />
                <vers num="1.5.0.3" />
                <vers num="1.5.0.4" />
                <vers num="1.5.0.5" />
                <vers num="1.5.0.6" />
                <vers num="1.5.0.7" />
                <vers num="1.5.0.8" />
                <vers num="1.5.0.9" />
                <vers num="1.5.1" />
                <vers num="1.5.2" />
                <vers num="1.5.3" />
                <vers num="1.5.4" />
                <vers num="1.5.5" />
                <vers num="1.5.6" />
                <vers num="1.5.7" />
                <vers num="1.5.8" />
                <vers num="1.8" />
                <vers edition="beta1" num="2.0" />
                <vers edition="beta_1" num="2.0" />
                <vers edition="rc2" num="2.0" />
                <vers edition="rc3" num="2.0" />
                <vers num="2.0.0.1" />
                <vers num="2.0.0.10" />
                <vers num="2.0.0.11" />
                <vers num="2.0.0.12" />
                <vers num="2.0.0.13" />
                <vers num="2.0.0.14" />
                <vers num="2.0.0.15" />
                <vers num="2.0.0.16" />
                <vers num="2.0.0.17" />
                <vers num="2.0.0.18" />
                <vers num="2.0.0.19" />
                <vers num="2.0.0.2" />
                <vers num="2.0.0.20" />
                <vers num="2.0.0.21" />
                <vers num="2.0.0.3" />
                <vers num="2.0.0.4" />
                <vers num="2.0.0.5" />
                <vers num="2.0.0.6" />
                <vers num="2.0.0.7" />
                <vers num="2.0.0.8" />
                <vers num="2.0.0.9" />
                <vers num="2.0_.1" />
                <vers num="2.0_.10" />
                <vers num="2.0_.4" />
                <vers num="2.0_.5" />
                <vers num="2.0_.6" />
                <vers num="2.0_.7" />
                <vers num="2.0_.9" />
                <vers num="2.0_8" />
                <vers edition="alpha" num="3.0" />
                <vers edition="beta2" num="3.0" />
                <vers edition="beta5" num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.10" />
                <vers num="3.0.11" />
                <vers num="3.0.12" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.6" />
                <vers num="3.0.7" />
                <vers num="3.0.8" />
                <vers num="3.0.9" />
                <vers num="3.0beta5" />
                <vers edition="beta1" num="3.1" />
                <vers edition="beta1" num="3.2" prev="1" />
                <vers edition="beta2" num="3.2" prev="1" />
                <vers edition="beta3" num="3.2" prev="1" />
            </prod>
            <prod vendor="mozilla" name="nss">
                <vers num="3.0" />
                <vers num="3.11.2" />
                <vers num="3.11.4" />
                <vers num="3.11.7" />
                <vers num="3.11.8" />
                <vers num="3.12" prev="1" />
                <vers num="3.4" />
                <vers num="3.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-2661" seq="2009-2661" severity="Medium" type="CVE" published="2009-08-04" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-27">
        <desc>
            <descript source="cve">The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data.  NOTE: this is due to an incomplete fix for CVE-2009-2185.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MLIST" patch="1" url="https://lists.strongswan.org/pipermail/announce/2009-July/000056.html">[Announce] 20090723 ANNOUNCE: strongswan-2.8.11 and strongswan-4.2.17 released</ref>
            <ref source="CONFIRM" patch="1" url="http://download.strongswan.org/patches/07_asn1_length_patch/strongswan-4.x.x_asn1_length.patch">http://download.strongswan.org/patches/07_asn1_length_patch/strongswan-4.x.x_asn1_length.patch</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2247">ADV-2009-2247</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/07/27/1">[oss-security] 20090727 CVE id request: strongswan</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1899">DSA-1899</ref>
            <ref source="CONFIRM" url="http://up2date.astaro.com/2009/08/up2date_7505_released.html">http://up2date.astaro.com/2009/08/up2date_7505_released.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36922">36922</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="CONFIRM" url="http://download.strongswan.org/patches/07_asn1_length_patch/strongswan-4.3.x_asn1_length.patch">http://download.strongswan.org/patches/07_asn1_length_patch/strongswan-4.3.x_asn1_length.patch</ref>
        </refs>
        <vuln_soft>
            <prod vendor="strongswan" name="strongswan">
                <vers num="2.8.0" />
                <vers num="2.8.1" />
                <vers num="2.8.10" />
                <vers num="2.8.2" />
                <vers num="2.8.3" />
                <vers num="2.8.4" />
                <vers num="2.8.5" />
                <vers num="2.8.6" />
                <vers num="2.8.7" />
                <vers num="2.8.8" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.10" />
                <vers num="4.2.11" />
                <vers num="4.2.12" />
                <vers num="4.2.13" />
                <vers num="4.2.14" />
                <vers num="4.2.15" />
                <vers num="4.2.16" />
                <vers num="4.2.2" />
                <vers num="4.2.3" />
                <vers num="4.3.0" />
                <vers num="4.3.1" />
                <vers num="4.3.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-2670" seq="2009-2670" severity="Medium" type="CVE" published="2009-08-05" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-27">
        <desc>
            <descript source="cve">The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html">TA09-294A</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263408-1" adv="1">263408</ref>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html">FEDORA-2009-8337</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html">FEDORA-2009-8329</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1201.html">RHSA-2009:1201</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1200.html">RHSA-2009:1200</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1199.html">RHSA-2009:1199</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/52306">jre-jdk-audiosystem-priv-escalation(52306)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2543">ADV-2009-2543</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022658">1022658</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35939">35939</ref>
            <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209">MDVSA-2009:209</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36248">36248</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36199">36199</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36180">36180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36176">36176</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36162">36162</ref>
            <ref source="OSVDB" url="http://osvdb.org/56788">56788</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html">SUSE-SA:2009:043</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html">APPLE-SA-2009-09-03-1</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u15.html">http://java.sun.com/javase/6/webnotes/6u15.html</ref>
            <ref source="CONFIRM" url="http://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20">http://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_19" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-2671" seq="2009-2671" severity="Medium" type="CVE" published="2009-08-05" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-27">
        <desc>
            <descript source="cve">The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover the username of the account that invoked an untrusted (1) applet or (2) Java Web Start application via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html">TA09-294A</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263409-1" adv="1">263409</ref>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html">FEDORA-2009-8337</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html">FEDORA-2009-8329</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1201.html">RHSA-2009:1201</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1200.html">RHSA-2009:1200</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1199.html">RHSA-2009:1199</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/52336">sun-jre-socks-info-disclosure(52336)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2543">ADV-2009-2543</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022659">1022659</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35943">35943</ref>
            <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209">MDVSA-2009:209</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36248">36248</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36199">36199</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36180">36180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36176">36176</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36162">36162</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html">SUSE-SA:2009:043</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html">APPLE-SA-2009-09-03-1</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u15.html">http://java.sun.com/javase/6/webnotes/6u15.html</ref>
            <ref source="CONFIRM" url="http://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20">http://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_19" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-2672" seq="2009-2672" severity="High" type="CVE" published="2009-08-05" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-27">
        <desc>
            <descript source="cve">The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html">TA09-294A</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263409-1" adv="1">263409</ref>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1201.html">RHSA-2009:1201</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1200.html">RHSA-2009:1200</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1199.html">RHSA-2009:1199</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/52337">sun-jre-proxy-session-hijacking(52337)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2543">ADV-2009-2543</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022659">1022659</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35943">35943</ref>
            <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36248">36248</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36199">36199</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36180">36180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36176">36176</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html">SUSE-SA:2009:043</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html">APPLE-SA-2009-09-03-1</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u15.html">http://java.sun.com/javase/6/webnotes/6u15.html</ref>
            <ref source="CONFIRM" url="http://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20">http://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_19" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-2673" seq="2009-2673" severity="High" type="CVE" published="2009-08-05" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-27">
        <desc>
            <descript source="cve">The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html">TA09-294A</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263409-1">263409</ref>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html">FEDORA-2009-8337</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html">FEDORA-2009-8329</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1201.html">RHSA-2009:1201</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1200.html">RHSA-2009:1200</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1199.html">RHSA-2009:1199</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/52338">sun-jre-proxy-security-bypass(52338)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2543">ADV-2009-2543</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022659">1022659</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35943">35943</ref>
            <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209">MDVSA-2009:209</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36248">36248</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36199">36199</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36180">36180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36176">36176</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36162">36162</ref>
            <ref source="OSVDB" url="http://osvdb.org/56785">56785</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html">SUSE-SA:2009:043</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html">APPLE-SA-2009-09-03-1</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u15.html">http://java.sun.com/javase/6/webnotes/6u15.html</ref>
            <ref source="CONFIRM" url="http://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20">http://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_19" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-2674" seq="2009-2674" severity="High" type="CVE" published="2009-08-05" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-27">
        <desc>
            <descript source="cve">Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html">TA09-294A</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263428-1" adv="1">263428</ref>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html">FEDORA-2009-8337</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html">FEDORA-2009-8329</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1201.html">RHSA-2009:1201</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1200.html">RHSA-2009:1200</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/52339">sun-jre-jpeg-bo(52339)</ref>
            <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-09-050/">http://www.zerodayinitiative.com/advisories/ZDI-09-050/</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2543">ADV-2009-2543</ref>
            <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209">MDVSA-2009:209</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36248">36248</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36180">36180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36176">36176</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36162">36162</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html">SUSE-SA:2009:043</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html">APPLE-SA-2009-09-03-1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_1" num="6" />
                <vers edition="update_10" num="6" />
                <vers edition="update_11" num="6" />
                <vers edition="update_12" num="6" />
                <vers edition="update_13" num="6" />
                <vers edition="update_2" num="6" />
                <vers edition="update_3" num="6" />
                <vers edition="update_4" num="6" />
                <vers edition="update_5" num="6" />
                <vers edition="update_6" num="6" />
                <vers edition="update_7" num="6" />
                <vers edition="update_8" num="6" />
                <vers edition="update_9" num="6" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update_1" num="6" />
                <vers edition="update_10" num="6" />
                <vers edition="update_11" num="6" />
                <vers edition="update_12" num="6" />
                <vers edition="update_13" num="6" />
                <vers edition="update_2" num="6" />
                <vers edition="update_3" num="6" />
                <vers edition="update_4" num="6" />
                <vers edition="update_5" num="6" />
                <vers edition="update_6" num="6" />
                <vers edition="update_7" num="6" />
                <vers edition="update_8" num="6" />
                <vers edition="update_9" num="6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-2675" seq="2009-2675" severity="High" type="CVE" published="2009-08-05" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-27">
        <desc>
            <descript source="cve">Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html">TA09-294A</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263488-1" adv="1">263488</ref>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html">FEDORA-2009-8337</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html">FEDORA-2009-8329</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1201.html">RHSA-2009:1201</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1200.html">RHSA-2009:1200</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1199.html">RHSA-2009:1199</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/52307">jre-pak200-bo(52307)</ref>
            <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-09-049/">http://www.zerodayinitiative.com/advisories/ZDI-09-049/</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2543">ADV-2009-2543</ref>
            <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209">MDVSA-2009:209</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36248">36248</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36199">36199</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36180">36180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36176">36176</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36162">36162</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html">SUSE-SA:2009:043</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html">APPLE-SA-2009-09-03-1</ref>
            <ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=814">20090804 Sun Java Runtime Environment (JRE) Pack200 Decompression Integer Overflow Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_19" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2009-2676" seq="2009-2676" severity="Medium" type="CVE" published="2009-08-05" CVSS_version="2.0" CVSS_score="6.8" modified="2009-10-27">
        <desc>
            <descript source="cve">Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html">TA09-294A</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263490-1" adv="1">263490</ref>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1200.html">RHSA-2009:1200</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1199.html">RHSA-2009:1199</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022657">1022657</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35946">35946</ref>
            <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36248">36248</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36199">36199</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36176">36176</ref>
            <ref source="OSVDB" url="http://osvdb.org/56789">56789</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html">SUSE-SA:2009:043</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="java_se">
                <vers edition=":business" num="" />
            </prod>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_19" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="sdk">
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" prev="1" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-2412" seq="2009-2412" severity="High" type="CVE" published="2009-08-06" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-31">
        <desc>
            <descript source="cve">Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows.  NOTE: some of these details are obtained from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/35949">35949</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00353.html">FEDORA-2009-8360</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00320.html">FEDORA-2009-8336</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-813-2">USN-813-2</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:195">MDVSA-2009:195</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc/apr/apr/branches/1.3.x/memory/unix/apr_pools.c?r1=678140&amp;r2=800732">http://svn.apache.org/viewvc/apr/apr/branches/1.3.x/memory/unix/apr_pools.c?r1=678140&amp;r2=800732</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc/apr/apr/branches/1.3.x/CHANGES?revision=800732&amp;view=markup">http://svn.apache.org/viewvc/apr/apr/branches/1.3.x/CHANGES?revision=800732&amp;view=markup</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc/apr/apr/branches/0.9.x/memory/unix/apr_pools.c?r1=585356&amp;r2=800733">http://svn.apache.org/viewvc/apr/apr/branches/0.9.x/memory/unix/apr_pools.c?r1=585356&amp;r2=800733</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc/apr/apr/branches/0.9.x/CHANGES?revision=800733&amp;view=markup">http://svn.apache.org/viewvc/apr/apr/branches/0.9.x/CHANGES?revision=800733&amp;view=markup</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc/apr/apr-util/branches/1.3.x/misc/apr_rmm.c?r1=647687&amp;r2=800735">http://svn.apache.org/viewvc/apr/apr-util/branches/1.3.x/misc/apr_rmm.c?r1=647687&amp;r2=800735</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc/apr/apr-util/branches/1.3.x/CHANGES?revision=800735&amp;view=markup">http://svn.apache.org/viewvc/apr/apr-util/branches/1.3.x/CHANGES?revision=800735&amp;view=markup</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc/apr/apr-util/branches/0.9.x/misc/apr_rmm.c?r1=230441&amp;r2=800736">http://svn.apache.org/viewvc/apr/apr-util/branches/0.9.x/misc/apr_rmm.c?r1=230441&amp;r2=800736</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc/apr/apr-util/branches/0.9.x/CHANGES?revision=800736&amp;view=markup">http://svn.apache.org/viewvc/apr/apr-util/branches/0.9.x/CHANGES?revision=800736&amp;view=markup</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37152">37152</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36233">36233</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36166">36166</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36140" adv="1">36140</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36138" adv="1">36138</ref>
            <ref source="OSVDB" url="http://osvdb.org/56766">56766</ref>
            <ref source="OSVDB" url="http://osvdb.org/56765">56765</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html">SUSE-SA:2009:050</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="apr-util">
                <vers num="0.9.1" />
                <vers num="0.9.16" />
                <vers num="0.9.2" />
                <vers num="0.9.2-dev" />
                <vers num="0.9.3" />
                <vers num="0.9.3-dev" />
                <vers num="0.9.4" />
                <vers num="0.9.5" />
                <vers num="0.9.6" />
                <vers num="0.9.7-dev" />
                <vers num="0.9.8" />
                <vers num="0.9.9" />
                <vers num="1.3.0" />
                <vers num="1.3.1" />
                <vers num="1.3.2" />
                <vers num="1.3.3" />
                <vers num="1.3.4" />
                <vers num="1.3.4-dev" />
                <vers num="1.3.5" />
                <vers num="1.3.6" />
                <vers num="1.3.6-dev" />
                <vers num="1.3.7" />
                <vers num="1.3.8" />
            </prod>
            <prod vendor="apache" name="portable_runtime">
                <vers num="0.9.1" />
                <vers num="0.9.16-dev" />
                <vers num="0.9.2" />
                <vers num="0.9.2-dev" />
                <vers num="0.9.3" />
                <vers num="0.9.3-dev" />
                <vers num="0.9.4" />
                <vers num="0.9.5" />
                <vers num="0.9.6" />
                <vers num="0.9.7" />
                <vers num="0.9.7-dev" />
                <vers num="0.9.8" />
                <vers num="0.9.9" />
                <vers num="1.3.0" />
                <vers num="1.3.1" />
                <vers num="1.3.2" />
                <vers num="1.3.3" />
                <vers num="1.3.4" />
                <vers num="1.3.4-dev" />
                <vers num="1.3.5" />
                <vers num="1.3.6" />
                <vers num="1.3.6-dev" />
                <vers num="1.3.7" />
                <vers num="1.3.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-2625" seq="2009-2625" severity="Medium" type="CVE" published="2009-08-06" CVSS_version="2.0" CVSS_score="5.0" modified="2009-11-06">
        <desc>
            <descript source="cve">XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html">TA09-294A</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263489-1" adv="1">263489</ref>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html">FEDORA-2009-8337</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html">FEDORA-2009-8329</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1201.html">RHSA-2009:1201</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1200.html">RHSA-2009:1200</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1199.html">RHSA-2009:1199</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2543">ADV-2009-2543</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022680">1022680</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35958">35958</ref>
            <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/10/26/3">[oss-security] 20091026 Re: CVE Request -- expat [was: Re: Regarding expat bug 1990430]</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/10/23/6">[oss-security] 20091023 Re: CVE Request -- expat [was: Re: Regarding expat bug 1990430]</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/10/22/9">[oss-security] 20091022 Re: Regarding expat bug 1990430</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/09/06/1">[oss-security] 20090906 Re: Re: expat bug 1990430</ref>
            <ref source="MISC" url="http://www.networkworld.com/columnists/2009/080509-xml-flaw.html">http://www.networkworld.com/columnists/2009/080509-xml-flaw.html</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209">MDVSA-2009:209</ref>
            <ref source="MISC" url="http://www.codenomicon.com/labs/xml/">http://www.codenomicon.com/labs/xml/</ref>
            <ref source="MISC" url="http://www.cert.fi/en/reports/2009/vulnerability2009085.html">http://www.cert.fi/en/reports/2009/vulnerability2009085.html</ref>
            <ref source="CONFIRM" url="http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=572055&amp;r2=787352&amp;pathrev=787353&amp;diff_format=h">http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=572055&amp;r2=787352&amp;pathrev=787353&amp;diff_format=h</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36199">36199</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36180">36180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36176">36176</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36162">36162</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html">APPLE-SA-2009-09-03-1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update_1" num="5.0" />
                <vers edition="update_10" num="5.0" />
                <vers edition="update_11" num="5.0" />
                <vers edition="update_12" num="5.0" />
                <vers edition="update_13" num="5.0" />
                <vers edition="update_14" num="5.0" />
                <vers edition="update_15" num="5.0" />
                <vers edition="update_16" num="5.0" />
                <vers edition="update_17" num="5.0" />
                <vers edition="update_19" num="5.0" />
                <vers edition="update_2" num="5.0" />
                <vers edition="update_3" num="5.0" />
                <vers edition="update_4" num="5.0" />
                <vers edition="update_5" num="5.0" />
                <vers edition="update_6" num="5.0" />
                <vers edition="update_7" num="5.0" />
                <vers edition="update_8" num="5.0" />
                <vers edition="update_9" num="5.0" />
                <vers edition="update_1" num="6" prev="1" />
                <vers edition="update_10" num="6" prev="1" />
                <vers edition="update_11" num="6" prev="1" />
                <vers edition="update_12" num="6" prev="1" />
                <vers edition="update_13" num="6" prev="1" />
                <vers edition="update_2" num="6" prev="1" />
                <vers edition="update_3" num="6" prev="1" />
                <vers edition="update_4" num="6" prev="1" />
                <vers edition="update_5" num="6" prev="1" />
                <vers edition="update_6" num="6" prev="1" />
                <vers edition="update_7" num="6" prev="1" />
                <vers edition="update_8" num="6" prev="1" />
                <vers edition="update_9" num="6" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" name="CVE-2009-2475" seq="2009-2475" severity="High" type="CVE" published="2009-08-10" CVSS_version="2.0" CVSS_score="7.8" modified="2009-10-27">
        <desc>
            <descript source="cve">Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents, (4) ImageReaderSpi.STANDARD_INPUT_TYPE, (5) ImageWriterSpi.STANDARD_OUTPUT_TYPE, (6) the imageio plugins, (7) DnsContext.debug, (8) RmfFileReader/StandardMidiFileWriter.types, (9) AbstractSaslImpl.logger, (10) Synth.Region.uiToRegionMap/lowerCaseNameMap, (11) the Introspector class and a cache of BeanInfo, and (12) JAX-WS, a different vulnerability than CVE-2009-2673.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1</ref>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html">FEDORA-2009-8337</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html">FEDORA-2009-8329</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1201.html">RHSA-2009:1201</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1200.html">RHSA-2009:1200</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1199.html">RHSA-2009:1199</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=513215">https://bugzilla.redhat.com/show_bug.cgi?id=513215</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2543">ADV-2009-2543</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209">MDVSA-2009:209</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36199" adv="1">36199</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36180" adv="1">36180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36176" adv="1">36176</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36162" adv="1">36162</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html">APPLE-SA-2009-09-03-1</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u15.html">http://java.sun.com/javase/6/webnotes/6u15.html</ref>
            <ref source="CONFIRM" url="http://java.sun.com/j2se/1.5.0/ReleaseNotes.html" adv="1">http://java.sun.com/j2se/1.5.0/ReleaseNotes.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="java_se">
                <vers edition="20" num="5.0" prev="1" />
                <vers edition="14" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="openjdk">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-2476" seq="2009-2476" severity="High" type="CVE" published="2009-08-10" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-27">
        <desc>
            <descript source="cve">The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html">FEDORA-2009-8337</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html">FEDORA-2009-8329</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1201.html">RHSA-2009:1201</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1200.html">RHSA-2009:1200</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=513220">https://bugzilla.redhat.com/show_bug.cgi?id=513220</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2543">ADV-2009-2543</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209">MDVSA-2009:209</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36180" adv="1">36180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36176" adv="1">36176</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36162" adv="1">36162</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html">APPLE-SA-2009-09-03-1</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u15.html" adv="1">http://java.sun.com/javase/6/webnotes/6u15.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="java_se">
                <vers edition="14" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="openjdk">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-2689" seq="2009-2689" severity="High" type="CVE" published="2009-08-10" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-27">
        <desc>
            <descript source="cve">JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1</ref>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1</ref>
            <ref source="CONFIRM" patch="1" url="http://java.sun.com/j2se/1.5.0/ReleaseNotes.html">http://java.sun.com/j2se/1.5.0/ReleaseNotes.html</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html">FEDORA-2009-8337</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html">FEDORA-2009-8329</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1201.html">RHSA-2009:1201</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1199.html">RHSA-2009:1199</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=513222">https://bugzilla.redhat.com/show_bug.cgi?id=513222</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2543">ADV-2009-2543</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209">MDVSA-2009:209</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36199" adv="1">36199</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36180" adv="1">36180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36162" adv="1">36162</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html">APPLE-SA-2009-09-03-1</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u15.html">http://java.sun.com/javase/6/webnotes/6u15.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="java_se">
                <vers edition="20" num="5.0" prev="1" />
                <vers edition="14" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="openjdk">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-2690" seq="2009-2690" severity="Medium" type="CVE" published="2009-08-10" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-27">
        <desc>
            <descript source="cve">The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-dependent attackers to obtain sensitive information via an untrusted (1) applet or (2) application.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html">FEDORA-2009-8337</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html">FEDORA-2009-8329</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1201.html">RHSA-2009:1201</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1200.html">RHSA-2009:1200</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=513223">https://bugzilla.redhat.com/show_bug.cgi?id=513223</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2543">ADV-2009-2543</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209">MDVSA-2009:209</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36180" adv="1">36180</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36176" adv="1">36176</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36162" adv="1">36162</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html">SUSE-SR:2009:016</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html">APPLE-SA-2009-09-03-1</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u15.html" adv="1">http://java.sun.com/javase/6/webnotes/6u15.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="java_se">
                <vers edition="14" num="6" prev="1" />
            </prod>
            <prod vendor="sun" name="openjdk">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2009-2691" seq="2009-2691" severity="Low" type="CVE" published="2009-08-14" CVSS_version="2.0" CVSS_score="2.1" modified="2009-11-06">
        <desc>
            <descript source="cve">The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MLIST" patch="1" url="http://marc.info/?l=linux-kernel&amp;m=124718949821250">[linux-kernel] 20090710 [PATCH 2/2] mm_for_maps: take ->cred_guard_mutex to fix the race</ref>
            <ref source="MLIST" patch="1" url="http://marc.info/?l=linux-kernel&amp;m=124718946021193">[linux-kernel] 20090710 [PATCH 1/2] mm_for_maps: shift down_read(mmap_sem) to the caller</ref>
            <ref source="MLIST" patch="1" url="http://lkml.org/lkml/2009/6/23/653">[linux-kernel] 20090623 [PATCH 1/1] mm_for_maps: simplify, use ptrace_may_access()</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01256.html">FEDORA-2009-9044</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1540.html">RHSA-2009:1540</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=516171">https://bugzilla.redhat.com/show_bug.cgi?id=516171</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/52401">linux-kernel-mmformaps-info-disclosure(52401)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2246" adv="1">ADV-2009-2246</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36019">36019</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/08/11/1">[oss-security] 20090811 CVE-2009-2691 kernel: /proc/$pid/maps visible during initial setuid ELF loading</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36501">36501</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36265" adv="1">36265</ref>
            <ref source="MLIST" url="http://lkml.org/lkml/2009/6/23/652">[linux-kernel] 20090623 [PATCH 0/1] mm_for_maps: simplify, use ptrace_may_access()</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=704b836cbf19e885f8366bccb2e4b0474346c02d">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=704b836cbf19e885f8366bccb2e4b0474346c02d</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=13f0feafa6b8aead57a2a328e2fca6a5828bf286">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=13f0feafa6b8aead57a2a328e2fca6a5828bf286</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=00f89d218523b9bf6b522349c039d5ac80aa536d">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=00f89d218523b9bf6b522349c039d5ac80aa536d</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers edition="rc1" num="2.6.30" />
                <vers edition="rc2" num="2.6.30" />
                <vers edition="rc3" num="2.6.30" />
                <vers edition="rc5" num="2.6.30" />
                <vers edition="rc6" num="2.6.30" />
                <vers edition="rc7-git6" num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.4" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2009-2692" seq="2009-2692" severity="High" type="CVE" published="2009-08-14" CVSS_version="2.0" CVSS_score="7.2" modified="2009-10-27">
        <desc>
            <descript source="cve">The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/2272" adv="1">ADV-2009-2272</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-3103">https://issues.rpath.com/browse/RPL-3103</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=516949">https://bugzilla.redhat.com/show_bug.cgi?id=516949</ref>
            <ref source="MISC" url="http://zenthought.org/content/file/android-root-2009-08-16-source">http://zenthought.org/content/file/android-root-2009-08-16-source</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36038">36038</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/505912/100/0/threaded">20090818 rPSA-2009-0121-1 kernel open-vm-tools</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/505751/100/0/threaded">20090813 Linux NULL pointer dereference due to incorrect proto_ops initializations</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1233.html">RHSA-2009:1233</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/08/14/1">[oss-security] 20090814 CVE-2009-2692 kernel: uninit op in SOCKOPS_WRAP() leads to privesc</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9477">9477</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc6" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.31-rc6</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.5" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.5</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.37.5" adv="1">http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.37.5</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0121">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0121</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36430" adv="1">36430</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36327" adv="1">36327</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36289" adv="1">36289</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36278" adv="1">36278</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2009-1223.html">RHSA-2009:1223</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2009-1222.html">RHSA-2009:1222</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html">SUSE-SR:2009:015</ref>
            <ref source="MISC" url="http://grsecurity.net/~spender/wunderbar_emporium.tgz">http://grsecurity.net/~spender/wunderbar_emporium.tgz</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e694958388c50148389b0e9b9e9e8945cf0f1b98">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e694958388c50148389b0e9b9e9e8945cf0f1b98</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.4.37.y.git;a=commit;h=c18d0fe535a73b219f960d1af3d0c264555a12e3">http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.4.37.y.git;a=commit;h=c18d0fe535a73b219f960d1af3d0c264555a12e3</ref>
            <ref source="MISC" url="http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html">http://blog.cr0.org/2009/08/linux-null-pointer-dereference-due-to.html</ref>
            <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2009-08/0174.html">20090813 Linux NULL pointer dereference due to incorrect proto_ops initializations</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.24.7" />
                <vers num="2.6.25.15" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition=":pre-2" num="2.4.18" />
                <vers edition=":pre-3" num="2.4.18" />
                <vers edition=":pre-1" num="2.4.18" />
                <vers edition=":pre-7" num="2.4.18" />
                <vers edition=":pre-6" num="2.4.18" />
                <vers edition=":pre-5" num="2.4.18" />
                <vers edition=":pre-4" num="2.4.18" />
                <vers edition=":pre-8" num="2.4.18" />
                <vers edition="" num="2.4.19" />
                <vers edition=":-pre1" num="2.4.19" />
                <vers edition=":-pre2" num="2.4.19" />
                <vers edition=":-pre5" num="2.4.19" />
                <vers edition=":-pre6" num="2.4.19" />
                <vers edition=":-pre3" num="2.4.19" />
                <vers edition=":-pre4" num="2.4.19" />
                <vers num="2.4.20" />
                <vers edition="" num="2.4.21" />
                <vers edition=":-pre1" num="2.4.21" />
                <vers edition=":-pre4" num="2.4.21" />
                <vers edition=":-pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="" num="2.4.23" />
                <vers edition=":-ow2" num="2.4.23" />
                <vers edition=":-pre9" num="2.4.23" />
                <vers edition="" num="2.4.24" />
                <vers edition=":-ow1" num="2.4.24" />
                <vers num="2.4.25" />
                <vers num="2.4.26" />
                <vers edition="" num="2.4.27" />
                <vers edition=":-pre1" num="2.4.27" />
                <vers edition=":-pre2" num="2.4.27" />
                <vers edition=":-pre3" num="2.4.27" />
                <vers edition=":-pre4" num="2.4.27" />
                <vers edition=":-pre5" num="2.4.27" />
                <vers num="2.4.28" />
                <vers edition="-rc1" num="2.4.29" />
                <vers edition="-rc2" num="2.4.29" />
                <vers edition="rc2" num="2.4.30" />
                <vers edition="rc3" num="2.4.30" />
                <vers edition="-pre1" num="2.4.31" />
                <vers edition="-pre1" num="2.4.32" />
                <vers edition="-pre2" num="2.4.32" />
                <vers edition="p-re1" num="2.4.33" />
                <vers num="2.4.33.2" />
                <vers num="2.4.33.3" />
                <vers num="2.4.33.4" />
                <vers num="2.4.33.5" />
                <vers num="2.4.33.7" />
                <vers num="2.4.34" />
                <vers num="2.4.35.3" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.4.36.7" />
                <vers num="2.4.36.8" />
                <vers edition="-rc1" num="2.4.37" />
                <vers num="2.4.37.1" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers num="2.6" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers edition="rc1" num="2.6.30" />
                <vers edition="rc2" num="2.6.30" />
                <vers edition="rc3" num="2.6.30" />
                <vers edition="rc5" num="2.6.30" />
                <vers edition="rc6" num="2.6.30" />
                <vers edition="rc7-git6" num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_base_score="4.7" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.9" name="CVE-2009-2848" seq="2009-2848" severity="Medium" type="CVE" published="2009-08-18" CVSS_version="2.0" CVSS_score="4.7" modified="2009-11-06">
        <desc>
            <descript source="cve">The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01256.html">FEDORA-2009-9044</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1550.html">RHSA-2009:1550</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/52899">kernel-execve-dos(52899)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1438.html">RHSA-2009:1438</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/08/05/10">[oss-security] 20090805 Re: CVE request - kernel: execve: must clear current->clear_child_tid</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/08/04/2">[oss-security] 20090804 CVE request - kernel: execve: must clear current->clear_child_tid</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36759">36759</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36501" adv="1">36501</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35983" adv="1">35983</ref>
            <ref source="MLIST" url="http://article.gmane.org/gmane.linux.kernel/871942">[linux-kernel] 20090801 [PATCH v2] execve: must clear current->clear_child_tid</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.6" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.22_rc1" />
                <vers num="2.6.22_rc7" />
                <vers edition="rc1" num="2.6.23" />
                <vers edition="rc2" num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers edition="rc1" num="2.6.24" />
                <vers edition="rc2" num="2.6.24" />
                <vers edition="rc3" num="2.6.24" />
                <vers edition="rc4" num="2.6.24" />
                <vers edition="rc5" num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers edition="rc4" num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers edition="rc1" num="2.6.27" />
                <vers edition="rc2" num="2.6.27" />
                <vers edition="rc3" num="2.6.27" />
                <vers edition="rc4" num="2.6.27" />
                <vers edition="rc5" num="2.6.27" />
                <vers edition="rc6" num="2.6.27" />
                <vers edition="rc7" num="2.6.27" />
                <vers edition="rc8" num="2.6.27" />
                <vers edition="rc9" num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers edition="rc1" num="2.6.28" />
                <vers edition="rc2" num="2.6.28" />
                <vers edition="rc3" num="2.6.28" />
                <vers edition="rc4" num="2.6.28" />
                <vers edition="rc5" num="2.6.28" />
                <vers edition="rc6" num="2.6.28" />
                <vers edition="rc7" num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers edition="git1" num="2.6.29" />
                <vers edition="rc1" num="2.6.29" />
                <vers edition="rc2" num="2.6.29" />
                <vers edition="rc2_git7" num="2.6.29" />
                <vers edition="rc8-kk" num="2.6.29" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.5" />
                <vers edition="rc1" num="2.6.30" prev="1" />
                <vers edition="rc2" num="2.6.30" prev="1" />
                <vers edition="rc3" num="2.6.30" prev="1" />
                <vers edition="rc4" num="2.6.30" prev="1" />
                <vers edition="rc4:x86_32" num="2.6.30" prev="1" />
                <vers edition="rc5" num="2.6.30" prev="1" />
                <vers edition="rc6" num="2.6.30" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_base_score="4.7" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.9" name="CVE-2009-2849" seq="2009-2849" severity="Medium" type="CVE" published="2009-08-18" CVSS_version="2.0" CVSS_score="4.7" modified="2009-11-06">
        <desc>
            <descript source="cve">The md driver (drivers/md/md.c) in the Linux kernel before 2.6.30.2 might allow local users to cause a denial of service (NULL pointer dereference) via vectors related to "suspend_* sysfs attributes" and the (1) suspend_lo_store or (2) suspend_hi_store functions.  NOTE: this is only a vulnerability when sysfs is writable by an attacker.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01256.html">FEDORA-2009-9044</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1540.html">RHSA-2009:1540</ref>
            <ref source="MISC" url="http://xorl.wordpress.com/2009/07/21/linux-kernel-md-driver-null-pointer-dereference/">http://xorl.wordpress.com/2009/07/21/linux-kernel-md-driver-null-pointer-dereference/</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/52858">kernel-mddriver-dos(52858)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022961">1022961</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/07/26/1">[oss-security] 20090726 Re: md raid null ptr dereference (when sysfs is writable)</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/07/24/1">[oss-security] 20090724 md raid null ptr dereference (when sysfs is writable)</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.2">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.2</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36501">36501</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.30.y.git;a=commit;h=3c92900d9a4afb176d3de335dc0da0198660a244">http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.30.y.git;a=commit;h=3c92900d9a4afb176d3de335dc0da0198660a244</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.20" />
                <vers num=