<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" nvd_xml_version="1.2" pub_date="2010-02-09" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-1999-0001" seq="1999-0001" severity="Medium" type="CVE" published="1999-12-30" CVSS_version="2.0" CVSS_score="5.0" modified="2010-01-22">
        <desc>
            <descript source="cve">ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="OSVDB" url="http://www.osvdb.org/5707">5707</ref>
            <ref source="CONFIRM" url="http://www.openbsd.org/errata23.html#tcpfix">http://www.openbsd.org/errata23.html#tcpfix</ref>
        </refs>
        <vuln_soft>
            <prod vendor="bsdi" name="bsd_os">
                <vers num="3.1" />
            </prod>
            <prod vendor="freebsd" name="freebsd">
                <vers num="1.0" />
                <vers num="1.1" />
                <vers num="1.1.5.1" />
                <vers num="1.2" />
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.0.5" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.6.1" />
                <vers num="2.1.7" />
                <vers num="2.1.7.1" />
                <vers num="2.2" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.8" />
                <vers num="3.0" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="2.3" />
                <vers num="2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2002-0164" seq="2002-0164" severity="Medium" type="CVE" published="2002-03-15" CVSS_version="2.0 incomplete approximation" CVSS_score="4.6" modified="2010-01-28">
        <desc>
            <descript source="cve">Vulnerability in the MIT-SHM extension of the X server on Linux (XFree86) 4.2.1 and earlier allows local users to read and write arbitrary shared memory, possibly to cause a denial of service or gain privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/8706">xfree86-mitshm-memory-access(8706)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/4396">4396</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-067.html">RHSA-2003:067</ref>
            <ref source="CALDERA" url="http://www.linuxsecurity.com/advisories/caldera_advisory-2006.html">CSSA-2002-009.0</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-380">DSA-380</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-228529-1">228529</ref>
            <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.14/CSSA-2002-SCO.14.txt">CSSA-2002-SCO.14</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20021001-01-P">20021001-01-P</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=103547625009363&amp;w=2">20021024 GLSA: xfree</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000529">CLSA-2002:529</ref>
        </refs>
        <vuln_soft>
            <prod vendor="caldera" name="openlinux_server">
                <vers num="3.1" />
                <vers num="3.1.1" />
            </prod>
            <prod vendor="caldera" name="openlinux_workstation">
                <vers num="3.1" />
                <vers num="3.1.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" name="CVE-2001-1409" seq="2001-1409" severity="Low" type="CVE" published="2003-07-24" CVSS_version="2.0 incomplete approximation" CVSS_score="3.6" modified="2010-01-28">
        <desc>
            <descript source="cve">dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
            <config />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-067.html" adv="1">RHSA-2003:067</ref>
            <ref source="CONFIRM" patch="1" url="http://groups.google.com/groups?selm=20010829121505.A16004%40compusol.com.au" adv="1">http://groups.google.com/groups?selm=20010829121505.A16004%40compusol.com.au</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-228529-1">228529</ref>
        </refs>
        <vuln_soft>
            <prod vendor="xfree86_project" name="xfree86_x_server">
                <vers num="4.1.0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0498" seq="2003-0498" severity="High" type="CVE" published="2003-08-07" CVSS_version="2.0" CVSS_score="7.2" modified="2010-02-09">
        <desc>
            <descript source="cve">Cach�Ã�© Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="intersystems" name="cache_database">
                <vers num="5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2003-0497" seq="2003-0497" severity="High" type="CVE" published="2003-08-07" CVSS_version="2.0" CVSS_score="7.2" modified="2010-02-09">
        <desc>
            <descript source="cve">Cach�Ã�© Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs />
        <vuln_soft>
            <prod vendor="intersystems" name="cache_database">
                <vers num="5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0544" seq="2003-0544" severity="Medium" type="CVE" published="2003-11-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2010-01-28">
        <desc>
            <descript source="cve">OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/380864">VU#380864</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-26.html">CA-2003-26</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-292.html" adv="1">RHSA-2003:292</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-291.html" adv="1">RHSA-2003:291</ref>
            <ref source="MISC" url="http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm">http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm</ref>
            <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3693.html">ESA-20030930-027</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-394">DSA-394</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-393">DSA-393</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201029-1">201029</ref>
            <ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43041">openssl-asn1-sslclient-dos(43041)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/8732">8732</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3900">ADV-2006-3900</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21247112">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22249">22249</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4574" sig="1">oval:org.mitre.oval:def:4574</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openssl" name="openssl">
                <vers num="0.9.6" />
                <vers num="0.9.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-0543" seq="2003-0543" severity="Medium" type="CVE" published="2003-11-17" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2010-01-28">
        <desc>
            <descript source="cve">Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input bound="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/255484">VU#255484</ref>
            <ref source="CERT" url="http://www.cert.org/advisories/CA-2003-26.html">CA-2003-26</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2003-291.html" adv="1">RHSA-2003:291</ref>
            <ref source="MISC" url="http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm">http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-292.html">RHSA-2003:292</ref>
            <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/engarde_advisory-3693.html">ESA-20030930-027</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-394">DSA-394</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-393">DSA-393</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201029-1">201029</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5292">oval:org.mitre.oval:def:5292</ref>
            <ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893" adv="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/8732">8732</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3900">ADV-2006-3900</ref>
            <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=swg21247112">http://www-1.ibm.com/support/docview.wss?uid=swg21247112</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22249">22249</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4254" sig="1">oval:org.mitre.oval:def:4254</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openssl" name="openssl">
                <vers num="0.9.6" />
                <vers num="0.9.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2003-1344" seq="2003-1344" severity="Medium" type="CVE" published="2003-12-31" CVSS_version="2.0" CVSS_score="5.0" modified="2010-02-02">
        <desc>
            <descript source="cve">Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive information via a URL request for getservers.exe with the action parameter set to "selects1", which returns log files.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11063">trend-vcs-weak-encryption(11063)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/6618">6618</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/7881" adv="1">7881</ref>
            <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0021.html">20030114 RE: [VulnWatch] Assorted Trend Vulns Rev 2.0</ref>
        </refs>
        <vuln_soft>
            <prod vendor="trend_micro" name="virus_control_system">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2004-1774" seq="2004-1774" severity="High" type="CVE" published="2004-08-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.2" modified="2010-02-06">
        <desc>
            <descript source="cve">Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.securiteam.com/securitynews/5CP010KE0W.html" adv="1">http://www.securiteam.com/securitynews/5CP010KE0W.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20078">oracle-mdsysmd2sdocodesize-bo(20078)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/13145" adv="1">13145</ref>
            <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf" adv="1">http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf</ref>
            <ref source="MISC" url="http://www.frsirt.com/exploits/20050413.OracleExploit.sql.php">http://www.frsirt.com/exploits/20050413.OracleExploit.sql.php</ref>
            <ref source="MISC" url="http://www.appsecinc.com/resources/alerts/oracle/2004-0001/">http://www.appsecinc.com/resources/alerts/oracle/2004-0001/</ref>
            <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/025984.html" adv="1">20040902 [SHATTER Team Security Alert] Multiple vulnerabilities in Oracle Database Server</ref>
        </refs>
        <vuln_soft>
            <prod vendor="oracle" name="application_server">
                <vers num="10.1.0.2" />
            </prod>
            <prod vendor="oracle" name="oracle10g">
                <vers num="enterprise_10.1.0.2" />
                <vers num="personal_10.1.0.2" />
                <vers num="standard_10.1.0.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0827" seq="2004-0827" severity="High" type="CVE" published="2004-09-16" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2010-01-28">
        <desc>
            <descript source="cve">Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-494.html" adv="1">RHSA-2004:494</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-480.html" adv="1">RHSA-2004:480</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-547" adv="1">DSA-547</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17173" adv="1">imagemagick-bmp-Bo(17173)</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201006-1">201006</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/0412">ADV-2008-0412</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1">231321</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28800">28800</ref>
        </refs>
        <vuln_soft>
            <prod vendor="enlightenment" name="imlib">
                <vers num="1.9" />
                <vers num="1.9.1" />
                <vers num="1.9.10" />
                <vers num="1.9.11" />
                <vers num="1.9.12" />
                <vers num="1.9.13" />
                <vers num="1.9.14" />
                <vers num="1.9.2" />
                <vers num="1.9.3" />
                <vers num="1.9.4" />
                <vers num="1.9.5" />
                <vers num="1.9.6" />
                <vers num="1.9.7" />
                <vers num="1.9.8" />
                <vers num="1.9.9" />
            </prod>
            <prod vendor="enlightenment" name="imlib2">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.1" />
                <vers num="1.1.1" />
            </prod>
            <prod vendor="imagemagick" name="imagemagick">
                <vers num="5.3.3" />
                <vers num="5.4.3" />
                <vers num="5.4.4.5" />
                <vers num="5.4.7" />
                <vers num="5.4.8" />
                <vers num="5.4.8.2.1.1.0" />
                <vers num="5.5.3.2.1.2.0" />
                <vers num="5.5.6.0_2003-04-09" />
                <vers num="5.5.7" />
                <vers num="6.0.2" />
            </prod>
            <prod vendor="sun" name="java_desktop_system">
                <vers num="2.0" />
                <vers num="2003" />
            </prod>
            <prod vendor="conectiva" name="linux">
                <vers num="10.0" />
                <vers num="9.0" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux">
                <vers edition="" num="10.0" />
                <vers edition=":amd64" num="10.0" />
                <vers edition="" num="9.2" />
                <vers edition=":amd64" num="9.2" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
                <vers edition="" num="2.1" />
                <vers edition=":x86_64" num="2.1" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="2.1" />
                <vers edition=":advanced_server_ia64" num="2.1" />
                <vers edition=":enterprise_server_ia64" num="2.1" />
                <vers edition=":advanced_server" num="2.1" />
                <vers edition=":workstation_ia64" num="2.1" />
                <vers edition=":workstation" num="2.1" />
                <vers edition=":enterprise_server" num="2.1" />
                <vers edition="" num="3.0" />
                <vers edition=":workstation_server" num="3.0" />
                <vers edition=":advanced_server" num="3.0" />
                <vers edition=":enterprise_server" num="3.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="3.0" />
            </prod>
            <prod vendor="redhat" name="fedora_core">
                <vers num="core_1.0" />
                <vers num="core_2.0" />
                <vers num="core_3.0" />
            </prod>
            <prod vendor="redhat" name="linux_advanced_workstation">
                <vers edition="" num="2.1" />
                <vers edition=":ia64" num="2.1" />
                <vers edition=":itanium_processor" num="2.1" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers edition="" num="8.0" />
                <vers edition=":i386" num="8.0" />
                <vers num="8.1" />
                <vers num="8.2" />
                <vers edition="" num="9.0" />
                <vers edition=":x86_64" num="9.0" />
                <vers num="9.1" />
                <vers num="9.2" />
            </prod>
            <prod vendor="turbolinux" name="turbolinux">
                <vers num="desktop_10.0" />
                <vers num="server_7.0" />
                <vers num="server_8.0" />
                <vers num="workstation_7.0" />
                <vers num="workstation_8.0" />
            </prod>
            <prod vendor="ubuntu" name="ubuntu_linux">
                <vers edition="" num="4.1" />
                <vers edition=":ppc" num="4.1" />
                <vers edition=":ia64" num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0693" seq="2004-0693" severity="Medium" type="CVE" published="2004-09-28" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2010-01-28">
        <desc>
            <descript source="cve">The GIF parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0692.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/17042" adv="1">qt-gif-dos(17042)</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200408-20.xml" adv="1">GLSA-200408-20</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-414.html">RHSA-2004:414</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_27_qt3.html">SUSE-SA:2004:027</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-542">DSA-542</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201610-1">201610</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:085">MDKSA-2004:085</ref>
        </refs>
        <vuln_soft>
            <prod vendor="trolltech" name="qt">
                <vers num="3.3.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2004-0692" seq="2004-0692" severity="Medium" type="CVE" published="2004-09-28" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2010-01-28">
        <desc>
            <descript source="cve">The XPM parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0693.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/17041" adv="1">qt-xpm-dos(17041)</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200408-20.xml" adv="1">GLSA-200408-20</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-414.html">RHSA-2004:414</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_27_qt3.html">SUSE-SA:2004:027</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-542">DSA-542</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201610-1">201610</ref>
            <ref source="FEDORA" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979666528890&amp;w=2">FLSA:2314</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:085">MDKSA-2004:085</ref>
        </refs>
        <vuln_soft>
            <prod vendor="trolltech" name="qt">
                <vers num="3.3.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0691" seq="2004-0691" severity="High" type="CVE" published="2004-09-28" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2010-01-28">
        <desc>
            <descript source="cve">Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/17040" adv="1">qt-bmp-bo(17040)</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-414.html" adv="1">RHSA-2004:414</ref>
            <ref source="GENTOO" patch="1" url="http://security.gentoo.org/glsa/glsa-200408-20.xml" adv="1">GLSA-200408-20</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_27_qt3.html">SUSE-SA:2004:027</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-542">DSA-542</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201610-1">201610</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109295309008309&amp;w=2">20040818 CESA-2004-004: qt</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:085">MDKSA-2004:085</ref>
        </refs>
        <vuln_soft>
            <prod vendor="trolltech" name="qt">
                <vers num="3.3.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0815" seq="2004-0815" severity="High" type="CVE" published="2004-11-03" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2010-01-28">
        <desc>
            <descript source="cve">The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via "/.////" style sequences in pathnames.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <vuln_types>
            <access />
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/11281" adv="1">11281</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-600" adv="1">DSA-600</ref>
            <ref source="BUGTRAQ" patch="1" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109655827913457&amp;w=2" adv="1">20040930 Samba Security Announcement -- Potential Arbitrary File Access</ref>
            <ref source="CONECTIVA" patch="1" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000873" adv="1">CLA-2004:873</ref>
            <ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2102">FLSA:2102</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17556">samba-file-access(17556)</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2004/0051/">2004-0051</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2004_35_samba.html">SUSE-SA:2004:035</ref>
            <ref source="MANDRAKE" url="http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:104">MDKSA-2004:104</ref>
            <ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=146&amp;type=vulnerabilities&amp;flashstatus=true" adv="1">20040930 Samba Arbitrary File Access Vulnerability</ref>
            <ref source="CONFIRM" url="http://us4.samba.org/samba/news/#security_2.2.12">http://us4.samba.org/samba/news/#security_2.2.12</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200529-1">200529</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/377618">20041005 ERRATA: Potential Arbitrary File Access (CAN-2004-0815)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-498.html">RHSA-2004:498</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57664-1">57664</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101584-1">101584</ref>
        </refs>
        <vuln_soft>
            <prod vendor="samba" name="samba">
                <vers num="2.2.0" />
                <vers num="2.2.0a" />
                <vers num="2.2.11" />
                <vers num="2.2.1a" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.3a" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.7a" />
                <vers num="2.2.8" />
                <vers num="2.2.8a" />
                <vers num="2.2.9" />
                <vers num="2.2a" />
                <vers num="3.0" />
                <vers num="3.0.0" />
                <vers num="3.0.1" />
                <vers num="3.0.2" />
                <vers num="3.0.2a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2004-0817" seq="2004-0817" severity="High" type="CVE" published="2004-12-31" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2010-01-28">
        <desc>
            <descript source="cve">Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/17182">imlib-bmp-bo(17182)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/11084">11084</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2004-465.html" adv="1">RHSA-2004:465</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200409-12.xml" adv="1">GLSA-200409-12</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2004/dsa-548" adv="1">DSA-548</ref>
            <ref source="CONECTIVA" patch="1" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000870">CLA-2004:870</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201611-1">201611</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2004:089">MDKSA-2004:089</ref>
        </refs>
        <vuln_soft>
            <prod vendor="enlightenment" name="imlib">
                <vers num="1.9" />
                <vers num="1.9.1" />
                <vers num="1.9.10" />
                <vers num="1.9.11" />
                <vers num="1.9.12" />
                <vers num="1.9.13" />
                <vers num="1.9.14" />
                <vers num="1.9.2" />
                <vers num="1.9.3" />
                <vers num="1.9.4" />
                <vers num="1.9.5" />
                <vers num="1.9.6" />
                <vers num="1.9.7" />
                <vers num="1.9.8" />
                <vers num="1.9.9" />
            </prod>
            <prod vendor="enlightenment" name="imlib2">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.1" />
                <vers num="1.1.1" />
            </prod>
            <prod vendor="imagemagick" name="imagemagick">
                <vers num="5.3.3" />
                <vers num="5.4.3" />
                <vers num="5.4.4.5" />
                <vers num="5.4.7" />
                <vers num="5.4.8" />
                <vers num="5.4.8.2.1.1.0" />
                <vers num="5.5.3.2.1.2.0" />
                <vers num="5.5.6.0_2003-04-09" />
                <vers num="5.5.7" />
                <vers num="6.0.2" />
            </prod>
            <prod vendor="sun" name="java_desktop_system">
                <vers num="2.0" />
                <vers num="2003" />
            </prod>
            <prod vendor="conectiva" name="linux">
                <vers num="10.0" />
                <vers num="9.0" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux">
                <vers edition="" num="10.0" />
                <vers edition=":amd64" num="10.0" />
                <vers edition="" num="9.2" />
                <vers edition=":amd64" num="9.2" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
                <vers edition="" num="2.1" />
                <vers edition=":x86_64" num="2.1" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="2.1" />
                <vers edition=":advanced_server_ia64" num="2.1" />
                <vers edition=":enterprise_server_ia64" num="2.1" />
                <vers edition=":advanced_server" num="2.1" />
                <vers edition=":workstation_ia64" num="2.1" />
                <vers edition=":workstation" num="2.1" />
                <vers edition=":enterprise_server" num="2.1" />
                <vers edition="" num="3.0" />
                <vers edition=":advanced_servers" num="3.0" />
                <vers edition=":workstation" num="3.0" />
                <vers edition=":enterprise_server" num="3.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="3.0" />
            </prod>
            <prod vendor="redhat" name="fedora_core">
                <vers num="core_1.0" />
                <vers num="core_2.0" />
                <vers num="core_3.0" />
            </prod>
            <prod vendor="redhat" name="linux_advanced_workstation">
                <vers edition="" num="2.1" />
                <vers edition=":ia64" num="2.1" />
                <vers edition=":itanium_processor" num="2.1" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers edition="" num="8.0" />
                <vers edition=":i386" num="8.0" />
                <vers num="8.1" />
                <vers num="8.2" />
                <vers edition="" num="9.0" />
                <vers edition=":x86_64" num="9.0" />
                <vers num="9.1" />
                <vers num="9.2" />
            </prod>
            <prod vendor="turbolinux" name="turbolinux_desktop">
                <vers num="10.0" />
            </prod>
            <prod vendor="turbolinux" name="turbolinux_server">
                <vers num="7.0" />
                <vers num="8.0" />
            </prod>
            <prod vendor="turbolinux" name="turbolinux_workstation">
                <vers num="7.0" />
                <vers num="8.0" />
            </prod>
            <prod vendor="ubuntu" name="ubuntu_linux">
                <vers edition="" num="4.1" />
                <vers edition=":ppc" num="4.1" />
                <vers edition=":ia64" num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" name="CVE-2004-0802" seq="2004-0802" severity="Medium" type="CVE" published="2004-12-31" CVSS_version="2.0 incomplete approximation" CVSS_score="5.1" modified="2010-01-28">
        <desc>
            <descript source="cve">Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" patch="1" url="http://xforce.iss.net/xforce/xfdb/17183">imlib2-bmp-bo(17183)</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/11084">11084</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200409-12.xml" adv="1">GLSA-200409-12</ref>
            <ref source="CONECTIVA" patch="1" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000870">CLA-2004:870</ref>
            <ref source="CONFIRM" url="http://www.vuxml.org/freebsd/ba005226-fb5b-11d8-9837-000c41e2cdad.html" adv="1">http://www.vuxml.org/freebsd/ba005226-fb5b-11d8-9837-000c41e2cdad.html</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201611-1">201611</ref>
            <ref source="MISC" url="http://cvs.sourceforge.net/viewcvs.py/enlightenment/e17/libs/imlib2/ChangeLog?rev=1.20&amp;view=markup">http://cvs.sourceforge.net/viewcvs.py/enlightenment/e17/libs/imlib2/ChangeLog?rev=1.20&amp;view=markup</ref>
        </refs>
        <vuln_soft>
            <prod vendor="enlightenment" name="imlib">
                <vers num="1.9" />
                <vers num="1.9.1" />
                <vers num="1.9.10" />
                <vers num="1.9.11" />
                <vers num="1.9.12" />
                <vers num="1.9.13" />
                <vers num="1.9.14" />
                <vers num="1.9.2" />
                <vers num="1.9.3" />
                <vers num="1.9.4" />
                <vers num="1.9.5" />
                <vers num="1.9.6" />
                <vers num="1.9.7" />
                <vers num="1.9.8" />
                <vers num="1.9.9" />
            </prod>
            <prod vendor="enlightenment" name="imlib2">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.1" />
                <vers num="1.1.1" />
            </prod>
            <prod vendor="imagemagick" name="imagemagick">
                <vers num="5.3.3" />
                <vers num="5.4.3" />
                <vers num="5.4.4.5" />
                <vers num="5.4.7" />
                <vers num="5.4.8" />
                <vers num="5.4.8.2.1.1.0" />
                <vers num="5.5.3.2.1.2.0" />
                <vers num="5.5.6.0_2003-04-09" />
                <vers num="5.5.7" />
                <vers num="6.0.2" />
            </prod>
            <prod vendor="sun" name="java_desktop_system">
                <vers num="2.0" />
                <vers num="2003" />
            </prod>
            <prod vendor="conectiva" name="linux">
                <vers num="10.0" />
                <vers num="9.0" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux">
                <vers edition="" num="10.0" />
                <vers edition=":amd64" num="10.0" />
                <vers edition="" num="9.2" />
                <vers edition=":amd64" num="9.2" />
            </prod>
            <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
                <vers edition="" num="2.1" />
                <vers edition=":x86_64" num="2.1" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux">
                <vers edition="" num="2.1" />
                <vers edition=":advanced_server_ia64" num="2.1" />
                <vers edition=":enterprise_server_ia64" num="2.1" />
                <vers edition=":advanced_server" num="2.1" />
                <vers edition=":workstation_ia64" num="2.1" />
                <vers edition=":workstation" num="2.1" />
                <vers edition=":enterprise_server" num="2.1" />
                <vers edition="" num="3.0" />
                <vers edition=":advanced_servers" num="3.0" />
                <vers edition=":workstation" num="3.0" />
                <vers edition=":enterprise_server" num="3.0" />
            </prod>
            <prod vendor="redhat" name="enterprise_linux_desktop">
                <vers num="3.0" />
            </prod>
            <prod vendor="redhat" name="fedora_core">
                <vers num="core_1.0" />
                <vers num="core_2.0" />
                <vers num="core_3.0" />
            </prod>
            <prod vendor="redhat" name="linux_advanced_workstation">
                <vers edition="" num="2.1" />
                <vers edition=":ia64" num="2.1" />
                <vers edition=":itanium_processor" num="2.1" />
            </prod>
            <prod vendor="suse" name="suse_linux">
                <vers edition="" num="8.0" />
                <vers edition=":i386" num="8.0" />
                <vers num="8.1" />
                <vers num="8.2" />
                <vers edition="" num="9.0" />
                <vers edition=":x86_64" num="9.0" />
                <vers num="9.1" />
                <vers num="9.2" />
            </prod>
            <prod vendor="turbolinux" name="turbolinux_desktop">
                <vers num="10.0" />
            </prod>
            <prod vendor="turbolinux" name="turbolinux_server">
                <vers num="7.0" />
                <vers num="8.0" />
            </prod>
            <prod vendor="turbolinux" name="turbolinux_workstation">
                <vers num="7.0" />
                <vers num="8.0" />
            </prod>
            <prod vendor="ubuntu" name="ubuntu_linux">
                <vers edition="" num="4.1" />
                <vers edition=":ppc" num="4.1" />
                <vers edition=":ia64" num="4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2005-2088" seq="2005-2088" severity="Medium" type="CVE" published="2005-07-05" CVSS_version="2.0 incomplete approximation" CVSS_score="4.3" modified="2010-01-25">
        <desc>
            <descript source="cve">The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00612828">HPSBUX02101</ref>
            <ref source="MISC" url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-160-2">USN-160-2</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/15647">15647</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/14106">14106</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="MISC" url="http://www.securiteam.com/securityreviews/5GP0220G0U.html">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-582.html">RHSA-2005:582</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/1018">ADV-2006-1018</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/2659">ADV-2005-2659</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/2140">ADV-2005-2140</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-805">DSA-805</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-803">DSA-803</ref>
            <ref source="CONFIRM" url="http://www.apache.org/dist/httpd/CHANGES_2.0">http://www.apache.org/dist/httpd/CHANGES_2.0</ref>
            <ref source="CONFIRM" url="http://www.apache.org/dist/httpd/CHANGES_1.3">http://www.apache.org/dist/httpd/CHANGES_1.3</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK16139&amp;apar=only">PK16139</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK13959&amp;apar=only">PK13959</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1">102197</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2005&amp;m=slackware-security.600000">SSA:2005-310-04</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1014323">1014323</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19317">19317</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19185">19185</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19073">19073</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19072">19072</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17813">17813</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17487">17487</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17319">17319</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/14530">14530</ref>
            <ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref>
            <ref source="MLIST" url="http://marc2.theaimsgroup.com/?l=apache-httpd-announce&amp;m=112931556417329&amp;w=3">[apache-httpd-announce] 20051014 Apache HTTP Server 2.0.55 Released</ref>
            <ref source="TRUSTIX" url="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html">TSLSA-2005-0059</ref>
            <ref source="APPLE" url="http://docs.info.apple.com/article.html?artnum=302847">APPLE-SA-2005-11-29</ref>
            <ref source="CONFIRM" url="https://secure-support.novell.com/KanisaPlatform/Publishing/741/3222109_f.SAL_Public.html">https://secure-support.novell.com/KanisaPlatform/Publishing/741/3222109_f.SAL_Public.html</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_46_apache.html">SUSE-SA:2005:046</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:130">MDKSA-2005:130</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4680">ADV-2006-4680</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/604">604</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23074">23074</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:130">MDKSA-2005:130</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:840" sig="1">oval:org.mitre.oval:def:840</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1629" sig="1">oval:org.mitre.oval:def:1629</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1526" sig="1">oval:org.mitre.oval:def:1526</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1237" sig="1">oval:org.mitre.oval:def:1237</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="1.3.29" />
                <vers num="1.3.30" />
                <vers num="1.3.31" />
                <vers num="1.3.32" />
                <vers num="1.3.33" />
                <vers num="2.0.45" />
                <vers num="2.0.46" />
                <vers num="2.0.47" />
                <vers num="2.0.48" />
                <vers num="2.0.49" />
                <vers num="2.0.50" />
                <vers num="2.0.51" />
                <vers num="2.0.52" />
                <vers num="2.0.53" />
                <vers num="2.0.54" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-1689" seq="2005-1689" severity="High" type="CVE" published="2005-07-18" CVSS_version="2.0" CVSS_score="7.5" modified="2010-02-08">
        <desc>
            <descript source="cve">Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/623332" adv="1">VU#623332</ref>
            <ref source="GENTOO" patch="1" url="http://www.gentoo.org/security/en/glsa/glsa-200507-11.xml" adv="1">GLSA-200507-11</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2005/dsa-757" adv="1">DSA-757</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21055">kerberos-kdc-krb5recvauth-execute-code(21055)</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-224-1">USN-224-1</ref>
            <ref source="TURBO" url="http://www.turbolinux.com/security/2005/TLSA-2005-78.txt">TLSA-2005-78</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0036">2005-0036</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/14239">14239</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-567.html">RHSA-2005:567</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-562.html">RHSA-2005:562</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_17_sr.html">SUSE-SR:2005:017</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3776" adv="1">ADV-2006-3776</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/1066" adv="1">ADV-2005-1066</ref>
            <ref source="CONFIRM" url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txt">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txt</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101810-1">101810</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1014461">1014461</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22090" adv="1">22090</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17899" adv="1">17899</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17135" adv="1">17135</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/16041" adv="1">16041</ref>
            <ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112119974704542&amp;w=2">20050712 MITKRB5-SA-2005-003: double-free in krb5_recvauth</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000993">CLA-2005:993</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.asc">20050703-01-U</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mit" name="kerberos">
                <vers num="5-1.3" />
                <vers num="5-1.3.1" />
                <vers num="5-1.3.2" />
                <vers num="5-1.3.3" />
                <vers num="5-1.3.4" />
                <vers num="5-1.3.5" />
                <vers num="5-1.3.6" />
                <vers num="5-1.4" />
                <vers num="5-1.4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2005-1268" seq="2005-1268" severity="Medium" type="CVE" published="2005-08-05" CVSS_version="2.0 incomplete approximation" CVSS_score="5.0" modified="2010-02-09">
        <desc>
            <descript source="cve">Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
            <other />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MANDRAKE" patch="1" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:129" adv="1">MDKSA-2005:129</ref>
            <ref source="REDHAT" patch="1" url="http://rhn.redhat.com/errata/RHSA-2005-582.html">RHSA-2005:582</ref>
            <ref source="MISC" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163013" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163013</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/14366">14366</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_46_apache.html">SUSE-SA:2005:046</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-805">DSA-805</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/604">604</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19185">19185</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19072">19072</ref>
            <ref source="TRUSTIX" url="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html">TSLSA-2005-0059</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1747" sig="1">oval:org.mitre.oval:def:1747</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1714" sig="1">oval:org.mitre.oval:def:1714</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1346" sig="1">oval:org.mitre.oval:def:1346</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2005-2491" seq="2005-2491" severity="High" type="CVE" published="2005-08-23" CVSS_version="2.0 incomplete approximation" CVSS_score="7.5" modified="2010-02-07">
        <desc>
            <descript source="cve">Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1014744">1014744</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/14620">14620</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/15647">15647</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">SSRT051251</ref>
            <ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427046/100/0/threaded">FLSA:168516</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0197.html">RHSA-2006:0197</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-761.html">RHSA-2005:761</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-358.html">RHSA-2005:358</ref>
            <ref source="CONFIRM" url="http://www.php.net/release_4_4_1.php">http://www.php.net/release_4_4_1.php</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_52_apache2.html">SUSE-SA:2005:052</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_49_php.html">SUSE-SA:2005:049</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_48_pcre.html">SUSE-SA:2005:048</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-19.xml">GLSA-200509-19</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-12.xml">GLSA-200509-12</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-02.xml">GLSA-200509-02</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200508-17.xml">GLSA-200509-08</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4502">ADV-2006-4502</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4320">ADV-2006-4320</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/2659">ADV-2005-2659</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/1511">ADV-2005-1511</ref>
            <ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00021.html">http://www.ethereal.com/appnotes/enpa-sa-00021.html</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-821">DSA-821</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-819">DSA-819</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-817">DSA-817</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-800">DSA-800</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-159.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-159.htm</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/604">604</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22875">22875</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22691">22691</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21522">21522</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19532">19532</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19193">19193</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19072">19072</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17813">17813</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17252">17252</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/16679">16679</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/16502">16502</ref>
            <ref source="OPENPKG" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112606064317223&amp;w=2">OpenPKG-SA-2005.018</ref>
            <ref source="SUSE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2">SUSE-SA:2005:051</ref>
            <ref source="TRUSTIX" url="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html">TSLSA-2005-0059</ref>
            <ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522">HPSBMA02159</ref>
            <ref source="APPLE" url="http://docs.info.apple.com/article.html?artnum=302847">APPLE-SA-2005-11-29</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U">20060401-01-U</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txt">SCOSA-2006.10</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:735" sig="1">oval:org.mitre.oval:def:735</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1659" sig="1">oval:org.mitre.oval:def:1659</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1496" sig="1">oval:org.mitre.oval:def:1496</ref>
        </refs>
        <vuln_soft>
            <prod vendor="pcre" name="pcre">
                <vers num="5.0" />
                <vers num="6.0" />
                <vers num="6.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2005-3962" seq="2005-3962" severity="Medium" type="CVE" published="2005-12-01" CVSS_version="2.0 upgrade from v1.0" CVSS_score="4.6" modified="2010-02-06">
        <desc>
            <descript source="cve">Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/948385">VU#948385</ref>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-333A.html">TA06-333A</ref>
            <ref source="MISC" patch="1" url="http://www.dyadsecurity.com/perl-0002.html" adv="1">http://www.dyadsecurity.com/perl-0002.html</ref>
            <ref source="FULLDISC" patch="1" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113342788118630&amp;w=2" adv="1">20051201 Perl format string integer wrap vulnerability</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-legacy-announce/2006-February/msg00008.html">FLSA-2006:176731</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-222-1">USN-222-1</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0070">TSLSA-2005-0070</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/15629">15629</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">SSRT061105</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">SSRT061105</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">SSRT061105</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">SSRT061105</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">SSRT061105</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">SSRT061105</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">SSRT061105</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">SSRT061105</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">SSRT061105</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/418333/100/0/threaded">20051201 Perl format string integer wrap vulnerability</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-881.html">RHSA-2005:881</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-880.html">RHSA-2005:880</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/22255">22255</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/21345">21345</ref>
            <ref source="OPENPKG" url="http://www.openpkg.org/security/OpenPKG-SA-2005.025-perl.html">OpenPKG-SA-2005.025</ref>
            <ref source="OPENBSD" url="http://www.openbsd.org/errata37.html#perl">[3.7] 20060105 007: SECURITY FIX: January 5, 2006</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_71_perl.html">SUSE-SA:2005:071</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200512-01.xml">GLSA-200512-01</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0771">ADV-2006-0771</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2005/2688">ADV-2005-2688</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-943">DSA-943</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102192-1">102192</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19041">19041</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18517">18517</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18413">18413</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18295">18295</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18187">18187</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18183">18183</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18075">18075</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17993">17993</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17952">17952</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17941">17941</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17844">17844</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17802">17802</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/17762">17762</ref>
            <ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113342788118630&amp;w=2">20051201 Perl format string integer wrap vulnerability</ref>
            <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:225">MDKSA-2005:225</ref>
            <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056">CLSA-2006:1056</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U">20060101-01-U</ref>
            <ref source="MISC" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/001_perl.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/001_perl.patch</ref>
            <ref source="CONFIRM" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/007_perl.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/007_perl.patch</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438726/100/0/threaded">SSRT061105</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_29_sr.html">SUSE-SR:2005:029</ref>
            <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:225">MDKSA-2005:225</ref>
            <ref source="CONFIRM" url="http://www.ipcop.org/index.php?name=News&amp;file=article&amp;sid=41">http://www.ipcop.org/index.php?name=News&amp;file=article&amp;sid=41</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4750">ADV-2006-4750</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/2613">ADV-2006-2613</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31208">31208</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23155">23155</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20894">20894</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html">APPLE-SA-2006-11-28</ref>
            <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=304829">http://docs.info.apple.com/article.html?artnum=304829</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1074" sig="1">oval:org.mitre.oval:def:1074</ref>
        </refs>
        <vuln_soft>
            <prod vendor="larry_wall" name="perl">
                <vers num="5.8.6" />
                <vers num="5.9.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-0292" seq="2006-0292" severity="High" type="CVE" published="2006-02-02" CVSS_version="2.0 upgrade from v1.0" CVSS_score="7.5" modified="2010-02-06">
        <desc>
            <descript source="cve">The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot user="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.mozilla.org/show_bug.cgi?id=316885">https://bugzilla.mozilla.org/show_bug.cgi?id=316885</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0200.html" adv="1">RHSA-2006:0200</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0199.html" adv="1">RHSA-2006:0199</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1">228526</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24430">mozilla-javascript-memory-corruption(24430)</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1">USN-276-1</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1">USN-275-1</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1">USN-271-1</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/16476">16476</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded">HPSBUX02156</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded">HPSBUX02122</ref>
            <ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/425978/100/0/threaded">FLSA-2006:180036-2</ref>
            <ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/425975/100/0/threaded">FLSA:180036-1</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0330.html">RHSA-2006:0330</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00006.html">FEDORA-2006-076</ref>
            <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00005.html">FEDORA-2006-075</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref>
            <ref source="CONFIRM" url="http://www.mozilla.org/security/announce/2006/mfsa2006-01.html">http://www.mozilla.org/security/announce/2006/mfsa2006-01.html</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:037">MDKSA-2006:037</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:036">MDKSA-2006:036</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml">GLSA-200605-09</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml">GLSA-200604-18</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml">GLSA-200604-12</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3749">ADV-2006-3749</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3391">ADV-2006-3391</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0413">ADV-2006-0413</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1044">DSA-1044</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1">102550</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1015570">1015570</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22065">22065</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21622">21622</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21033">21033</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/20051">20051</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19950">19950</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19902">19902</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19862">19862</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19852">19852</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19821">19821</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19780">19780</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19759">19759</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19746">19746</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/19230">19230</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18709">18709</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18708">18708</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18706">18706</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18705">18705</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18704">18704</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18703">18703</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18700">18700</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:078">MDKSA-2006:078</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:037">MDKSA-2006:037</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:036">MDKSA-2006:036</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U">20060201-01-U</ref>
            <ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt">SCOSA-2006.26</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:670" sig="1">oval:org.mitre.oval:def:670</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="0.10" />
                <vers num="0.10.1" />
                <vers num="0.8" />
                <vers edition="rc" num="0.9" />
                <vers num="0.9.1" />
                <vers num="0.9.2" />
                <vers num="0.9.3" />
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers edition="" num="1.0.6" />
                <vers edition=":linux" num="1.0.6" />
                <vers num="1.0.7" />
                <vers edition="beta1" num="1.5" />
            </prod>
            <prod vendor="mozilla" name="mozilla">
                <vers num="1.4" />
                <vers num="1.4.1" />
                <vers edition="alpha" num="1.5" />
                <vers edition="rc1" num="1.5" />
                <vers edition="rc2" num="1.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2006-1017" seq="2006-1017" severity="High" type="CVE" published="2006-03-06" CVSS_version="2.0" CVSS_score="9.3" modified="2010-01-26">
        <desc>
            <descript source="cve">The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24964">php-imap-restriction-bypass(24964)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426339/100/0/threaded">20060228 (PHP) imap functions bypass safemode and open_basedir restrictions</ref>
            <ref source="CONFIRM" url="http://www.php.net/release_5_1_5.php">http://www.php.net/release_5_1_5.php</ref>
            <ref source="CONFIRM" url="http://www.php.net/ChangeLog-5.php#5.1.5">http://www.php.net/ChangeLog-5.php#5.1.5</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/23535">23535</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:122">MDKSA-2006:122</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/0772" adv="1">ADV-2006-0772</ref>
            <ref source="SREASON" url="http://securityreason.com/securityalert/516">516</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21546">21546</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21050" adv="1">21050</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/18694" adv="1">18694</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:122">MDKSA-2006:122</ref>
            <ref source="CONFIRM" url="http://bugs.php.net/bug.php?id=37265">http://bugs.php.net/bug.php?id=37265</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.10" />
                <vers num="3.0.11" />
                <vers num="3.0.12" />
                <vers num="3.0.13" />
                <vers num="3.0.14" />
                <vers num="3.0.15" />
                <vers num="3.0.16" />
                <vers num="3.0.17" />
                <vers num="3.0.18" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.6" />
                <vers num="3.0.7" />
                <vers num="3.0.8" />
                <vers num="3.0.9" />
                <vers num="4.0.0" />
                <vers edition="patch1" num="4.0.1" />
                <vers edition="patch2" num="4.0.1" />
                <vers num="4.0.2" />
                <vers edition="patch1" num="4.0.3" />
                <vers num="4.0.4" />
                <vers num="4.0.5" />
                <vers num="4.0.6" />
                <vers edition="rc1" num="4.0.7" />
                <vers edition="rc2" num="4.0.7" />
                <vers edition="rc3" num="4.0.7" />
                <vers num="4.1.0" />
                <vers num="4.1.1" />
                <vers num="4.1.2" />
                <vers edition="" num="4.2" />
                <vers edition=":dev" num="4.2" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.2" />
                <vers num="4.2.3" />
                <vers num="4.3" />
                <vers num="4.3.1" />
                <vers num="4.3.10" />
                <vers num="4.3.11" />
                <vers num="4.3.2" />
                <vers num="4.3.3" />
                <vers num="4.3.4" />
                <vers num="4.3.5" />
                <vers num="4.3.6" />
                <vers num="4.3.7" />
                <vers num="4.3.8" />
                <vers num="4.3.9" />
                <vers num="4.4.0" />
                <vers num="4.4.1" />
                <vers num="4.4.2" />
                <vers num="4.4.3" />
                <vers edition="rc1" num="5.0" />
                <vers edition="rc2" num="5.0" />
                <vers edition="rc3" num="5.0" />
                <vers edition="beta1" num="5.0.0" />
                <vers edition="beta2" num="5.0.0" />
                <vers edition="beta3" num="5.0.0" />
                <vers edition="beta4" num="5.0.0" />
                <vers edition="rc1" num="5.0.0" />
                <vers edition="rc2" num="5.0.0" />
                <vers edition="rc3" num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.1.0" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1.3" />
                <vers num="5.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2006-4481" seq="2006-4481" severity="High" type="CVE" published="2006-08-31" CVSS_version="2.0" CVSS_score="7.2" modified="2010-01-26">
        <desc>
            <descript source="cve">The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 do not check for the safe_mode and open_basedir settings, which allows local users to bypass the settings.  NOTE: the error_log function is covered by CVE-2006-3011, and the imap_open function is covered by CVE-2006-1017.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.php.net/release_5_1_5.php">http://www.php.net/release_5_1_5.php</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/21842" adv="1">21842</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/21768" adv="1">21768</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/21546" adv="1">21546</ref>
            <ref source="MANDRIVA" patch="1" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:162" adv="1">MDKSA-2006:162</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-342-1">USN-342-1</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/19582">19582</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_52_php.html">SUSE-SA:2006:052</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:162">MDKSA-2006:162</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3318">ADV-2006-3318</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22039">22039</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="5.1" />
                <vers num="5.1.0" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2006-4339" seq="2006-4339" severity="Medium" type="CVE" published="2006-09-05" CVSS_version="2.0" CVSS_score="4.3" modified="2010-02-06">
        <desc>
            <descript source="cve">OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <exception />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/845620">VU#845620</ref>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-333A.html">TA06-333A</ref>
            <ref source="DEBIAN" patch="1" url="http://www.us.debian.org/security/2006/dsa-1173">DSA-1173</ref>
            <ref source="UBUNTU" patch="1" url="http://www.ubuntu.com/usn/usn-339-1">USN-339-1</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/19849">19849</ref>
            <ref source="CONFIRM" patch="1" url="http://www.openssl.org/news/secadv_20060905.txt" adv="1">http://www.openssl.org/news/secadv_20060905.txt</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/3453" adv="1">ADV-2006-3453</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2006/dsa-1174">DSA-1174</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/21709" adv="1">21709</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-616">https://issues.rpath.com/browse/RPL-616</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28755">openssl-rsa-security-bypass(28755)</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/445822/100/0/threaded">20060912 ERRATA: [ GLSA 200609-05 ] OpenSSL, AMD64 x86 emulation base libraries: RSA signature forgery</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/445231/100/0/threaded">20060905 rPSA-2006-0163-1 openssl openssl-scripts</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0629.html">RHSA-2008:0629</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0661.html">RHSA-2006:0661</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/28549">28549</ref>
            <ref source="CONFIRM" url="http://www.opera.com/support/search/supsearch.dml?index=845">http://www.opera.com/support/search/supsearch.dml?index=845</ref>
            <ref source="OPENBSD" url="http://www.openbsd.org/errata.html">[3.9] 20060908 011: SECURITY FIX: September 8, 2006</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_55_ssl.html">SUSE-SA:2006:055</ref>
            <ref source="MISC" url="http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/">http://www.matasano.com/log/469/many-rsa-signatures-may-be-forgeable-in-openssl-and-elsewhere/</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:161">MDKSA-2006:161</ref>
            <ref source="MLIST" url="http://www.imc.org/ietf-openpgp/mail-archive/msg14307.html">[ietf-openpgp] 20060827 Bleichenbacher's RSA signature forgery based on implementation error</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3793" adv="1">ADV-2006-3793</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3730" adv="1">ADV-2006-3730</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3566" adv="1">ADV-2006-3566</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2006-188.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-188.htm</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.605306">SSA:2006-257-02</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1016791">1016791</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200609-18.xml">GLSA-200609-18</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200609-05.xml">GLSA-200609-05</ref>
            <ref source="FREEBSD" url="http://security.freebsd.org/advisories/FreeBSD-SA-06:19.openssl.asc">FreeBSD-SA-06:19</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31492">31492</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22259" adv="1">22259</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22161" adv="1">22161</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22036" adv="1">22036</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21982" adv="1">21982</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21930" adv="1">21930</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21927" adv="1">21927</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21906" adv="1">21906</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21873" adv="1">21873</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21870" adv="1">21870</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21852" adv="1">21852</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21846" adv="1">21846</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21823" adv="1">21823</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21812" adv="1">21812</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21791" adv="1">21791</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21785" adv="1">21785</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21778" adv="1">21778</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21776" adv="1">21776</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/21767" adv="1">21767</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771">HPSBMA02250</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495">SSRT061273</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:178">MDKSA-2006:178</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:177">MDKSA-2006:177</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc">20060901-01-P</ref>
            <ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">SSRT061239</ref>
            <ref source="CONFIRM" url="https://secure-support.novell.com/KanisaPlatform/Publishing/41/3143224_f.SAL_Public.html">https://secure-support.novell.com/KanisaPlatform/Publishing/41/3143224_f.SAL_Public.html</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-1633">https://issues.rpath.com/browse/RPL-1633</ref>
            <ref source="CONFIRM" url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=3117</ref>
            <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742">HPSBUX02153</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html">http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html">http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/server/doc/releasenotes_server.html">http://www.vmware.com/support/server/doc/releasenotes_server.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/player/doc/releasenotes_player.html">http://www.vmware.com/support/player/doc/releasenotes_player.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html">http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html">http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html">http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html">http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/security/advisories/VMSA-2008-0005.html">http://www.vmware.com/security/advisories/VMSA-2008-0005.html</ref>
            <ref source="CONFIRM" url="http://www.sybase.com/detail?id=1047991">http://www.sybase.com/detail?id=1047991</ref>
            <ref source="CONFIRM" url="http://www.serv-u.com/releasenotes/">http://www.serv-u.com/releasenotes/</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/28276">28276</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489739/100/0/threaded">20080318 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456546/100/200/threaded">20070110 VMware ESX server security updates</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/450327/100/0/threaded">HPSBUX02165</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0073.html">RHSA-2007:0073</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0072.html">RHSA-2007:0072</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0062.html">RHSA-2007:0062</ref>
            <ref source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
            <ref source="OPENPKG" url="http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.029-bind.html">OpenPKG-SA-2006.029</ref>
            <ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.018.html">OpenPKG-SA-2006.018</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_10_ibmjava.html">SUSE-SA:2007:010</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_61_opera.html">SUSE-SA:2006:061</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_26_sr.html">SUSE-SR:2006:026</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:207">MDKSA-2006:207</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:178">MDKSA-2006:178</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:177">MDKSA-2006:177</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200610-06.xml">GLSA-200610-06</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/0905/references">ADV-2008-0905</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/4224">ADV-2007-4224</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/2783">ADV-2007-2783</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/2315">ADV-2007-2315</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/2163">ADV-2007-2163</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/1945">ADV-2007-1945</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/1815">ADV-2007-1815</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/1401">ADV-2007-1401</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/0343">ADV-2007-0343</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/0254">ADV-2007-0254</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/5146">ADV-2006-5146</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4750">ADV-2006-4750</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4744">ADV-2006-4744</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4586">ADV-2006-4586</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4417">ADV-2006-4417</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4366">ADV-2006-4366</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4329">ADV-2006-4329</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4327">ADV-2006-4327</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4216">ADV-2006-4216</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4207">ADV-2006-4207</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4206">ADV-2006-4206</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/4205">ADV-2006-4205</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3936">ADV-2006-3936</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3899">ADV-2006-3899</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2006/3748">ADV-2006-3748</ref>
            <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sr-20061108-openssl.shtml">20061108 Multiple Vulnerabilities in OpenSSL library</ref>
            <ref source="CISCO" url="http://www.cisco.com/en/US/products/hw/contnetw/ps4162/tsd_products_security_response09186a008077af1b.html">20061108 Multiple Vulnerabilities in OpenSSL Library</ref>
            <ref source="CONFIRM" url="http://www.bluecoat.com/support/knowledge/openSSL_RSA_Signature_forgery.html">http://www.bluecoat.com/support/knowledge/openSSL_RSA_Signature_forgery.html</ref>
            <ref source="CONFIRM" url="http://www.arkoon.fr/upload/alertes/40AK-2006-04-FR-1.1_SSL360_OPENSSL_RSA.pdf">http://www.arkoon.fr/upload/alertes/40AK-2006-04-FR-1.1_SSL360_OPENSSL_RSA.pdf</ref>
            <ref source="CONFIRM" url="http://support.attachmate.com/techdocs/2137.html">http://support.attachmate.com/techdocs/2137.html</ref>
            <ref source="CONFIRM" url="http://support.attachmate.com/techdocs/2128.html">http://support.attachmate.com/techdocs/2128.html</ref>
            <ref source="CONFIRM" url="http://support.attachmate.com/techdocs/2127.html">http://support.attachmate.com/techdocs/2127.html</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201534-1">201534</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201247-1">201247</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200708-1">200708</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102759-1">102759</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102744-1">102744</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102722-1">102722</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102696-1">102696</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102686-1">102686</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102657-1">102657</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102656-1">102656</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1">102648</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.566955">SSA:2006-310-01</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28115">28115</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26893">26893</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26329">26329</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25649">25649</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25399">25399</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25284">25284</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24950">24950</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24930">24930</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24099">24099</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23915">23915</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23841">23841</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23680">23680</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23455">23455</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23155">23155</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22949">22949</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22948">22948</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22940">22940</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22939">22939</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22938">22938</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22937">22937</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22936">22936</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22934">22934</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22932">22932</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22799">22799</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22758">22758</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22733">22733</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22711">22711</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22689">22689</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22671">22671</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22585">22585</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22545">22545</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22523">22523</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22513">22513</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22509">22509</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22446">22446</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22325">22325</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22284">22284</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22260">22260</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22232">22232</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22226">22226</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22066">22066</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/22044">22044</ref>
            <ref source="CONFIRM" url="http://openvpn.net/changelog.html">http://openvpn.net/changelog.html</ref>
            <ref source="MLIST" url="http://marc.theaimsgroup.com/?l=bind-announce&amp;m=116253119512445&amp;w=2">[bind-announce] 20061103 Internet Systems Consortium Security Advisory. [revised]</ref>
            <ref source="MLIST" url="http://lists.vmware.com/pipermail/security-announce/2008/000008.html">[security-announce] 20080317 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html">APPLE-SA-2007-12-14</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html">APPLE-SA-2006-11-28</ref>
            <ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540">SSRT071299</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771">HPSBMA02250</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495">SSRT061273</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:207">MDKSA-2006:207</ref>
            <ref source="MISC" url="http://docs.info.apple.com/article.html?artnum=307177">http://docs.info.apple.com/article.html?artnum=307177</ref>
            <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=304829">http://docs.info.apple.com/article.html?artnum=304829</ref>
            <ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/238">BEA07-169.00</ref>
        </refs>
        <vuln_soft>
            <prod vendor="openssl" name="openssl">
                <vers num="0.9.1c" />
                <vers num="0.9.2b" />
                <vers num="0.9.3" />
                <vers num="0.9.3a" />
                <vers num="0.9.4" />
                <vers edition="beta1" num="0.9.5" />
                <vers edition="beta2" num="0.9.5" />
                <vers edition="beta1" num="0.9.5a" />
                <vers edition="beta2" num="0.9.5a" />
                <vers edition="beta1" num="0.9.6" />
                <vers edition="beta2" num="0.9.6" />
                <vers edition="beta3" num="0.9.6" />
                <vers edition="beta1" num="0.9.6a" />
                <vers edition="beta2" num="0.9.6a" />
                <vers edition="beta3" num="0.9.6a" />
                <vers num="0.9.6b" />
                <vers num="0.9.6c" />
                <vers num="0.9.6d" />
                <vers num="0.9.6e" />
                <vers num="0.9.6f" />
                <vers num="0.9.6g" />
                <vers num="0.9.6h" />
                <vers num="0.9.6i" />
                <vers num="0.9.6j" />
                <vers num="0.9.6k" />
                <vers num="0.9.6l" />
                <vers num="0.9.6m" />
                <vers num="0.9.7" prev="1" />
                <vers num="0.9.7a" />
                <vers num="0.9.7b" />
                <vers num="0.9.7c" />
                <vers num="0.9.7d" />
                <vers num="0.9.7e" />
                <vers num="0.9.7f" />
                <vers num="0.9.7g" />
                <vers num="0.9.7h" />
                <vers num="0.9.7i" />
                <vers num="0.9.7j" />
                <vers num="0.9.8" />
                <vers num="0.9.8a" />
                <vers num="0.9.8b" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2006-6304" seq="2006-6304" severity="High" type="CVE" published="2006-12-14" CVSS_version="2.0" CVSS_score="7.5" modified="2010-02-02">
        <desc>
            <descript source="cve">The do_coredump function in fs/exec.c in the Linux kernel 2.6.19 sets the flag variable to O_EXCL but does not use it, which allows context-dependent attackers to modify arbitrary files via a rewrite attack during a core dump.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/21591">21591</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/5002" adv="1">ADV-2006-5002</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2010-0046.html">RHSA-2010:0046</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.19.1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.19.1</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0074/">2006-0074</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23349">23349</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="linux_kernel">
                <vers edition="test1" num="2.6.0" />
                <vers edition="test10" num="2.6.0" />
                <vers edition="test11" num="2.6.0" />
                <vers edition="test2" num="2.6.0" />
                <vers edition="test3" num="2.6.0" />
                <vers edition="test4" num="2.6.0" />
                <vers edition="test5" num="2.6.0" />
                <vers edition="test6" num="2.6.0" />
                <vers edition="test7" num="2.6.0" />
                <vers edition="test8" num="2.6.0" />
                <vers edition="test9" num="2.6.0" />
                <vers edition="rc1" num="2.6.1" />
                <vers edition="rc2" num="2.6.1" />
                <vers edition="rc2" num="2.6.10" />
                <vers edition="rc2" num="2.6.11" />
                <vers edition="rc3" num="2.6.11" />
                <vers edition="rc4" num="2.6.11" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers edition="rc1" num="2.6.12" />
                <vers edition="rc4" num="2.6.12" />
                <vers edition="rc5" num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.12" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.22" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers edition="rc1" num="2.6.13" />
                <vers edition="rc4" num="2.6.13" />
                <vers edition="rc6" num="2.6.13" />
                <vers edition="rc7" num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers edition="rc1" num="2.6.14" />
                <vers edition="rc2" num="2.6.14" />
                <vers edition="rc3" num="2.6.14" />
                <vers edition="rc4" num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers edition="rc1" num="2.6.15" />
                <vers edition="rc3" num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.11" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers edition="rc1" num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.9" />
                <vers edition="rc5" num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers edition="rc1" num="2.6.19" />
                <vers edition="rc2" num="2.6.19" />
                <vers edition="rc3" num="2.6.19" />
                <vers edition="rc4" num="2.6.19" />
                <vers num="2.6.19.0" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers edition="rc1" num="2.6.6" />
                <vers edition="rc1" num="2.6.7" />
                <vers edition="rc1" num="2.6.8" />
                <vers edition="rc2" num="2.6.8" />
                <vers edition="rc3" num="2.6.8" />
                <vers edition="2.6.20" num="2.6.9" />
                <vers num="2.6_test9_cvs" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2006-6731" seq="2006-6731" severity="High" type="CVE" published="2006-12-26" CVSS_version="2.0" CVSS_score="9.3" modified="2010-02-07">
        <desc>
            <descript source="cve">Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function.  NOTE: some of these details are obtained from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <vuln_types>
            <input buffer="1" />
        </vuln_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/939609">VU#939609</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/149457">VU#149457</ref>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-022A.html">TA07-022A</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/21675">21675</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2006/5073" adv="1">ADV-2006-5073</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102729-1">102729</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1017425">1017425</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23650" adv="1">23650</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23445" adv="1">23445</ref>
            <ref source="MISC" url="http://scary.beasts.org/security/CESA-2005-008.txt">http://scary.beasts.org/security/CESA-2005-008.txt</ref>
            <ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0003.html" adv="1">SUSE-SA:2007:003</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0073.html">RHSA-2007:0073</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0072.html">RHSA-2007:0072</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0062.html">RHSA-2007:0062</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_10_ibmjava.html">SUSE-SA:2007:010</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200705-20.xml">GLSA-200705-20</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/4224">ADV-2007-4224</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/1814">ADV-2007-1814</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/0936">ADV-2007-0936</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200702-08.xml">GLSA-200702-08</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200701-15.xml">GLSA-200701-15</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28115">28115</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25404">25404</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25283">25283</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24468">24468</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24189">24189</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/24099">24099</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/23835">23835</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html">APPLE-SA-2007-12-14</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</ref>
            <ref source="MISC" url="http://docs.info.apple.com/article.html?artnum=307177">http://docs.info.apple.com/article.html?artnum=307177</ref>
            <ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/243">BEA07-174.00</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update7" num="1.5.0" prev="1" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update18" num="1.3.1" prev="1" />
                <vers edition="update12" num="1.4.2" prev="1" />
                <vers edition="update7" num="1.5.0" prev="1" />
            </prod>
            <prod vendor="sun" name="sdk">
                <vers num="1.3.1_18" prev="1" />
                <vers num="1.4.2_12" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" name="CVE-2007-1558" seq="2007-1558" severity="Low" type="CVE" published="2007-04-16" CVSS_version="2.0" CVSS_score="2.6" modified="2010-02-06">
        <desc>
            <descript source="cve">The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions.  NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <vuln_types>
            <design />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-151A.html">TA07-151A</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/23257">23257</ref>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2007/mfsa2007-15.html" adv="1">http://www.mozilla.org/security/announce/2007/mfsa2007-15.html</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2007/1994" adv="1">ADV-2007-1994</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2007/1939" adv="1">ADV-2007-1939</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2007/1480" adv="1">ADV-2007-1480</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2007/1468" adv="1">ADV-2007-1468</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2007/1467" adv="1">ADV-2007-1467</ref>
            <ref source="VUPEN" patch="1" url="http://www.frsirt.com/english/advisories/2007/1466" adv="1">ADV-2007-1466</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2007/dsa-1305">DSA-1305</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-1424">https://issues.rpath.com/browse/RPL-1424</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-1232">https://issues.rpath.com/browse/RPL-1232</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-1231">https://issues.rpath.com/browse/RPL-1231</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-520-1">USN-520-1</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-469-1">USN-469-1</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1018008">1018008</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/471842/100/0/threaded">20070620 FLEA-2007-0027-1: thunderbird</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/471720/100/0/threaded">20070619 FLEA-2007-0026-1: evolution-data-server</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/471455/100/0/threaded">20070615 rPSA-2007-0122-1 evolution-data-server</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470172/100/200/threaded">20070531 FLEA-2007-0023-1: firefox</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464569/100/0/threaded">20070403 Re: APOP vulnerability</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/464477/30/0/threaded" adv="1">20070402 APOP vulnerability</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1140.html">RHSA-2009:1140</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0402.html">RHSA-2007:0402</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0401.html">RHSA-2007:0401</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0386.html">RHSA-2007:0386</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0385.html">RHSA-2007:0385</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0353.html">RHSA-2007:0353</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0344.html">RHSA-2007:0344</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/08/18/1">[oss-security] 20090818 Re: CVE-2007-1558 update (was: mailfilter 0.8.2 fixes CVE-2007-1558 (APOP))</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/08/15/1">[oss-security] 20090815 mailfilter 0.8.2 fixes CVE-2007-1558 (APOP)</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_36_mozilla.html">SUSE-SA:2007:036</ref>
            <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_14_sr.html">SUSE-SR:2007:014</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:131">MDKSA-2007:131</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:119">MDKSA-2007:119</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:113">MDKSA-2007:113</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:107">MDKSA-2007:107</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:105">MDKSA-2007:105</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1300">DSA-1300</ref>
            <ref source="CONFIRM" url="http://www.claws-mail.org/news.php">http://www.claws-mail.org/news.php</ref>
            <ref source="CONFIRM" url="http://sylpheed.sraoss.jp/en/news.html">http://sylpheed.sraoss.jp/en/news.html</ref>
            <ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=683706">http://sourceforge.net/forum/forum.php?forum_id=683706</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.571857">SSA:2007-152-02</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200706-06.xml">GLSA-200706-06</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35699">35699</ref>
            <ref source="MLIST" url="http://mail.gnome.org/archives/balsa-list/2007-July/msg00000.html">[balsa-list] 20070704 balsa-2.3.17 released</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579">SSRT061236</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579">SSRT061236</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579">SSRT061236</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579">SSRT061236</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579">SSRT061236</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref>
            <ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:105">MDKSA-2007:105</ref>
            <ref source="CONFIRM" url="http://fetchmail.berlios.de/fetchmail-SA-2007-01.txt">http://fetchmail.berlios.de/fetchmail-SA-2007-01.txt</ref>
            <ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=305530">http://docs.info.apple.com/article.html?artnum=305530</ref>
            <ref source="CONFIRM" url="http://balsa.gnome.org/download.html">http://balsa.gnome.org/download.html</ref>
            <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc">20070602-01-P</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/0082">ADV-2008-0082</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/2788">ADV-2007-2788</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26415">26415</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26083">26083</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25894">25894</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25858">25858</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25798">25798</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25750">25750</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25664">25664</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25559">25559</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25546">25546</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25534">25534</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25529">25529</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25496">25496</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25476">25476</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25402">25402</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25353">25353</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579">SSRT061236</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apop_protocol" name="apop_protocol">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2007-2586" seq="2007-2586" severity="High" type="CVE" published="2007-05-09" CVSS_version="2.0" CVSS_score="9.3" modified="2010-01-26">
        <desc>
            <descript source="cve">The IOS FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote authenticated users to execute arbitrary code and read and write arbitrary files, as demonstrated by reading startup-config, aka bug ID CSCek55259.</descript>
            <descript source="nvd">Per http://www.cisco.com/warp/public/707/cisco-sa-20070509-iosftp.shtml, authentication is not required.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <access />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CISCO" patch="1" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00808399d0.shtml" adv="1">20070509 Multiple Vulnerabilities in the IOS FTP Server</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34197">cisco-ios-ftp-unauthorized-access(34197)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1018030">1018030</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/23885">23885</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/35334">35334</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/1749" adv="1">ADV-2007-1749</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25199" adv="1">25199</ref>
            <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2009/Jan/0183.html">20090120 Re: Remote Cisco IOS FTP exploit</ref>
            <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5036">oval:org.mitre.oval:def:5036</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cisco" name="ios">
                <vers num="11.3" />
                <vers num="11.3(1)" />
                <vers num="11.3(1)ed" />
                <vers num="11.3(1)t" />
                <vers num="11.3(11)b" />
                <vers num="11.3(11b)" />
                <vers num="11.3(11b)t2" />
                <vers num="11.3(11c)" />
                <vers num="11.3(11d)" />
                <vers num="11.3(2)xa" />
                <vers num="11.3(7)db1" />
                <vers num="11.3(8)db2" />
                <vers num="11.3(8)t1" />
                <vers num="11.3aa" />
                <vers num="11.3da" />
                <vers num="11.3db" />
                <vers num="11.3ha" />
                <vers num="11.3ma" />
                <vers num="11.3na" />
                <vers num="11.3t" />
                <vers num="11.3wa4" />
                <vers num="11.3xa" />
                <vers num="12.0" />
                <vers num="12.0(05)wc8" />
                <vers num="12.0(1)" />
                <vers num="12.0(1)s" />
                <vers num="12.0(1)st" />
                <vers num="12.0(1)w" />
                <vers num="12.0(1)xa3" />
                <vers num="12.0(1)xb" />
                <vers num="12.0(1)xe" />
                <vers num="12.0(10)" />
                <vers num="12.0(10)s3b" />
                <vers num="12.0(10)s7" />
                <vers num="12.0(10)s8" />
                <vers num="12.0(10)w5" />
                <vers num="12.0(10)w5(18f)" />
                <vers num="12.0(10)w5(18g)" />
                <vers num="12.0(10a)" />
                <vers num="12.0(11)s6" />
                <vers num="12.0(11)st4" />
                <vers num="12.0(11a)" />
                <vers num="12.0(12)" />
                <vers num="12.0(12)s3" />
                <vers num="12.0(12)s4" />
                <vers num="12.0(12a)" />
                <vers num="12.0(13)s6" />
                <vers num="12.0(13)s8" />
                <vers num="12.0(13)w5(19c)" />
                <vers num="12.0(13)wt6(1)" />
                <vers num="12.0(13a)" />
                <vers num="12.0(14)" />
                <vers num="12.0(14)s7" />
                <vers num="12.0(14)s8" />
                <vers num="12.0(14)st" />
                <vers num="12.0(14)st3" />
                <vers num="12.0(14)w5(20)" />
                <vers num="12.0(14a)" />
                <vers num="12.0(15)s" />
                <vers num="12.0(15)s3" />
                <vers num="12.0(15)s6" />
                <vers num="12.0(15)s7" />
                <vers num="12.0(15)sc" />
                <vers num="12.0(15)sl" />
                <vers num="12.0(15a)" />
                <vers num="12.0(16)s" />
                <vers num="12.0(16)s10" />
                <vers num="12.0(16)s8" />
                <vers num="12.0(16)s8a" />
                <vers num="12.0(16)sc" />
                <vers num="12.0(16)sc3" />
                <vers num="12.0(16)st" />
                <vers num="12.0(16)st1" />
                <vers num="12.0(16)w5(21)" />
                <vers num="12.0(16.06)s" />
                <vers num="12.0(16a)" />
                <vers num="12.0(17)" />
                <vers num="12.0(17)s" />
                <vers num="12.0(17)s4" />
                <vers num="12.0(17)s7" />
                <vers num="12.0(17)sl" />
                <vers num="12.0(17)sl2" />
                <vers num="12.0(17)sl6" />
                <vers num="12.0(17)sl9" />
                <vers num="12.0(17)st1" />
                <vers num="12.0(17)st5" />
                <vers num="12.0(17)st8" />
                <vers num="12.0(17a)" />
                <vers num="12.0(18)s" />
                <vers num="12.0(18)s5" />
                <vers num="12.0(18)s5a" />
                <vers num="12.0(18)s7" />
                <vers num="12.0(18)sl" />
                <vers num="12.0(18)st1" />
                <vers num="12.0(18)w5(22b)" />
                <vers num="12.0(18b)" />
                <vers num="12.0(19)" />
                <vers num="12.0(19)s" />
                <vers num="12.0(19)s2" />
                <vers num="12.0(19)s2a" />
                <vers num="12.0(19)s4" />
                <vers num="12.0(19)sl" />
                <vers num="12.0(19)sl4" />
                <vers num="12.0(19)sp" />
                <vers num="12.0(19)st" />
                <vers num="12.0(19)st2" />
                <vers num="12.0(19)st6" />
                <vers num="12.0(19a)" />
                <vers num="12.0(2)" />
                <vers num="12.0(2)xc" />
                <vers num="12.0(2)xd" />
                <vers num="12.0(2)xe" />
                <vers num="12.0(2)xf" />
                <vers num="12.0(2)xg" />
                <vers num="12.0(20)sl" />
                <vers num="12.0(20)sp" />
                <vers num="12.0(20)sp1" />
                <vers num="12.0(20)st2" />
                <vers num="12.0(20)st6" />
                <vers num="12.0(20)st7" />
                <vers num="12.0(20)sx" />
                <vers num="12.0(20)w5(22b)" />
                <vers num="12.0(20.4)sp" />
                <vers num="12.0(20a)" />
                <vers num="12.0(21)s" />
                <vers num="12.0(21)s1" />
                <vers num="12.0(21)s3" />
                <vers num="12.0(21)s4a" />
                <vers num="12.0(21)s5a" />
                <vers num="12.0(21)s6" />
                <vers num="12.0(21)s7" />
                <vers num="12.0(21)sl" />
                <vers num="12.0(21)st" />
                <vers num="12.0(21)st6" />
                <vers num="12.0(21)st7" />
                <vers num="12.0(21)sx" />
                <vers num="12.0(21a)" />
                <vers num="12.0(22)s" />
                <vers num="12.0(22)s4" />
                <vers num="12.0(22)s5" />
                <vers num="12.0(22)sy" />
                <vers num="12.0(23)s2" />
                <vers num="12.0(23)s3" />
                <vers num="12.0(23)s4" />
                <vers num="12.0(23)s5" />
                <vers num="12.0(23)s6" />
                <vers num="12.0(23)sx" />
                <vers num="12.0(23)sz" />
                <vers num="12.0(24)s1" />
                <vers num="12.0(24)s2" />
                <vers num="12.0(24)s4" />
                <vers num="12.0(24)s5" />
                <vers num="12.0(24)s6" />
                <vers num="12.0(24.2)s" />
                <vers num="12.0(25)s1" />
                <vers num="12.0(25)w5(27)" />
                <vers num="12.0(25)w5(27c)" />
                <vers num="12.0(25)w5-27d" />
                <vers num="12.0(25.4)s1" />
                <vers num="12.0(26)" />
                <vers num="12.0(26)s" />
                <vers num="12.0(26)s1" />
                <vers num="12.0(26)s2" />
                <vers num="12.0(26)s6" />
                <vers num="12.0(26)w5(28)" />
                <vers num="12.0(26)w5(28a)" />
                <vers num="12.0(27)" />
                <vers num="12.0(27)s" />
                <vers num="12.0(27)s1" />
                <vers num="12.0(27)sv" />
                <vers num="12.0(27)sv1" />
                <vers num="12.0(27)sv2" />
                <vers num="12.0(28)" />
                <vers num="12.0(28)s3" />
                <vers num="12.0(28)s5" />
                <vers num="12.0(28)w5(31a)" />
                <vers num="12.0(28)w5-30b" />
                <vers num="12.0(28)w5-32a" />
                <vers num="12.0(28c)" />
                <vers num="12.0(28d)" />
                <vers num="12.0(2a)" />
                <vers num="12.0(2b)" />
                <vers num="12.0(3)" />
                <vers num="12.0(3)t2" />
                <vers num="12.0(3)xe" />
                <vers num="12.0(3.2)" />
                <vers num="12.0(3.3)s" />
                <vers num="12.0(3.4)t" />
                <vers num="12.0(3.6)w5(9.0.5)" />
                <vers num="12.0(30)s1" />
                <vers num="12.0(30)s2" />
                <vers num="12.0(30)s4" />
                <vers num="12.0(31)s" />
                <vers num="12.0(31)s1" />
                <vers num="12.0(3d)" />
                <vers num="12.0(4)" />
                <vers num="12.0(4)s" />
                <vers num="12.0(4)t" />
                <vers num="12.0(4)xe" />
                <vers num="12.0(4)xe1" />
                <vers num="12.0(4)xm" />
                <vers num="12.0(4)xm1" />
                <vers num="12.0(5)" />
                <vers num="12.0(5)s" />
                <vers num="12.0(5)t" />
                <vers num="12.0(5)t1" />
                <vers num="12.0(5)t2" />
                <vers num="12.0(5)wc" />
                <vers num="12.0(5)wc11" />
                <vers num="12.0(5)wc13" />
                <vers num="12.0(5)wc2" />
                <vers num="12.0(5)wc2b" />
                <vers num="12.0(5)wc3" />
                <vers num="12.0(5)wc3b" />
                <vers num="12.0(5)wc5a" />
                <vers num="12.0(5)wc9" />
                <vers num="12.0(5)wc9a" />
                <vers num="12.0(5)wx" />
                <vers num="12.0(5)xe" />
                <vers num="12.0(5)xk" />
                <vers num="12.0(5)xk2" />
                <vers num="12.0(5)xn" />
                <vers num="12.0(5)xn1" />
                <vers num="12.0(5)xs" />
                <vers num="12.0(5)xu" />
                <vers num="12.0(5)yb4" />
                <vers num="12.0(5.1)xp" />
                <vers num="12.0(5.2)xu" />
                <vers num="12.0(5.3)wc1" />
                <vers num="12.0(5.4)wc1" />
                <vers num="12.0(5a)e" />
                <vers num="12.0(6)" />
                <vers num="12.0(6b)" />
                <vers num="12.0(7)db2" />
                <vers num="12.0(7)dc1" />
                <vers num="12.0(7)s1" />
                <vers num="12.0(7)sc" />
                <vers num="12.0(7)t" />
                <vers num="12.0(7)t2" />
                <vers num="12.0(7)t3" />
                <vers num="12.0(7)wx5(15a)" />
                <vers num="12.0(7)xe" />
                <vers num="12.0(7)xe2" />
                <vers num="12.0(7)xf" />
                <vers num="12.0(7)xf1" />
                <vers num="12.0(7)xk" />
                <vers num="12.0(7)xk2" />
                <vers num="12.0(7)xk3" />
                <vers num="12.0(7)xv" />
                <vers num="12.0(7.4)s" />
                <vers num="12.0(7a)" />
                <vers num="12.0(8)" />
                <vers num="12.0(8)s1" />
                <vers num="12.0(8.0.2)s" />
                <vers num="12.0(8.3)sc" />
                <vers num="12.0(8a)" />
                <vers num="12.0(9)" />
                <vers num="12.0(9)s" />
                <vers num="12.0(9)s8" />
                <vers num="12.0(9a)" />
                <vers num="12.0da" />
                <vers num="12.0db" />
                <vers num="12.0dc" />
                <vers num="12.0ev" />
                <vers num="12.0s" />
                <vers num="12.0sc" />
                <vers num="12.0sl" />
                <vers num="12.0sp" />
                <vers num="12.0st" />
                <vers num="12.0sv" />
                <vers num="12.0sx" />
                <vers num="12.0sy" />
                <vers num="12.0sz" />
                <vers num="12.0t" />
                <vers num="12.0w5" />
                <vers num="12.0wc" />
                <vers num="12.0wt" />
                <vers num="12.0wx" />
                <vers num="12.0xa" />
                <vers num="12.0xb" />
                <vers num="12.0xc" />
                <vers num="12.0xd" />
                <vers num="12.0xe" />
                <vers num="12.0xf" />
                <vers num="12.0xg" />
                <vers num="12.0xh" />
                <vers num="12.0xi" />
                <vers num="12.0xj" />
                <vers num="12.0xk" />
                <vers num="12.0xl" />
                <vers num="12.0xm" />
                <vers num="12.0xn" />
                <vers num="12.0xp" />
                <vers num="12.0xq" />
                <vers num="12.0xr" />
                <vers num="12.0xs" />
                <vers num="12.0xt" />
                <vers num="12.0xu" />
                <vers num="12.0xv" />
                <vers num="12.0xw" />
                <vers num="12.1" />
                <vers num="12.1(1)" />
                <vers num="12.1(1)db" />
                <vers num="12.1(1)db2" />
                <vers num="12.1(1)dc" />
                <vers num="12.1(1)dc2" />
                <vers num="12.1(1)e5" />
                <vers num="12.1(1)ex" />
                <vers num="12.1(1)t" />
                <vers num="12.1(1.3)t" />
                <vers num="12.1(10)" />
                <vers num="12.1(10)aa" />
                <vers num="12.1(10)e" />
                <vers num="12.1(10)e4" />
                <vers num="12.1(10)ec" />
                <vers num="12.1(10)ec1" />
                <vers num="12.1(10)ex" />
                <vers num="12.1(10)ey" />
                <vers num="12.1(10.5)ec" />
                <vers num="12.1(10a)" />
                <vers num="12.1(11)" />
                <vers num="12.1(11)e" />
                <vers num="12.1(11)ea1" />
                <vers num="12.1(11)ec" />
                <vers num="12.1(11.5)e" />
                <vers num="12.1(11a)" />
                <vers num="12.1(11b)" />
                <vers num="12.1(11b)e" />
                <vers num="12.1(11b)e12" />
                <vers num="12.1(11b)e14" />
                <vers num="12.1(12)" />
                <vers num="12.1(12)e" />
                <vers num="12.1(12a)" />
                <vers num="12.1(12b)" />
                <vers num="12.1(12c)" />
                <vers num="12.1(12c)e7" />
                <vers num="12.1(12c)ec" />
                <vers num="12.1(12c)ev01" />
                <vers num="12.1(12c)ew4" />
                <vers num="12.1(13)" />
                <vers num="12.1(13)ay" />
                <vers num="12.1(13)e1" />
                <vers num="12.1(13)e12" />
                <vers num="12.1(13)e13" />
                <vers num="12.1(13)e17" />
                <vers num="12.1(13)e3" />
                <vers num="12.1(13)e7" />
                <vers num="12.1(13)e9" />
                <vers num="12.1(13)ea1" />
                <vers num="12.1(13)ea1c" />
                <vers num="12.1(13)ew" />
                <vers num="12.1(13)ew4" />
                <vers num="12.1(13)ex2" />
                <vers num="12.1(13.4)e" />
                <vers num="12.1(14)" />
                <vers num="12.1(14)e1" />
                <vers num="12.1(14)e10" />
                <vers num="12.1(14)e4" />
                <vers num="12.1(14)e9" />
                <vers num="12.1(14)ea1" />
                <vers num="12.1(14)eb" />
                <vers num="12.1(14.5)" />
                <vers num="12.1(15)bc1" />
                <vers num="12.1(16)" />
                <vers num="12.1(18)" />
                <vers num="12.1(18.4)" />
                <vers num="12.1(19)" />
                <vers num="12.1(19)e" />
                <vers num="12.1(19)e1" />
                <vers num="12.1(19)e6" />
                <vers num="12.1(19)ec" />
                <vers num="12.1(19)ew" />
                <vers num="12.1(19)ew3" />
                <vers num="12.1(19)fc1" />
                <vers num="12.1(19.3)e" />
                <vers num="12.1(1a)t1" />
                <vers num="12.1(1c)" />
                <vers num="12.1(2)e1" />
                <vers num="12.1(2)t" />
                <vers num="12.1(2)xf" />
                <vers num="12.1(2)xf4" />
                <vers num="12.1(2)xf5" />
                <vers num="12.1(20)" />
                <vers num="12.1(20)e" />
                <vers num="12.1(20)e1" />
                <vers num="12.1(20)e2" />
                <vers num="12.1(20)e3" />
                <vers num="12.1(20)e5" />
                <vers num="12.1(20)ea1" />
                <vers num="12.1(20)ea1a" />
                <vers num="12.1(20)ec" />
                <vers num="12.1(20)ec1" />
                <vers num="12.1(20)ec2" />
                <vers num="12.1(20)eo" />
                <vers num="12.1(20)eo1" />
                <vers num="12.1(20)eo3" />
                <vers num="12.1(20)ew" />
                <vers num="12.1(20)ew1" />
                <vers num="12.1(20)ew2" />
                <vers num="12.1(20)ew4" />
                <vers num="12.1(22)" />
                <vers num="12.1(22)e1" />
                <vers num="12.1(22)e3" />
                <vers num="12.1(22)ea3" />
                <vers num="12.1(22)ea4" />
                <vers num="12.1(22)ea4a" />
                <vers num="12.1(22)ea5a" />
                <vers num="12.1(22)ea6" />
                <vers num="12.1(22)eb" />
                <vers num="12.1(23)e1" />
                <vers num="12.1(23)e4" />
                <vers num="12.1(26)e1" />
                <vers num="12.1(26)e3" />
                <vers num="12.1(26)eb1" />
                <vers num="12.1(27)" />
                <vers num="12.1(27b)" />
                <vers num="12.1(2b)" />
                <vers num="12.1(3)" />
                <vers num="12.1(3)db1" />
                <vers num="12.1(3)dc2" />
                <vers num="12.1(3)t" />
                <vers num="12.1(3)xi" />
                <vers num="12.1(3)xp" />
                <vers num="12.1(3)xp4" />
                <vers num="12.1(3)xq" />
                <vers num="12.1(3)xt" />
                <vers num="12.1(3)xt3" />
                <vers num="12.1(3a)" />
                <vers num="12.1(3a)e7" />
                <vers num="12.1(3a)e8" />
                <vers num="12.1(3a)t4" />
                <vers num="12.1(3a)t7" />
                <vers num="12.1(3a)xi8" />
                <vers num="12.1(3b)" />
                <vers num="12.1(4)" />
                <vers num="12.1(4)db" />
                <vers num="12.1(4)db1" />
                <vers num="12.1(4)db2" />
                <vers num="12.1(4)dc" />
                <vers num="12.1(4)dc2" />
                <vers num="12.1(4)e3" />
                <vers num="12.1(4)ea1e" />
                <vers num="12.1(4)xm4" />
                <vers num="12.1(4)xz" />
                <vers num="12.1(4)xz7" />
                <vers num="12.1(4.3)t" />
                <vers num="12.1(4a)" />
                <vers num="12.1(5)da1" />
                <vers num="12.1(5)db1" />
                <vers num="12.1(5)dc" />
                <vers num="12.1(5)dc2" />
                <vers num="12.1(5)ey" />
                <vers num="12.1(5)t" />
                <vers num="12.1(5)t12" />
                <vers num="12.1(5)t15" />
                <vers num="12.1(5)t9" />
                <vers num="12.1(5)xg5" />
                <vers num="12.1(5)xm" />
                <vers num="12.1(5)xm4" />
                <vers num="12.1(5)xm7" />
                <vers num="12.1(5)xr2" />
                <vers num="12.1(5)xs" />
                <vers num="12.1(5)xs2" />
                <vers num="12.1(5)xu1" />
                <vers num="12.1(5)xv" />
                <vers num="12.1(5)xv3" />
                <vers num="12.1(5)xv4" />
                <vers num="12.1(5)xv5" />
                <vers num="12.1(5)xy6" />
                <vers num="12.1(5)ya" />
                <vers num="12.1(5)ya2" />
                <vers num="12.1(5)yb" />
                <vers num="12.1(5)yb4" />
                <vers num="12.1(5)yb5" />
                <vers num="12.1(5)yc" />
                <vers num="12.1(5)yc1" />
                <vers num="12.1(5)yc2" />
                <vers num="12.1(5)yd" />
                <vers num="12.1(5)yd2" />
                <vers num="12.1(5)yd6" />
                <vers num="12.1(5)yf" />
                <vers num="12.1(5)yf2" />
                <vers num="12.1(5)yf4" />
                <vers num="12.1(5)yh" />
                <vers num="12.1(5)yh3" />
                <vers num="12.1(5)yi" />
                <vers num="12.1(5)yi1" />
                <vers num="12.1(5a)e" />
                <vers num="12.1(5c)" />
                <vers num="12.1(5c)e12" />
                <vers num="12.1(5c)ex" />
                <vers num="12.1(5e)" />
                <vers num="12.1(6)" />
                <vers num="12.1(6)e12" />
                <vers num="12.1(6)e8" />
                <vers num="12.1(6)ea1" />
                <vers num="12.1(6)ea1a" />
                <vers num="12.1(6)ea2" />
                <vers num="12.1(6)ea2a" />
                <vers num="12.1(6)ea2b" />
                <vers num="12.1(6)ea2c" />
                <vers num="12.1(6)ey" />
                <vers num="12.1(6)ez1" />
                <vers num="12.1(6)ez2" />
                <vers num="12.1(6.5)" />
                <vers num="12.1(6.5)ec3" />
                <vers num="12.1(6a)" />
                <vers num="12.1(7)" />
                <vers num="12.1(7)cx" />
                <vers num="12.1(7)da2" />
                <vers num="12.1(7)da3" />
                <vers num="12.1(7)ec" />
                <vers num="12.1(7a)e6" />
                <vers num="12.1(7a)ey" />
                <vers num="12.1(7a)ey3" />
                <vers num="12.1(7b)" />
                <vers num="12.1(8)" />
                <vers num="12.1(8)aa1" />
                <vers num="12.1(8)e" />
                <vers num="12.1(8)ea" />
                <vers num="12.1(8)ea1b" />
                <vers num="12.1(8)ea2b" />
                <vers num="12.1(8a)e" />
                <vers num="12.1(8a)ew" />
                <vers num="12.1(8a)ew1" />
                <vers num="12.1(8a)ex" />
                <vers num="12.1(8b)e14" />
                <vers num="12.1(8b)e15" />
                <vers num="12.1(8b)e16" />
                <vers num="12.1(8b)e18" />
                <vers num="12.1(8b)e20" />
                <vers num="12.1(8b)e8" />
                <vers num="12.1(8b)e9" />
                <vers num="12.1(8b)ex4" />
                <vers num="12.1(8c)" />
                <vers num="12.1(9)" />
                <vers num="12.1(9)aa" />
                <vers num="12.1(9)e" />
                <vers num="12.1(9)e3" />
                <vers num="12.1(9)ea" />
                <vers num="12.1(9)ex" />
                <vers num="12.1(9)ex3" />
                <vers num="12.1(9a)" />
                <vers num="12.1aa" />
                <vers num="12.1ax" />
                <vers num="12.1ay" />
                <vers num="12.1az" />
                <vers num="12.1cx" />
                <vers num="12.1da" />
                <vers num="12.1db" />
                <vers num="12.1dc" />
                <vers num="12.1e" />
                <vers num="12.1ea" />
                <vers num="12.1eb" />
                <vers num="12.1ec" />
                <vers num="12.1eo" />
                <vers num="12.1eu" />
                <vers num="12.1ev" />
                <vers num="12.1ew" />
                <vers num="12.1ex" />
                <vers num="12.1ey" />
                <vers num="12.1ez" />
                <vers num="12.1ga" />
                <vers num="12.1gb" />
                <vers num="12.1m" />
                <vers num="12.1s" />
                <vers num="12.1sec" />
                <vers num="12.1t" />
                <vers num="12.1x(l)" />
                <vers num="12.1xa" />
                <vers num="12.1xb" />
                <vers num="12.1xc" />
                <vers num="12.1xd" />
                <vers num="12.1xe" />
                <vers num="12.1xf" />
                <vers num="12.1xg" />
                <vers num="12.1xh" />
                <vers num="12.1xi" />
                <vers num="12.1xj" />
                <vers num="12.1xk" />
                <vers num="12.1xl" />
                <vers num="12.1xm" />
                <vers num="12.1xp" />
                <vers num="12.1xq" />
                <vers num="12.1xr" />
                <vers num="12.1xs" />
                <vers num="12.1xt" />
                <vers num="12.1xu" />
                <vers num="12.1xv" />
                <vers num="12.1xw" />
                <vers num="12.1xx" />
                <vers num="12.1xy" />
                <vers num="12.1xz" />
                <vers num="12.1ya" />
                <vers num="12.1yb" />
                <vers num="12.1yc" />
                <vers num="12.1yd" />
                <vers num="12.1ye" />
                <vers num="12.1yf" />
                <vers num="12.1yh" />
                <vers num="12.1yi" />
                <vers num="12.1yj" />
                <vers num="12.2" />
                <vers num="12.2(1)" />
                <vers num="12.2(1)dx" />
                <vers num="12.2(1)s" />
                <vers num="12.2(1)t" />
                <vers num="12.2(1)xa" />
                <vers num="12.2(1)xd" />
                <vers num="12.2(1)xd1" />
                <vers num="12.2(1)xd3" />
                <vers num="12.2(1)xd4" />
                <vers num="12.2(1)xe" />
                <vers num="12.2(1)xe2" />
                <vers num="12.2(1)xe3" />
                <vers num="12.2(1)xh" />
                <vers num="12.2(1)xq" />
                <vers num="12.2(1)xs" />
                <vers num="12.2(1)xs1" />
                <vers num="12.2(1.1)" />
                <vers num="12.2(1.1)pi" />
                <vers num="12.2(1.4)s" />
                <vers num="12.2(10)da2" />
                <vers num="12.2(10)da4" />
                <vers num="12.2(10.5)s" />
                <vers num="12.2(10g)" />
                <vers num="12.2(11)bc3c" />
                <vers num="12.2(11)ja" />
                <vers num="12.2(11)ja1" />
                <vers num="12.2(11)t" />
                <vers num="12.2(11)t2" />
                <vers num="12.2(11)t3" />
                <vers num="12.2(11)t8" />
                <vers num="12.2(11)t9" />
                <vers num="12.2(11)yp1" />
                <vers num="12.2(11)yu" />
                <vers num="12.2(11)yv" />
                <vers num="12.2(11)yx1" />
                <vers num="12.2(11)yz2" />
                <vers num="12.2(12)" />
                <vers num="12.2(12)da3" />
                <vers num="12.2(12)da8" />
                <vers num="12.2(12)da9" />
                <vers num="12.2(12.02)s" />
                <vers num="12.2(12.02)t" />
                <vers num="12.2(12.05)" />
                <vers num="12.2(12.05)s" />
                <vers num="12.2(12.05)t" />
                <vers num="12.2(12b)" />
                <vers num="12.2(12c)" />
                <vers num="12.2(12g)" />
                <vers num="12.2(12h)" />
                <vers num="12.2(12i)" />
                <vers num="12.2(12m)" />
                <vers num="12.2(13)" />
                <vers num="12.2(13)ja1" />
                <vers num="12.2(13)mc1" />
                <vers num="12.2(13)t" />
                <vers num="12.2(13)t1" />
                <vers num="12.2(13)t14" />
                <vers num="12.2(13)t16" />
                <vers num="12.2(13)t9" />
                <vers num="12.2(13)zc" />
                <vers num="12.2(13)zd" />
                <vers num="12.2(13)zd3" />
                <vers num="12.2(13)zd4" />
                <vers num="12.2(13)ze" />
                <vers num="12.2(13)zf" />
                <vers num="12.2(13)zg" />
                <vers num="12.2(13)zh" />
                <vers num="12.2(13)zh3" />
                <vers num="12.2(13)zh8" />
                <vers num="12.2(13)zj" />
                <vers num="12.2(13)zk" />
                <vers num="12.2(13)zl" />
                <vers num="12.2(13.03)b" />
                <vers num="12.2(13a)" />
                <vers num="12.2(13e)" />
                <vers num="12.2(14)s" />
                <vers num="12.2(14)s13" />
                <vers num="12.2(14)s14" />
                <vers num="12.2(14)s15" />
                <vers num="12.2(14)su2" />
                <vers num="12.2(14)sx1" />
                <vers num="12.2(14)sy" />
                <vers num="12.2(14)sy03" />
                <vers num="12.2(14)sy1" />
                <vers num="12.2(14)sz" />
                <vers num="12.2(14)sz1" />
                <vers num="12.2(14)sz2" />
                <vers num="12.2(14)za" />
                <vers num="12.2(14)za2" />
                <vers num="12.2(14)za8" />
                <vers num="12.2(14.5)" />
                <vers num="12.2(14.5)t" />
                <vers num="12.2(15)b" />
                <vers num="12.2(15)bc" />
                <vers num="12.2(15)bc1" />
                <vers num="12.2(15)bc1f" />
                <vers num="12.2(15)bc2f" />
                <vers num="12.2(15)bc2h" />
                <vers num="12.2(15)bc2i" />
                <vers num="12.2(15)bx" />
                <vers num="12.2(15)bz" />
                <vers num="12.2(15)cx" />
                <vers num="12.2(15)cz3" />
                <vers num="12.2(15)jk2" />
                <vers num="12.2(15)jk4" />
                <vers num="12.2(15)jk5" />
                <vers num="12.2(15)mc1" />
                <vers num="12.2(15)mc2c" />
                <vers num="12.2(15)mc2e" />
                <vers num="12.2(15)sl1" />
                <vers num="12.2(15)t" />
                <vers num="12.2(15)t15" />
                <vers num="12.2(15)t16" />
                <vers num="12.2(15)t17" />
                <vers num="12.2(15)t5" />
                <vers num="12.2(15)t7" />
                <vers num="12.2(15)t8" />
                <vers num="12.2(15)t9" />
                <vers num="12.2(15)xr" />
                <vers num="12.2(15)xr2" />
                <vers num="12.2(15)ys" />
                <vers num="12.2(15)ys_1.2(1)" />
                <vers num="12.2(15)zj" />
                <vers num="12.2(15)zj1" />
                <vers num="12.2(15)zj2" />
                <vers num="12.2(15)zj3" />
                <vers num="12.2(15)zk" />
                <vers num="12.2(15)zl" />
                <vers num="12.2(15)zl1" />
                <vers num="12.2(15)zn" />
                <vers num="12.2(15)zo" />
                <vers num="12.2(15.1)s" />
                <vers num="12.2(16)b" />
                <vers num="12.2(16)b1" />
                <vers num="12.2(16)bx" />
                <vers num="12.2(16.1)b" />
                <vers num="12.2(16.5)s" />
                <vers num="12.2(16f)" />
                <vers num="12.2(17)" />
                <vers num="12.2(17)a" />
                <vers num="12.2(17)zd3" />
                <vers num="12.2(17a)" />
                <vers num="12.2(17a)sxa" />
                <vers num="12.2(17b)sxa" />
                <vers num="12.2(17d)" />
                <vers num="12.2(17d)sx" />
                <vers num="12.2(17d)sxb" />
                <vers num="12.2(17d)sxb10" />
                <vers num="12.2(17d)sxb7" />
                <vers num="12.2(17d)sxb8" />
                <vers num="12.2(17f)" />
                <vers num="12.2(18)ew" />
                <vers num="12.2(18)ew2" />
                <vers num="12.2(18)ew3" />
                <vers num="12.2(18)ew5" />
                <vers num="12.2(18)ewa" />
                <vers num="12.2(18)s" />
                <vers num="12.2(18)s10" />
                <vers num="12.2(18)s6" />
                <vers num="12.2(18)s8" />
                <vers num="12.2(18)s9" />
                <vers num="12.2(18)se" />
                <vers num="12.2(18)so4" />
                <vers num="12.2(18)sv" />
                <vers num="12.2(18)sv3" />
                <vers num="12.2(18)sw" />
                <vers num="12.2(18)sxd1" />
                <vers num="12.2(18)sxd4" />
                <vers num="12.2(18)sxd5" />
                <vers num="12.2(18)sxd6" />
                <vers num="12.2(18)sxd7" />
                <vers num="12.2(18)sxe" />
                <vers num="12.2(18)sxe1" />
                <vers num="12.2(18)sxe3" />
                <vers num="12.2(18)sxf" />
                <vers num="12.2(18.2)" />
                <vers num="12.2(19)" />
                <vers num="12.2(19)b" />
                <vers num="12.2(1b)" />
                <vers num="12.2(1b)da1" />
                <vers num="12.2(1d)" />
                <vers num="12.2(2)b" />
                <vers num="12.2(2)bx" />
                <vers num="12.2(2)by" />
                <vers num="12.2(2)by2" />
                <vers num="12.2(2)dd3" />
                <vers num="12.2(2)t" />
                <vers num="12.2(2)t1" />
                <vers num="12.2(2)t4" />
                <vers num="12.2(2)xa" />
                <vers num="12.2(2)xa1" />
                <vers num="12.2(2)xa5" />
                <vers num="12.2(2)xb" />
                <vers num="12.2(2)xb11" />
                <vers num="12.2(2)xb14" />
                <vers num="12.2(2)xb15" />
                <vers num="12.2(2)xb3" />
                <vers num="12.2(2)xb4" />
                <vers num="12.2(2)xc1" />
                <vers num="12.2(2)xf" />
                <vers num="12.2(2)xg" />
                <vers num="12.2(2)xh" />
                <vers num="12.2(2)xh2" />
                <vers num="12.2(2)xh3" />
                <vers num="12.2(2)xi" />
                <vers num="12.2(2)xi1" />
                <vers num="12.2(2)xi2" />
                <vers num="12.2(2)xj" />
                <vers num="12.2(2)xj1" />
                <vers num="12.2(2)xk" />
                <vers num="12.2(2)xk2" />
                <vers num="12.2(2)xn" />
                <vers num="12.2(2)xr" />
                <vers num="12.2(2)xt" />
                <vers num="12.2(2)xt3" />
                <vers num="12.2(2)xu" />
                <vers num="12.2(2)xu2" />
                <vers num="12.2(2)yc" />
                <vers num="12.2(2.2)t" />
                <vers num="12.2(20)eu" />
                <vers num="12.2(20)eu1" />
                <vers num="12.2(20)eu2" />
                <vers num="12.2(20)ew" />
                <vers num="12.2(20)ew2" />
                <vers num="12.2(20)ew3" />
                <vers num="12.2(20)ewa" />
                <vers num="12.2(20)ewa2" />
                <vers num="12.2(20)ewa3" />
                <vers num="12.2(20)s" />
                <vers num="12.2(20)s1" />
                <vers num="12.2(20)s2" />
                <vers num="12.2(20)s4" />
                <vers num="12.2(20)s7" />
                <vers num="12.2(20)s8" />
                <vers num="12.2(20)s9" />
                <vers num="12.2(20)se3" />
                <vers num="12.2(21)" />
                <vers num="12.2(21a)" />
                <vers num="12.2(21b)" />
                <vers num="12.2(22)ea6" />
                <vers num="12.2(22)s" />
                <vers num="12.2(22)s2" />
                <vers num="12.2(22)sv1" />
                <vers num="12.2(23)" />
                <vers num="12.2(23)sv1" />
                <vers num="12.2(23)sw" />
                <vers num="12.2(23.6)" />
                <vers num="12.2(23a)" />
                <vers num="12.2(23f)" />
                <vers num="12.2(24)" />
                <vers num="12.2(24)sv" />
                <vers num="12.2(24)sv1" />
                <vers num="12.2(25)ewa" />
                <vers num="12.2(25)ewa1" />
                <vers num="12.2(25)ewa3" />
                <vers num="12.2(25)ewa4" />
                <vers num="12.2(25)ex" />
                <vers num="12.2(25)ey" />
                <vers num="12.2(25)ey2" />
                <vers num="12.2(25)ey3" />
                <vers num="12.2(25)ez" />
                <vers num="12.2(25)ez1" />
                <vers num="12.2(25)fx" />
                <vers num="12.2(25)fy" />
                <vers num="12.2(25)s" />
                <vers num="12.2(25)s1" />
                <vers num="12.2(25)s3" />
                <vers num="12.2(25)s4" />
                <vers num="12.2(25)s6" />
                <vers num="12.2(25)se" />
                <vers num="12.2(25)seb" />
                <vers num="12.2(25)seb2" />
                <vers num="12.2(25)seb3" />
                <vers num="12.2(25)seb4" />
                <vers num="12.2(25)sec1" />
                <vers num="12.2(25)sec2" />
                <vers num="12.2(25)sed" />
                <vers num="12.2(25)sg" />
                <vers num="12.2(25)sv2" />
                <vers num="12.2(25)sw" />
                <vers num="12.2(25)sw3a" />
                <vers num="12.2(25)sw4" />
                <vers num="12.2(25)sw4a" />
                <vers num="12.2(26)sv" />
                <vers num="12.2(26)sv1" />
                <vers num="12.2(26b)" />
                <vers num="12.2(27)sbc" />
                <vers num="12.2(27)sv1" />
                <vers num="12.2(27b)" />
                <vers num="12.2(28)" />
                <vers num="12.2(28c)" />
                <vers num="12.2(29a)" />
                <vers num="12.2(3)" />
                <vers num="12.2(3.4)bp" />
                <vers num="12.2(30)s1" />
                <vers num="12.2(31)" />
                <vers num="12.2(3d)" />
                <vers num="12.2(4)" />
                <vers num="12.2(4)b" />
                <vers num="12.2(4)b1" />
                <vers num="12.2(4)b2" />
                <vers num="12.2(4)b3" />
                <vers num="12.2(4)b4" />
                <vers num="12.2(4)bc1" />
                <vers num="12.2(4)bc1a" />
                <vers num="12.2(4)bx" />
                <vers num="12.2(4)ja" />
                <vers num="12.2(4)ja1" />
                <vers num="12.2(4)mb12" />
                <vers num="12.2(4)mb13b" />
                <vers num="12.2(4)mb13c" />
                <vers num="12.2(4)mb3" />
                <vers num="12.2(4)mx" />
                <vers num="12.2(4)mx1" />
                <vers num="12.2(4)t" />
                <vers num="12.2(4)t1" />
                <vers num="12.2(4)t3" />
                <vers num="12.2(4)t6" />
                <vers num="12.2(4)xl" />
                <vers num="12.2(4)xl4" />
                <vers num="12.2(4)xm" />
                <vers num="12.2(4)xm2" />
                <vers num="12.2(4)xr" />
                <vers num="12.2(4)xw" />
                <vers num="12.2(4)xw1" />
                <vers num="12.2(4)ya" />
                <vers num="12.2(4)ya1" />
                <vers num="12.2(4)ya10" />
                <vers num="12.2(4)ya11" />
                <vers num="12.2(4)ya7" />
                <vers num="12.2(4)ya8" />
                <vers num="12.2(4)ya9" />
                <vers num="12.2(4)yb" />
                <vers num="12.2(5)" />
                <vers num="12.2(5)ca1" />
                <vers num="12.2(5d)" />
                <vers num="12.2(6.8)t0a" />
                <vers num="12.2(6.8)t1a" />
                <vers num="12.2(6.8a)" />
                <vers num="12.2(6c)" />
                <vers num="12.2(7)" />
                <vers num="12.2(7)da" />
                <vers num="12.2(7.4)s" />
                <vers num="12.2(7a)" />
                <vers num="12.2(7b)" />
                <vers num="12.2(7c)" />
                <vers num="12.2(8)bc1" />
                <vers num="12.2(8)ja" />
                <vers num="12.2(8)t" />
                <vers num="12.2(8)t10" />
                <vers num="12.2(8)tpc10a" />
                <vers num="12.2(8)yd" />
                <vers num="12.2(8)yw2" />
                <vers num="12.2(8)yw3" />
                <vers num="12.2(8)yy" />
                <vers num="12.2(8)yy3" />
                <vers num="12.2(8)zb7" />
                <vers num="12.2(9)s" />
                <vers num="12.2(9.4)da" />
                <vers num="12.2b" />
                <vers num="12.2bc" />
                <vers num="12.2bw" />
                <vers num="12.2bx" />
                <vers num="12.2by" />
                <vers num="12.2bz" />
                <vers num="12.2ca" />
                <vers num="12.2cx" />
                <vers num="12.2cy" />
                <vers num="12.2cz" />
                <vers num="12.2da" />
                <vers num="12.2dd" />
                <vers num="12.2dx" />
                <vers num="12.2e" />
                <vers num="12.2eu" />
                <vers num="12.2ew" />
                <vers num="12.2ewa" />
                <vers num="12.2ex" />
                <vers num="12.2ey" />
                <vers num="12.2ez" />
                <vers num="12.2f" />
                <vers num="12.2fx" />
                <vers num="12.2fy" />
                <vers num="12.2ja" />
                <vers num="12.2jk" />
                <vers num="12.2jx" />
                <vers num="12.2mb" />
                <vers num="12.2mc" />
                <vers num="12.2mx" />
                <vers num="12.2n" />
                <vers num="12.2pb" />
                <vers num="12.2pi" />
                <vers num="12.2s" />
                <vers num="12.2sa" />
                <vers num="12.2sbc" />
                <vers num="12.2se" />
                <vers num="12.2sea" />
                <vers num="12.2seb" />
                <vers num="12.2sec" />
                <vers num="12.2sg" />
                <vers num="12.2sh" />
                <vers num="12.2so" />
                <vers num="12.2su" />
                <vers num="12.2sv" />
                <vers num="12.2sw" />
                <vers num="12.2sx" />
                <vers num="12.2sxa" />
                <vers num="12.2sxb" />
                <vers num="12.2sxd" />
                <vers num="12.2sxe" />
                <vers num="12.2sxf" />
                <vers num="12.2sy" />
                <vers num="12.2sz" />
                <vers num="12.2t" />
                <vers num="12.2tpc" />
                <vers num="12.2x" />
                <vers num="12.2xa" />
                <vers num="12.2xb" />
                <vers num="12.2xc" />
                <vers num="12.2xd" />
                <vers num="12.2xe" />
                <vers num="12.2xf" />
                <vers num="12.2xg" />
                <vers num="12.2xh" />
                <vers num="12.2xi" />
                <vers num="12.2xj" />
                <vers num="12.2xk" />
                <vers num="12.2xl" />
                <vers num="12.2xm" />
                <vers num="12.2xn" />
                <vers num="12.2xq" />
                <vers num="12.2xr" />
                <vers num="12.2xs" />
                <vers num="12.2xt" />
                <vers num="12.2xu" />
                <vers num="12.2xv" />
                <vers num="12.2xw" />
                <vers num="12.2xz" />
                <vers num="12.2ya" />
                <vers num="12.2yb" />
                <vers num="12.2yc" />
                <vers num="12.2yd" />
                <vers num="12.2ye" />
                <vers num="12.2yf" />
                <vers num="12.2yg" />
                <vers num="12.2yh" />
                <vers num="12.2yj" />
                <vers num="12.2yk" />
                <vers num="12.2yl" />
                <vers num="12.2ym" />
                <vers num="12.2yn" />
                <vers num="12.2yo" />
                <vers num="12.2yp" />
                <vers num="12.2yq" />
                <vers num="12.2yr" />
                <vers num="12.2ys" />
                <vers num="12.2yt" />
                <vers num="12.2yu" />
                <vers num="12.2yv" />
                <vers num="12.2yw" />
                <vers num="12.2yx" />
                <vers num="12.2yy" />
                <vers num="12.2yz" />
                <vers num="12.2za" />
                <vers num="12.2zb" />
                <vers num="12.2zc" />
                <vers num="12.2zd" />
                <vers num="12.2ze" />
                <vers num="12.2zf" />
                <vers num="12.2zg" />
                <vers num="12.2zh" />
                <vers num="12.2zi" />
                <vers num="12.2zj" />
                <vers num="12.2zk" />
                <vers num="12.2zl" />
                <vers num="12.2zm" />
                <vers num="12.2zn" />
                <vers num="12.2zo" />
                <vers num="12.2zp" />
                <vers num="12.2zq" />
                <vers num="12.3" />
                <vers num="12.3(10)" />
                <vers num="12.3(10c)" />
                <vers num="12.3(10d)" />
                <vers num="12.3(10e)" />
                <vers num="12.3(11)" />
                <vers num="12.3(11)t" />
                <vers num="12.3(11)t4" />
                <vers num="12.3(11)t5" />
                <vers num="12.3(11)t6" />
                <vers num="12.3(11)t8" />
                <vers num="12.3(11)t9" />
                <vers num="12.3(11)xl" />
                <vers num="12.3(11)xl3" />
                <vers num="12.3(11)yf" />
                <vers num="12.3(11)yf2" />
                <vers num="12.3(11)yf3" />
                <vers num="12.3(11)yf4" />
                <vers num="12.3(11)yj" />
                <vers num="12.3(11)yk" />
                <vers num="12.3(11)yk1" />
                <vers num="12.3(11)yk2" />
                <vers num="12.3(11)yl" />
                <vers num="12.3(11)yn" />
                <vers num="12.3(11)yr" />
                <vers num="12.3(11)ys" />
                <vers num="12.3(11)ys1" />
                <vers num="12.3(11)yw" />
                <vers num="12.3(12)" />
                <vers num="12.3(12b)" />
                <vers num="12.3(12e)" />
                <vers num="12.3(13)" />
                <vers num="12.3(13a)" />
                <vers num="12.3(13a)bc" />
                <vers num="12.3(13a)bc1" />
                <vers num="12.3(13b)" />
                <vers num="12.3(14)t" />
                <vers num="12.3(14)t2" />
                <vers num="12.3(14)t4" />
                <vers num="12.3(14)t5" />
                <vers num="12.3(14)ym4" />
                <vers num="12.3(14)yq" />
                <vers num="12.3(14)yq1" />
                <vers num="12.3(14)yq3" />
                <vers num="12.3(14)yq4" />
                <vers num="12.3(14)yt" />
                <vers num="12.3(14)yt1" />
                <vers num="12.3(14)yu" />
                <vers num="12.3(14)yu1" />
                <vers num="12.3(15)" />
                <vers num="12.3(15b)" />
                <vers num="12.3(16)" />
                <vers num="12.3(1a)" />
                <vers num="12.3(2)ja" />
                <vers num="12.3(2)ja5" />
                <vers num="12.3(2)jk" />
                <vers num="12.3(2)jk1" />
                <vers num="12.3(2)t3" />
                <vers num="12.3(2)t8" />
                <vers num="12.3(2)xa4" />
                <vers num="12.3(2)xa5" />
                <vers num="12.3(2)xc1" />
                <vers num="12.3(2)xc2" />
                <vers num="12.3(2)xc3" />
                <vers num="12.3(2)xc4" />
                <vers num="12.3(2)xe3" />
                <vers num="12.3(2)xe4" />
                <vers num="12.3(3e)" />
                <vers num="12.3(3h)" />
                <vers num="12.3(3i)" />
                <vers num="12.3(4)eo1" />
                <vers num="12.3(4)ja" />
                <vers num="12.3(4)ja1" />
                <vers num="12.3(4)t" />
                <vers num="12.3(4)t1" />
                <vers num="12.3(4)t2" />
                <vers num="12.3(4)t3" />
                <vers num="12.3(4)t4" />
                <vers num="12.3(4)t8" />
                <vers num="12.3(4)tpc11a" />
                <vers num="12.3(4)xd" />
                <vers num="12.3(4)xd1" />
                <vers num="12.3(4)xd2" />
                <vers num="12.3(4)xe4" />
                <vers num="12.3(4)xg1" />
                <vers num="12.3(4)xg2" />
                <vers num="12.3(4)xg4" />
                <vers num="12.3(4)xg5" />
                <vers num="12.3(4)xh" />
                <vers num="12.3(4)xk" />
                <vers num="12.3(4)xk1" />
                <vers num="12.3(4)xk3" />
                <vers num="12.3(4)xk4" />
                <vers num="12.3(4)xq" />
                <vers num="12.3(4)xq1" />
                <vers num="12.3(5)" />
                <vers num="12.3(5)b1" />
                <vers num="12.3(5a)" />
                <vers num="12.3(5a)b" />
                <vers num="12.3(5a)b2" />
                <vers num="12.3(5a)b5" />
                <vers num="12.3(5b)" />
                <vers num="12.3(5c)" />
                <vers num="12.3(5e)" />
                <vers num="12.3(5f)" />
                <vers num="12.3(6)" />
                <vers num="12.3(6a)" />
                <vers num="12.3(6d)" />
                <vers num="12.3(6e)" />
                <vers num="12.3(6f)" />
                <vers num="12.3(7)ja" />
                <vers num="12.3(7)ja1" />
                <vers num="12.3(7)jx" />
                <vers num="12.3(7)t" />
                <vers num="12.3(7)t10" />
                <vers num="12.3(7)t12" />
                <vers num="12.3(7)t4" />
                <vers num="12.3(7)t8" />
                <vers num="12.3(7)t9" />
                <vers num="12.3(7)xi3" />
                <vers num="12.3(7)xi4" />
                <vers num="12.3(7)xi7" />
                <vers num="12.3(7)xr3" />
                <vers num="12.3(7)xr4" />
                <vers num="12.3(7)xr6" />
                <vers num="12.3(7.7)" />
                <vers num="12.3(8)ja" />
                <vers num="12.3(8)ja1" />
                <vers num="12.3(8)t11" />
                <vers num="12.3(8)t4" />
                <vers num="12.3(8)t7" />
                <vers num="12.3(8)t8" />
                <vers num="12.3(8)t9" />
                <vers num="12.3(8)xu2" />
                <vers num="12.3(8)xy4" />
                <vers num="12.3(8)xy5" />
                <vers num="12.3(8)xy6" />
                <vers num="12.3(8)ya1" />
                <vers num="12.3(8)yd" />
                <vers num="12.3(8)yf" />
                <vers num="12.3(8)yg" />
                <vers num="12.3(8)yg1" />
                <vers num="12.3(8)yg2" />
                <vers num="12.3(8)yg3" />
                <vers num="12.3(8)yh" />
                <vers num="12.3(8)yi" />
                <vers num="12.3(8)yi1" />
                <vers num="12.3(8)yi3" />
                <vers num="12.3(9)" />
                <vers num="12.3(9a)bc" />
                <vers num="12.3(9a)bc2" />
                <vers num="12.3(9a)bc6" />
                <vers num="12.3(9a)bc7" />
                <vers num="12.3(9d)" />
                <vers num="12.3(9e)" />
                <vers num="12.3b" />
                <vers num="12.3bc" />
                <vers num="12.3bw" />
                <vers num="12.3j" />
                <vers num="12.3ja" />
                <vers num="12.3jea" />
                <vers num="12.3jeb" />
                <vers num="12.3jec" />
                <vers num="12.3jk" />
                <vers num="12.3jx" />
                <vers num="12.3t" />
                <vers num="12.3tpc" />
                <vers num="12.3xa" />
                <vers num="12.3xb" />
                <vers num="12.3xc" />
                <vers num="12.3xd" />
                <vers num="12.3xe" />
                <vers num="12.3xf" />
                <vers num="12.3xg" />
                <vers num="12.3xh" />
                <vers num="12.3xi" />
                <vers num="12.3xj" />
                <vers num="12.3xk" />
                <vers num="12.3xl" />
                <vers num="12.3xm" />
                <vers num="12.3xn" />
                <vers num="12.3xq" />
                <vers num="12.3xr" />
                <vers num="12.3xs" />
                <vers num="12.3xt" />
                <vers num="12.3xu" />
                <vers num="12.3xv" />
                <vers num="12.3xw" />
                <vers num="12.3xx" />
                <vers num="12.3xy" />
                <vers num="12.3xz" />
                <vers num="12.3ya" />
                <vers num="12.3yb" />
                <vers num="12.3yc" />
                <vers num="12.3yd" />
                <vers num="12.3ye" />
                <vers num="12.3yf" />
                <vers num="12.3yg" />
                <vers num="12.3yh" />
                <vers num="12.3yi" />
                <vers num="12.3yj" />
                <vers num="12.3yk" />
                <vers num="12.3yl" />
                <vers num="12.3ym" />
                <vers num="12.3yn" />
                <vers num="12.3yq" />
                <vers num="12.3yr" />
                <vers num="12.3ys" />
                <vers num="12.3yt" />
                <vers num="12.3yu" />
                <vers num="12.3yw" />
                <vers num="12.3yx" />
                <vers num="12.3yz" />
                <vers num="12.4" />
                <vers num="12.4(1)" />
                <vers num="12.4(1b)" />
                <vers num="12.4(1c)" />
                <vers num="12.4(2)mr" />
                <vers num="12.4(2)mr1" />
                <vers num="12.4(2)t" />
                <vers num="12.4(2)t1" />
                <vers num="12.4(2)t2" />
                <vers num="12.4(2)t3" />
                <vers num="12.4(2)t4" />
                <vers num="12.4(2)xa" />
                <vers num="12.4(2)xb" />
                <vers num="12.4(2)xb2" />
                <vers num="12.4(3)" />
                <vers num="12.4(3)t2" />
                <vers num="12.4(3a)" />
                <vers num="12.4(3b)" />
                <vers num="12.4(3d)" />
                <vers num="12.4(4)mr" />
                <vers num="12.4(4)t" />
                <vers num="12.4(4)t2" />
                <vers num="12.4(5)" />
                <vers num="12.4(5b)" />
                <vers num="12.4(6)t" />
                <vers num="12.4(6)t1" />
                <vers num="12.4(7)" />
                <vers num="12.4(7a)" />
                <vers num="12.4(8)" />
                <vers num="12.4(9)t" />
                <vers num="12.4ja" />
                <vers num="12.4jda" />
                <vers num="12.4jk" />
                <vers num="12.4jl" />
                <vers num="12.4jma" />
                <vers num="12.4jmb" />
                <vers num="12.4jx" />
                <vers num="12.4md" />
                <vers num="12.4mr" />
                <vers num="12.4sw" />
                <vers num="12.4t" />
                <vers num="12.4xa" />
                <vers num="12.4xc" />
                <vers num="12.4xd" />
                <vers num="12.4xe" />
                <vers num="12.4xn" />
                <vers num="12.4xp" />
                <vers num="12.4xt" />
                <vers num="12.4xv" />
                <vers num="12.4xw" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2007-2872" seq="2007-2872" severity="Medium" type="CVE" published="2007-06-04" CVSS_version="2.0" CVSS_score="6.8" modified="2010-01-25">
        <desc>
            <descript source="cve">Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <vuln_types>
            <input />
        </vuln_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.php.net/releases/5_2_3.php">http://www.php.net/releases/5_2_3.php</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.html">FEDORA-2007-2215</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00354.html">FEDORA-2007-709</ref>
            <ref source="CONFIRM" url="https://launchpad.net/bugs/173043">https://launchpad.net/bugs/173043</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-1702">https://issues.rpath.com/browse/RPL-1702</ref>
            <ref source="CONFIRM" url="https://issues.rpath.com/browse/RPL-1693">https://issues.rpath.com/browse/RPL-1693</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39398">php-chunksplit-security-bypass(39398)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2008/0059">ADV-2008-0059</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-549-1">USN-549-1</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-549-2">USN-549-2</ref>
            <ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0023/">2007-0023</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1018186">1018186</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/24261">24261</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/491693/100/0/threaded">HPSBUX02332</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/491693/100/0/threaded">HPSBUX02332</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470244/100/0/threaded">20070601 SEC Consult SA-20070601-0 :: PHP chunk_split() integer overflow</ref>
            <ref source="MISC" url="http://www.sec-consult.com/291.html">http://www.sec-consult.com/291.html</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0891.html">RHSA-2007:0891</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0890.html">RHSA-2007:0890</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0888.html">RHSA-2007:0888</ref>
            <ref source="CONFIRM" url="http://www.php.net/releases/4_4_8.php">http://www.php.net/releases/4_4_8.php</ref>
            <ref source="CONFIRM" url="http://www.php.net/ChangeLog-4.php">http://www.php.net/ChangeLog-4.php</ref>
            <ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.020.html">OpenPKG-SA-2007.020</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:187">MDKSA-2007:187</ref>
            <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml">GLSA-200710-02</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/3386" adv="1">ADV-2007-3386</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2007/2061" adv="1">ADV-2007-2061</ref>
            <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm">http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.482863">SSA:2007-152-01</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28318" adv="1">28318</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27864" adv="1">27864</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27545" adv="1">27545</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27377" adv="1">27377</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27351" adv="1">27351</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27110" adv="1">27110</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27102" adv="1">27102</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/27037" adv="1">27037</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26967" adv="1">26967</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26930" adv="1">26930</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26895" adv="1">26895</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26871" adv="1">26871</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26838" adv="1">26838</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26231" adv="1">26231</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/26048" adv="1">26048</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25535" adv="1">25535</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/25456" adv="1">25456</ref>
            <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0889.html">RHSA-2007:0889</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html">SUSE-SA:2007:044</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501">HPSBUX02308</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501">HPSBUX02308</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501">HPSBUX02308</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">SSRT071447</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">SSRT071447</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">SSRT071447</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">SSRT071447</ref>
            <ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/491693/100/0/threaded">HPSBUX02332</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/0398">ADV-2008-0398</ref>
            <ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.335136">SSA:2008-045-03</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30040">30040</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28936">28936</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28750">28750</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/28658">28658</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html">SUSE-SA:2008:004</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501">HPSBUX02308</ref>
        </refs>
        <vuln_soft>
            <prod vendor="php" name="php">
                <vers num="4.4.7" prev="1" />
                <vers num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.2" />
                <vers num="5.0.3" />
                <vers num="5.0.4" />
                <vers num="5.0.5" />
                <vers num="5.1" />
                <vers num="5.1.0" />
                <vers num="5.1.1" />
                <vers num="5.1.2" />
                <vers num="5.1.3" />
                <vers num="5.1.4" />
                <vers num="5.1.5" />
                <vers num="5.1.6" />
                <vers num="5.2.0" />
                <vers num="5.2.1" />
                <vers num="5.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2008-2079" seq="2008-2079" severity="Medium" type="CVE" published="2008-05-05" CVSS_version="2.0" CVSS_score="4.6" modified="2010-01-26">
        <desc>
            <descript source="cve">MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future.</descript>
            <descript source="nvd">Per http://www.securityfocus.com/bid/29106 and http://secunia.com/advisories/32222, this vulnerability is remotely exploitable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/31681">31681</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/29106">29106</ref>
            <ref source="CONFIRM" patch="1" url="http://bugs.mysql.com/bug.php?id=32167">http://bugs.mysql.com/bug.php?id=32167</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42267">mysql-myisam-security-bypass(42267)</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1019995">1019995</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0768.html">RHSA-2008:0768</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0510.html">RHSA-2008:0510</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0505.html">RHSA-2008:0505</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:150">MDVSA-2008:150</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:149">MDVSA-2008:149</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/2780" adv="1">ADV-2008-2780</ref>
            <ref source="VUPEN" url="http://www.frsirt.com/english/advisories/2008/1472/references" adv="1">ADV-2008-1472</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1608">DSA-1608</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3865">http://support.apple.com/kb/HT3865</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3216">http://support.apple.com/kb/HT3216</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36701" adv="1">36701</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32222" adv="1">32222</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31687">31687</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31226">31226</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/31066">31066</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30134" adv="1">30134</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html">SUSE-SR:2008:017</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html">APPLE-SA-2009-09-10-2</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html">APPLE-SA-2008-10-09</ref>
            <ref source="CONFIRM" url="http://dev.mysql.com/doc/refman/6.0/en/news-6-0-5.html">http://dev.mysql.com/doc/refman/6.0/en/news-6-0-5.html</ref>
            <ref source="CONFIRM" url="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-24.html">http://dev.mysql.com/doc/refman/5.1/en/news-5-1-24.html</ref>
            <ref source="CONFIRM" url="http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-60.html">http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-60.html</ref>
            <ref source="CONFIRM" url="http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.html">http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mysql" name="mysql">
                <vers num="4.1.0" />
                <vers num="4.1.1" />
                <vers num="4.1.10" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.1.13" />
                <vers num="4.1.14" />
                <vers num="4.1.15" />
                <vers num="4.1.16" />
                <vers num="4.1.17" />
                <vers num="4.1.18" />
                <vers num="4.1.19" />
                <vers num="4.1.2" />
                <vers num="4.1.20" />
                <vers num="4.1.21" />
                <vers num="4.1.22" />
                <vers num="4.1.23" prev="1" />
                <vers edition="alpha" num="5.0.0" />
                <vers num="5.0.1" />
                <vers num="5.0.10" />
                <vers num="5.0.10a" />
                <vers num="5.0.11" />
                <vers num="5.0.12" />
                <vers num="5.0.13" />
                <vers num="5.0.15" />
                <vers num="5.0.19" />
                <vers num="5.0.1a" />
                <vers num="5.0.2" />
                <vers num="5.0.21" />
                <vers num="5.0.22" />
                <vers num="5.0.23" />
                <vers num="5.0.24" />
                <vers num="5.0.24a" />
                <vers num="5.0.25" />
                <vers num="5.0.3" />
                <vers num="5.0.30" />
                <vers num="5.0.32" />
                <vers num="5.0.33" />
                <vers num="5.0.36" />
                <vers num="5.0.37" />
                <vers num="5.0.38" />
                <vers num="5.0.3a" />
                <vers num="5.0.4" />
                <vers num="5.0.41" />
                <vers num="5.0.42" />
                <vers num="5.0.44" />
                <vers num="5.0.45" />
                <vers num="5.0.4a" />
                <vers num="5.0.5.0.21" />
                <vers num="5.0.50" />
                <vers num="5.0.51" />
                <vers num="5.0.52" />
                <vers num="5.0.54" />
                <vers num="5.0.56" />
                <vers num="5.0.6" />
                <vers num="5.0.9" />
                <vers num="5.1.11" />
                <vers num="5.1.12" />
                <vers num="5.1.14" />
                <vers num="5.1.15" />
                <vers num="5.1.16" />
                <vers num="5.1.17" />
                <vers num="5.1.18" />
                <vers num="5.1.19" />
                <vers num="5.1.20" />
                <vers num="5.1.21" />
                <vers num="5.1.22" />
                <vers num="5.1.23" />
                <vers num="5.1.23a" prev="1" />
                <vers num="5.1.3" />
                <vers num="5.1.4" />
                <vers num="5.1.5" />
                <vers num="5.1.5a" />
                <vers num="5.1.6" />
                <vers num="5.1.7" />
                <vers num="5.1.9" />
                <vers num="6.0.0" />
                <vers num="6.0.1" />
                <vers num="6.0.2" />
                <vers num="6.0.3" />
                <vers num="6.0.4" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2008-4097" seq="2008-4097" severity="Medium" type="CVE" published="2008-09-18" CVSS_version="2.0" CVSS_score="4.6" modified="2010-01-26">
        <desc>
            <descript source="cve">MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are associated with symlinks within pathnames for subdirectories of the MySQL home data directory, which are followed when tables are created in the future. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-2079.</descript>
            <descript source="nvd">Per http://www.securityfocus.com/bid/29106 this vulnerability is remotely exploitable.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/45648">mysql-myisam-symlinks-security-bypass(45648)</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/09/16/3">[oss-security] 20080916 Re: CVE request: MySQL incomplete fix for CVE-2008-2079</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/09/09/20">[oss-security] 20080909 Re: CVE request: MySQL incomplete fix for CVE-2008-2079</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:094">MDVSA-2009:094</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/32759" adv="1">32759</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html">SUSE-SR:2008:025</ref>
            <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=480292#25">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=480292#25</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mysql" name="mysql">
                <vers num="5.0.51a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-0375" seq="2009-0375" severity="High" type="CVE" published="2009-02-08" CVSS_version="2.0" CVSS_score="9.3" modified="2010-01-28">
        <desc>
            <descript source="cve">Buffer overflow in a DLL file in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a crafted Internet Video Recording (IVR) file with a filename length field containing a large integer, which triggers overwrite of an arbitrary memory location with a 0x00 byte value, related to use of RealPlayer through a Windows Explorer plugin.</descript>
            <descript source="nvd">Per http://www.fortiguardcenter.com/advisory/FGA-2009-04.html:

"It should be noted that the victim does not necessarily have to open the malicious file for exploitation to occur: the vulnerabilities lie in a DLL that is also used as a plugin for the Windows Explorer shell. A successful attack could take place by merely previewing the IVR file through Windows Explorer. "</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/48567">realplayer-ivr-bo(48567)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0178">ADV-2010-0178</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/33652">33652</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/500722/100/0/threaded">20090206 RealNetworks RealPlayer IVR File Processing Multiple Code Execute Vulnerabilities</ref>
            <ref source="MISC" url="http://www.fortiguardcenter.com/advisory/FGA-2009-04.html">http://www.fortiguardcenter.com/advisory/FGA-2009-04.html</ref>
            <ref source="CONFIRM" url="http://service.real.com/realplayer/security/01192010_player/en/">http://service.real.com/realplayer/security/01192010_player/en/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38218">38218</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33810">33810</ref>
        </refs>
        <vuln_soft>
            <prod vendor="realnetworks" name="realplayer">
                <vers num="11" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-0376" seq="2009-0376" severity="High" type="CVE" published="2009-02-08" CVSS_version="2.0" CVSS_score="9.3" modified="2010-01-28">
        <desc>
            <descript source="cve">Heap-based buffer overflow in a DLL file in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a crafted Internet Video Recording (IVR) file with a modified field that controls an unspecified structure length and triggers heap corruption, related to use of RealPlayer through a Windows Explorer plugin.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/48568">realplayer-ivr-code-execution(48568)</ref>
            <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-10-009/">http://www.zerodayinitiative.com/advisories/ZDI-10-009/</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0178">ADV-2010-0178</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/33652">33652</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/509097/100/0/threaded">20100121 ZDI-10-009: RealNetworks RealPlayer IVR Format Remote Code Execution Vulnerability</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/500722/100/0/threaded">20090206 RealNetworks RealPlayer IVR File Processing Multiple Code Execute Vulnerabilities</ref>
            <ref source="MISC" url="http://www.fortiguardcenter.com/advisory/FGA-2009-04.html">http://www.fortiguardcenter.com/advisory/FGA-2009-04.html</ref>
            <ref source="CONFIRM" url="http://service.real.com/realplayer/security/01192010_player/en/">http://service.real.com/realplayer/security/01192010_player/en/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38218">38218</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/33810">33810</ref>
        </refs>
        <vuln_soft>
            <prod vendor="realnetworks" name="realplayer">
                <vers num="11" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2009-0689" seq="2009-0689" severity="Medium" type="CVE" published="2009-07-01" CVSS_version="2.0" CVSS_score="6.8" modified="2010-01-23">
        <desc>
            <descript source="cve">Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/35510">35510</ref>
            <ref source="CONFIRM" patch="1" url="http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gdtoa/misc.c" adv="1">http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gdtoa/misc.c</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1022478">1022478</ref>
            <ref source="CONFIRM" patch="1" url="http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gdtoa/gdtoaimp.h">http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gdtoa/gdtoaimp.h</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=516862">https://bugzilla.mozilla.org/show_bug.cgi?id=516862</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=516396">https://bugzilla.mozilla.org/show_bug.cgi?id=516396</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0094">ADV-2010-0094</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3334">ADV-2009-3334</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3299">ADV-2009-3299</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3297">ADV-2009-3297</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/508423/100/0/threaded">20091210 Camino 1.6.10 Remote Array Overrun (Arbitrary code execution)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/508417/100/0/threaded">20091210 Flock 2.5.2 Remote Array Overrun (Arbitrary code execution)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507979/100/0/threaded">20091120 SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507977/100/0/threaded">20091120 K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution)</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1601.html">RHSA-2009:1601</ref>
            <ref source="CONFIRM" url="http://www.opera.com/support/kb/view/942/">http://www.opera.com/support/kb/view/942/</ref>
            <ref source="CONFIRM" url="http://www.mozilla.org/security/announce/2009/mfsa2009-59.html">http://www.mozilla.org/security/announce/2009/mfsa2009-59.html</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:330">MDVSA-2009:330</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:294">MDVSA-2009:294</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-272909-1">272909</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/81">20100108 MacOS X 10.5/10.6 libc/strtod(3) buffer overflow</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/78">20091211 Thunderbird 2.0.0.23 (lib) Remote Array Overrun (Arbitrary code execution)</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/77">20091211 Sunbird 0.9 Array Overrun (code execution)</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/76">20091211 Camino 1.6.10 Remote Array Overrun (Arbitrary code execution)</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/75">20091211 Flock 2.5.2 Remote Array Overrun (Arbitrary code execution)</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/73">20091120 Opera 10.01 Remote Array Overrun (Arbitrary code execution)</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/72">20091120 K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution)</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/71">20091120 SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution)</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/69">20091030 Multiple BSD printf(1) and multiple dtoa/*printf(3) vulnerabilities</ref>
            <ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/63">20090625 Multiple Vendors libc/gdtoa printf(3) Array Overrun</ref>
            <ref source="MISC" url="http://secunia.com/secunia_research/2009-35/">http://secunia.com/secunia_research/2009-35/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38066">38066</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37683">37683</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37682">37682</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37431">37431</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html">SUSE-SR:2009:018</ref>
        </refs>
        <vuln_soft>
            <prod vendor="freebsd" name="freebsd">
                <vers edition="release" num="6.4" />
                <vers edition="release_p2" num="6.4" />
                <vers edition="release_p3" num="6.4" />
                <vers edition="release_p4" num="6.4" />
                <vers edition="release_p5" num="6.4" />
                <vers edition="stable" num="6.4" />
                <vers edition="pre-release" num="7.2" />
                <vers edition="stable" num="7.2" />
            </prod>
            <prod vendor="netbsd" name="netbsd">
                <vers num="5.0" />
            </prod>
            <prod vendor="openbsd" name="openbsd">
                <vers num="4.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-2285" seq="2009-2285" severity="Medium" type="CVE" published="2009-07-01" CVSS_version="2.0" CVSS_score="4.3" modified="2010-02-05">
        <desc>
            <descript source="cve">Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafted TIFF image, a different vulnerability than CVE-2008-2327.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00714.html">FEDORA-2009-7763</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00655.html">FEDORA-2009-7717</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00230.html">FEDORA-2009-7417</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00161.html">FEDORA-2009-7358</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00142.html">FEDORA-2009-7335</ref>
            <ref source="CONFIRM" url="https://bugs.launchpad.net/ubuntu/+source/tiff/+bug/380149">https://bugs.launchpad.net/ubuntu/+source/tiff/+bug/380149</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0173">ADV-2010-0173</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3184">ADV-2009-3184</ref>
            <ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-797-1">USN-797-1</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1159.html">RHSA-2009:1159</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/06/29/5">[oss-security] 20090629 CVE Request -- libtiff [was: Re: libtiff buffer underflow in LZWDecodeCompat]</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/06/23/1">[oss-security] 20090623 Re: libtiff buffer underflow in LZWDecodeCompat</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/06/22/1">[oss-security] 20090621 libtiff buffer underflow in LZWDecodeCompat</ref>
            <ref source="MISC" url="http://www.lan.st/showthread.php?t=1856&amp;page=3">http://www.lan.st/showthread.php?t=1856&amp;page=3</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1835">DSA-1835</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4013">http://support.apple.com/kb/HT4013</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4004">http://support.apple.com/kb/HT4004</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT3937">http://support.apple.com/kb/HT3937</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-267808-1">267808</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200908-03.xml">GLSA-200908-03</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38241">38241</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36831">36831</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36194">36194</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35912">35912</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35883">35883</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35866">35866</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35716">35716</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35695">35695</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html">APPLE-SA-2010-01-19-1</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html">APPLE-SA-2010-02-02-1</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html">APPLE-SA-2009-11-09-1</ref>
            <ref source="CONFIRM" url="http://bugzilla.maptools.org/show_bug.cgi?id=2065">http://bugzilla.maptools.org/show_bug.cgi?id=2065</ref>
        </refs>
        <vuln_soft>
            <prod vendor="libtiff" name="libtiff">
                <vers num="3.8.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-2439" seq="2009-2439" severity="High" type="CVE" published="2009-07-13" CVSS_version="2.0" CVSS_score="7.5" modified="2010-02-08">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in Web Development House Alibaba (aka Alibaba.com) Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1838" adv="1">ADV-2009-1838</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35741" adv="1">35741</ref>
            <ref source="MISC" url="http://packetstormsecurity.org/0907-exploits/alibabaclone-sql.txt">http://packetstormsecurity.org/0907-exploits/alibabaclone-sql.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="web_development_house" name="alibaba_clone">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" name="CVE-2009-2407" seq="2009-2407" severity="Medium" type="CVE" published="2009-07-31" CVSS_version="2.0" CVSS_score="6.9" modified="2010-01-27">
        <desc>
            <descript source="cve">Heap-based buffer overflow in the parse_tag_3_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to a large encrypted key size in a Tag 3 packet.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
            <user_init />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/2041" adv="1">ADV-2009-2041</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/35850">35850</ref>
            <ref source="DEBIAN" patch="1" url="http://www.debian.org/security/2009/dsa-1844">DSA-1844</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/36051" adv="1">36051</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/36045" adv="1">36045</ref>
            <ref source="SECUNIA" patch="1" url="http://secunia.com/advisories/35985" adv="1">35985</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00223.html">FEDORA-2009-8144</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00166.html">FEDORA-2009-8264</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3316">ADV-2009-3316</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-807-1">USN-807-1</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/505337/100/0/threaded">20090728 [RISE-2009003] Linux eCryptfs parse_tag_3_packet Encrypted Key Buffer Overflow Vulnerability</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1193.html">RHSA-2009:1193</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.4" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.4</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1845">DSA-1845</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37471">37471</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36131" adv="1">36131</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36116" adv="1">36116</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36054" adv="1">36054</ref>
            <ref source="MISC" url="http://risesecurity.org/advisories/RISE-2009003.txt">http://risesecurity.org/advisories/RISE-2009003.txt</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html">SUSE-SR:2009:015</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f151cd2c54ddc7714e2f740681350476cda03a28">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f151cd2c54ddc7714e2f740681350476cda03a28</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers num="2.6.25" />
                <vers num="2.6.25.1" />
                <vers num="2.6.25.10" />
                <vers num="2.6.25.11" />
                <vers num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers num="2.6.25.3" />
                <vers num="2.6.25.4" />
                <vers num="2.6.25.5" />
                <vers num="2.6.25.6" />
                <vers num="2.6.25.7" />
                <vers num="2.6.25.8" />
                <vers num="2.6.25.9" />
                <vers num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.13" />
                <vers num="2.6.27.14" />
                <vers num="2.6.27.15" />
                <vers num="2.6.27.16" />
                <vers num="2.6.27.17" />
                <vers num="2.6.27.18" />
                <vers num="2.6.27.19" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.20" />
                <vers num="2.6.27.21" />
                <vers num="2.6.27.22" />
                <vers num="2.6.27.23" />
                <vers num="2.6.27.24" />
                <vers num="2.6.27.25" />
                <vers num="2.6.27.26" />
                <vers num="2.6.27.27" />
                <vers num="2.6.27.28" />
                <vers num="2.6.27.29" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.30" />
                <vers num="2.6.27.31" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.10" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers num="2.6.29" />
                <vers num="2.6.29.1" />
                <vers num="2.6.29.2" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.4" />
                <vers num="2.6.29.5" />
                <vers num="2.6.29.6" />
                <vers num="2.6.3" />
                <vers num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.3" prev="1" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" name="CVE-2009-2910" seq="2009-2910" severity="Medium" type="CVE" published="2009-10-20" CVSS_version="2.0" CVSS_score="4.9" modified="2010-02-02">
        <desc>
            <descript source="cve">arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="FEDORA" patch="1" url="https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00483.html">FEDORA-2009-10525</ref>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=526788">https://bugzilla.redhat.com/show_bug.cgi?id=526788</ref>
            <ref source="CONFIRM" patch="1" url="http://git.kernel.org/?p=linux/kernel/git/x86/linux-2.6-tip.git;a=commit;h=24e35800cdc4350fc34e2bed37b608a9e13ab3b6">http://git.kernel.org/?p=linux/kernel/git/x86/linux-2.6-tip.git;a=commit;h=24e35800cdc4350fc34e2bed37b608a9e13ab3b6</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2010-0046.html">RHSA-2010:0046</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1540.html">RHSA-2009:1540</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36576">36576</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1671.html">RHSA-2009:1671</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/10/02/1">[oss-security] 20091001 Re: CVE Request (kernel)</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.4" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.4</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37351">37351</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37075" adv="1">37075</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36927" adv="1">36927</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125511635004768&amp;w=2">[oss-security] 20091009 Re: CVE Request (kernel)</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125444390112831&amp;w=2">[oss-security] 20091002 Re: CVE Request (kernel)</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125442304214452&amp;w=2">[oss-security] 20091001 CVE Request (kernel)</ref>
            <ref source="MLIST" url="http://lkml.org/lkml/2009/10/1/164">[linux-kernel] 20091001 [tip:x86/urgent] x86: Don't leak 64-bit kernel register values to 32-bit processes</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.html">SUSE-SA:2009:056</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.html">SUSE-SA:2009:054</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition=":pre-2" num="2.4.18" />
                <vers edition=":pre-3" num="2.4.18" />
                <vers edition=":pre-1" num="2.4.18" />
                <vers edition=":pre-7" num="2.4.18" />
                <vers edition=":pre-6" num="2.4.18" />
                <vers edition=":pre-5" num="2.4.18" />
                <vers edition=":pre-4" num="2.4.18" />
                <vers edition=":pre-8" num="2.4.18" />
                <vers edition="" num="2.4.19" />
                <vers edition=":-pre1" num="2.4.19" />
                <vers edition=":-pre2" num="2.4.19" />
                <vers edition=":-pre5" num="2.4.19" />
                <vers edition=":-pre6" num="2.4.19" />
                <vers edition=":-pre3" num="2.4.19" />
                <vers edition=":-pre4" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="" num="2.4.21" />
                <vers edition=":-pre1" num="2.4.21" />
                <vers edition=":-pre4" num="2.4.21" />
                <vers edition=":-pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="" num="2.4.23" />
                <vers edition=":-ow2" num="2.4.23" />
                <vers edition=":-pre9" num="2.4.23" />
                <vers edition="" num="2.4.24" />
                <vers edition=":-ow1" num="2.4.24" />
                <vers num="2.4.25" />
                <vers num="2.4.26" />
                <vers edition="" num="2.4.27" />
                <vers edition=":-pre1" num="2.4.27" />
                <vers edition=":-pre2" num="2.4.27" />
                <vers edition=":-pre3" num="2.4.27" />
                <vers edition=":-pre4" num="2.4.27" />
                <vers edition=":-pre5" num="2.4.27" />
                <vers num="2.4.28" />
                <vers edition="-rc1" num="2.4.29" />
                <vers edition="-rc2" num="2.4.29" />
                <vers num="2.4.3" />
                <vers edition="rc2" num="2.4.30" />
                <vers edition="rc3" num="2.4.30" />
                <vers edition="-pre1" num="2.4.31" />
                <vers edition="-pre1" num="2.4.32" />
                <vers edition="-pre2" num="2.4.32" />
                <vers edition="p-re1" num="2.4.33" />
                <vers num="2.4.33.1" />
                <vers num="2.4.33.2" />
                <vers num="2.4.33.3" />
                <vers num="2.4.33.4" />
                <vers num="2.4.33.5" />
                <vers num="2.4.33.7" />
                <vers num="2.4.34" />
                <vers num="2.4.34.1" />
                <vers num="2.4.34.2" />
                <vers num="2.4.34.3" />
                <vers num="2.4.34.4" />
                <vers num="2.4.34.5" />
                <vers num="2.4.34.6" />
                <vers num="2.4.35.1" />
                <vers num="2.4.35.2" />
                <vers num="2.4.35.3" />
                <vers num="2.4.35.4" />
                <vers num="2.4.35.5" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.4.36.7" />
                <vers num="2.4.36.8" />
                <vers num="2.4.36.9" />
                <vers edition="-rc1" num="2.4.37" />
                <vers num="2.4.37.1" />
                <vers num="2.4.37.2" />
                <vers num="2.4.37.3" />
                <vers num="2.4.37.4" />
                <vers num="2.4.37.5" />
                <vers num="2.4.37.6" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers num="2.6" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.2.27.13" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers edition="rc1" num="2.6.23" />
                <vers edition="rc2" num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers edition="rc1" num="2.6.24" />
                <vers edition="rc2" num="2.6.24" />
                <vers edition="rc3" num="2.6.24" />
                <vers edition="rc4" num="2.6.24" />
                <vers edition="rc5" num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers num="2.6.25" />
                <vers num="2.6.25.1" />
                <vers num="2.6.25.10" />
                <vers num="2.6.25.11" />
                <vers num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers num="2.6.25.3" />
                <vers num="2.6.25.4" />
                <vers num="2.6.25.5" />
                <vers num="2.6.25.6" />
                <vers num="2.6.25.7" />
                <vers num="2.6.25.8" />
                <vers num="2.6.25.9" />
                <vers edition="rc4" num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers edition="rc1" num="2.6.27" />
                <vers edition="rc2" num="2.6.27" />
                <vers edition="rc3" num="2.6.27" />
                <vers edition="rc4" num="2.6.27" />
                <vers edition="rc5" num="2.6.27" />
                <vers edition="rc6" num="2.6.27" />
                <vers edition="rc7" num="2.6.27" />
                <vers edition="rc8" num="2.6.27" />
                <vers edition="rc9" num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.13" />
                <vers num="2.6.27.14" />
                <vers num="2.6.27.15" />
                <vers num="2.6.27.16" />
                <vers num="2.6.27.17" />
                <vers num="2.6.27.18" />
                <vers num="2.6.27.19" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.20" />
                <vers num="2.6.27.21" />
                <vers num="2.6.27.22" />
                <vers num="2.6.27.23" />
                <vers num="2.6.27.24" />
                <vers num="2.6.27.25" />
                <vers num="2.6.27.26" />
                <vers num="2.6.27.27" />
                <vers num="2.6.27.28" />
                <vers num="2.6.27.29" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.30" />
                <vers num="2.6.27.31" />
                <vers num="2.6.27.32" />
                <vers num="2.6.27.33" />
                <vers num="2.6.27.34" />
                <vers num="2.6.27.35" />
                <vers num="2.6.27.36" />
                <vers num="2.6.27.37" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers edition="git7" num="2.6.28" />
                <vers edition="rc1" num="2.6.28" />
                <vers edition="rc2" num="2.6.28" />
                <vers edition="rc3" num="2.6.28" />
                <vers edition="rc4" num="2.6.28" />
                <vers edition="rc5" num="2.6.28" />
                <vers edition="rc6" num="2.6.28" />
                <vers edition="rc7" num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.10" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers edition="git1" num="2.6.29" />
                <vers edition="rc1" num="2.6.29" />
                <vers edition="rc2" num="2.6.29" />
                <vers edition="rc2_git7" num="2.6.29" />
                <vers edition="rc8-kk" num="2.6.29" />
                <vers num="2.6.29.1" />
                <vers num="2.6.29.2" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.4" />
                <vers num="2.6.29.5" />
                <vers num="2.6.29.6" />
                <vers num="2.6.29.rc1" />
                <vers num="2.6.29.rc2" />
                <vers num="2.6.29.rc2-git1" />
                <vers num="2.6.3" />
                <vers edition="rc1" num="2.6.30" />
                <vers edition="rc2" num="2.6.30" />
                <vers edition="rc3" num="2.6.30" />
                <vers edition="rc4" num="2.6.30" />
                <vers edition="rc4:x86_32" num="2.6.30" />
                <vers edition="rc5" num="2.6.30" />
                <vers edition="rc6" num="2.6.30" />
                <vers edition="rc7-git6" num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.3" />
                <vers num="2.6.30.4" />
                <vers num="2.6.30.5" />
                <vers num="2.6.30.6" />
                <vers num="2.6.30.7" />
                <vers num="2.6.30.8" />
                <vers num="2.6.30.9" />
                <vers edition="rc1" num="2.6.31" />
                <vers edition="rc2" num="2.6.31" />
                <vers edition="rc3" num="2.6.31" />
                <vers edition="rc4" num="2.6.31" />
                <vers edition="rc5" num="2.6.31" />
                <vers edition="rc6" num="2.6.31" />
                <vers edition="rc7" num="2.6.31" />
                <vers num="2.6.31.1" />
                <vers num="2.6.31.2" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-2009-3555" seq="2009-3555" severity="Medium" type="CVE" published="2009-11-09" CVSS_version="2.0" CVSS_score="6.4" modified="2010-01-23">
        <desc>
            <descript source="cve">The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/120541">VU#120541</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36935">36935</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01029.html">FEDORA-2009-12229</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01020.html">FEDORA-2009-12305</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html">FEDORA-2009-12606</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html">FEDORA-2009-12604</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00634.html">FEDORA-2009-12968</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html">FEDORA-2009-12782</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html">FEDORA-2009-12775</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html">FEDORA-2009-12750</ref>
            <ref source="MISC" url="https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt">https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt</ref>
            <ref source="MISC" url="https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html">https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=533125">https://bugzilla.redhat.com/show_bug.cgi?id=533125</ref>
            <ref source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=526689">https://bugzilla.mozilla.org/show_bug.cgi?id=526689</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54158">tls-renegotiation-weak-security(54158)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0173">ADV-2010-0173</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3587">ADV-2009-3587</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3521">ADV-2009-3521</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3484">ADV-2009-3484</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3354">ADV-2009-3354</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3353">ADV-2009-3353</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3220">ADV-2009-3220</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3205">ADV-2009-3205</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3165" adv="1">ADV-2009-3165</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3164" adv="1">ADV-2009-3164</ref>
            <ref source="MISC" url="http://www.tombom.co.uk/blog/?p=85">http://www.tombom.co.uk/blog/?p=85</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023275">1023275</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023274">1023274</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023273">1023273</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023272">1023272</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023271">1023271</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023270">1023270</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023243">1023243</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023219">1023219</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023218">1023218</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023217">1023217</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023216">1023216</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023215">1023215</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023212">1023212</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023211">1023211</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023210">1023210</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023209">1023209</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023208">1023208</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023207">1023207</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023206">1023206</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023205">1023205</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023204">1023204</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023163">1023163</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/508130/100/0/threaded">20091130 TLS / SSLv3 vulnerability explained (New ways to leverage the vulnerability)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/508075/100/0/threaded">20091124 rPSA-2009-0155-1 httpd mod_ssl</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507952/100/0/threaded">20091118 TLS / SSLv3 vulnerability explained (DRAFT)</ref>
            <ref source="MISC" url="http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html">http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html</ref>
            <ref source="CONFIRM" url="http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c">http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/23/10">[oss-security] 20091123 Re: CVEs for nginx</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/20/1">[oss-security] 20091120 CVEs for nginx</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/07/3">[oss-security] 20091107 Re: [TLS] CVE-2009-3555 for TLS renegotiation MITM attacks</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/06/3">[oss-security] 20091107 Re: CVE-2009-3555 for TLS renegotiation MITM attacks</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/05/5">[oss-security] 20091105 Re: CVE-2009-3555 for TLS renegotiation MITM attacks</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/05/3">[oss-security] 20091105 CVE-2009-3555 for TLS renegotiation MITM attacks</ref>
            <ref source="MISC" url="http://www.links.org/?p=789">http://www.links.org/?p=789</ref>
            <ref source="MISC" url="http://www.links.org/?p=786">http://www.links.org/?p=786</ref>
            <ref source="MISC" url="http://www.links.org/?p=780">http://www.links.org/?p=780</ref>
            <ref source="CONFIRM" url="http://www.ingate.com/Relnote.php?ver=481">http://www.ingate.com/Relnote.php?ver=481</ref>
            <ref source="MLIST" url="http://www.ietf.org/mail-archive/web/tls/current/msg03948.html">[tls] 20091104 TLS renegotiation issue</ref>
            <ref source="MLIST" url="http://www.ietf.org/mail-archive/web/tls/current/msg03928.html">[tls] 20091104 MITM attack on delayed TLS-client auth through renegotiation</ref>
            <ref source="MISC" url="http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html">http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1934">DSA-1934</ref>
            <ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b01d1d.shtml">20091109 Transport Layer Security Renegotiation Vulnerability</ref>
            <ref source="MISC" url="http://www.betanews.com/article/1257452450">http://www.betanews.com/article/1257452450</ref>
            <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PM00675&amp;apar=only">PM00675</ref>
            <ref source="CONFIRM" url="http://www-01.ibm.com/support/docview.wss?uid=swg24025312">http://www-01.ibm.com/support/docview.wss?uid=swg24025312</ref>
            <ref source="CONFIRM" url="http://wiki.rpath.com/Advisories:rPSA-2009-0155">http://wiki.rpath.com/Advisories:rPSA-2009-0155</ref>
            <ref source="CONFIRM" url="http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.html">http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.html</ref>
            <ref source="CONFIRM" url="http://sysoev.ru/nginx/patch.cve-2009-3555.txt">http://sysoev.ru/nginx/patch.cve-2009-3555.txt</ref>
            <ref source="CONFIRM" url="http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released">http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released</ref>
            <ref source="CONFIRM" url="http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES">http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES</ref>
            <ref source="CONFIRM" url="http://support.citrix.com/article/CTX123359">http://support.citrix.com/article/CTX123359</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4004">http://support.apple.com/kb/HT4004</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-273029-1">273029</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023148">1023148</ref>
            <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200912-01.xml">GLSA-200912-01</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38241">38241</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38056">38056</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37859">37859</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37675">37675</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37656">37656</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37640">37640</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37604">37604</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37504">37504</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37501">37501</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37320">37320</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37292" adv="1">37292</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37291" adv="1">37291</ref>
            <ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2009/Nov/139">20091111 Re: SSL/TLS MiTM PoC</ref>
            <ref source="OSVDB" url="http://osvdb.org/60972">60972</ref>
            <ref source="OSVDB" url="http://osvdb.org/60521">60521</ref>
            <ref source="OPENBSD" url="http://openbsd.org/errata46.html#004_openssl">[4.6] 004: SECURITY FIX: November 26, 2009</ref>
            <ref source="OPENBSD" url="http://openbsd.org/errata45.html#010_openssl">[4.5] 010: SECURITY FIX: November 26, 2009</ref>
            <ref source="MLIST" url="http://marc.info/?l=cryptography&amp;m=125752275331877&amp;w=2">[cryptography] 20091105 OpenSSL 0.9.8l released</ref>
            <ref source="MLIST" url="http://marc.info/?l=apache-httpd-announce&amp;m=125755783724966&amp;w=2">[announce] 20091107 CVE-2009-3555 - apache/mod_ssl vulnerability and mitigation</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.html">SUSE-SA:2009:057</ref>
            <ref source="MLIST" url="http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00029.html">[gnutls-devel] 20091105 Re: TLS renegotiation MITM</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html">APPLE-SA-2010-01-19-1</ref>
            <ref source="CONFIRM" url="http://kbase.redhat.com/faq/docs/DOC-20491">http://kbase.redhat.com/faq/docs/DOC-20491</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686">SSRT090249</ref>
            <ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686">SSRT090249</ref>
            <ref source="MISC" url="http://extendedsubset.com/Renegotiating_TLS.pdf">http://extendedsubset.com/Renegotiating_TLS.pdf</ref>
            <ref source="MISC" url="http://extendedsubset.com/?p=8">http://extendedsubset.com/?p=8</ref>
            <ref source="MISC" url="http://clicky.me/tlsvuln">http://clicky.me/tlsvuln</ref>
            <ref source="CONFIRM" url="http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during">http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during</ref>
            <ref source="MISC" url="http://blogs.iss.net/archive/sslmitmiscsrf.html">http://blogs.iss.net/archive/sslmitmiscsrf.html</ref>
            <ref source="MISC" url="http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html">http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="http_server">
                <vers num="0.8.11" />
                <vers num="0.8.14" />
                <vers num="1.0" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.5" />
                <vers num="1.1.1" />
                <vers num="1.2" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
                <vers num="1.2.6" />
                <vers num="1.3" />
                <vers num="1.3.0" />
                <vers num="1.3.1.1" />
                <vers num="1.3.11" />
                <vers num="1.3.12" />
                <vers num="1.3.13" />
                <vers num="1.3.14" />
                <vers num="1.3.15" />
                <vers num="1.3.16" />
                <vers num="1.3.17" />
                <vers num="1.3.18" />
                <vers num="1.3.19" />
                <vers num="1.3.2" />
                <vers num="1.3.20" />
                <vers num="1.3.22" />
                <vers num="1.3.23" />
                <vers num="1.3.24" />
                <vers num="1.3.25" />
                <vers num="1.3.26" />
                <vers num="1.3.27" />
                <vers num="1.3.28" />
                <vers num="1.3.29" />
                <vers num="1.3.3" />
                <vers num="1.3.30" />
                <vers num="1.3.31" />
                <vers num="1.3.32" />
                <vers num="1.3.33" />
                <vers num="1.3.34" />
                <vers num="1.3.35" />
                <vers num="1.3.36" />
                <vers num="1.3.37" />
                <vers num="1.3.38" />
                <vers num="1.3.39" />
                <vers num="1.3.4" />
                <vers num="1.3.5" />
                <vers num="1.3.6" />
                <vers num="1.3.65" />
                <vers num="1.3.68" />
                <vers edition="" num="1.3.7" />
                <vers edition=":dev" num="1.3.7" />
                <vers num="1.3.8" />
                <vers num="1.3.9" />
                <vers num="1.4.0" />
                <vers num="1.99" />
                <vers num="2.0" />
                <vers edition="beta" num="2.0.28" />
                <vers edition="beta" num="2.0.32" />
                <vers edition="beta" num="2.0.34" />
                <vers num="2.0.35" />
                <vers num="2.0.36" />
                <vers num="2.0.37" />
                <vers num="2.0.38" />
                <vers num="2.0.39" />
                <vers num="2.0.40" />
                <vers num="2.0.41" />
                <vers num="2.0.42" />
                <vers num="2.0.43" />
                <vers num="2.0.44" />
                <vers num="2.0.45" />
                <vers edition="" num="2.0.46" />
                <vers edition=":win32" num="2.0.46" />
                <vers num="2.0.47" />
                <vers num="2.0.48" />
                <vers num="2.0.49" />
                <vers num="2.0.50" />
                <vers num="2.0.51" />
                <vers num="2.0.52" />
                <vers num="2.0.53" />
                <vers num="2.0.54" />
                <vers num="2.0.55" />
                <vers num="2.0.56" />
                <vers num="2.0.57" />
                <vers edition="" num="2.0.58" />
                <vers edition=":win32" num="2.0.58" />
                <vers num="2.0.59" />
                <vers num="2.0.60" />
                <vers num="2.0.61" />
                <vers num="2.0.63" />
                <vers num="2.0.9" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.7" />
                <vers num="2.1.8" />
                <vers num="2.1.9" />
                <vers num="2.2" />
                <vers num="2.2.0" />
                <vers num="2.2.1" />
                <vers num="2.2.10" />
                <vers num="2.2.11" />
                <vers num="2.2.12" />
                <vers num="2.2.13" prev="1" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.2.6" />
                <vers num="2.2.7" />
                <vers num="2.2.8" />
            </prod>
            <prod vendor="gnu" name="gnutls">
                <vers num="1.0.16" />
                <vers num="1.0.17" />
                <vers num="1.0.18" />
                <vers num="1.0.19" />
                <vers num="1.0.20" />
                <vers num="1.0.21" />
                <vers num="1.0.22" />
                <vers num="1.0.23" />
                <vers num="1.0.24" />
                <vers num="1.0.25" />
                <vers num="1.1.13" />
                <vers num="1.1.14" />
                <vers num="1.1.15" />
                <vers num="1.1.16" />
                <vers num="1.1.17" />
                <vers num="1.1.18" />
                <vers num="1.1.19" />
                <vers num="1.1.20" />
                <vers num="1.1.21" />
                <vers num="1.1.22" />
                <vers num="1.1.23" />
                <vers num="1.2.0" />
                <vers num="1.2.1" />
                <vers num="1.2.10" />
                <vers num="1.2.11" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
                <vers num="1.2.6" />
                <vers num="1.2.7" />
                <vers num="1.2.8" />
                <vers num="1.2.8.1a1" />
                <vers num="1.2.9" />
                <vers num="1.3.0" />
                <vers num="1.3.1" />
                <vers num="1.3.2" />
                <vers num="1.3.3" />
                <vers num="1.3.4" />
                <vers num="1.3.5" />
                <vers num="1.4.0" />
                <vers num="1.4.1" />
                <vers num="1.4.2" />
                <vers num="1.4.3" />
                <vers num="1.4.4" />
                <vers num="1.4.5" />
                <vers num="1.5.0" />
                <vers num="1.5.1" />
                <vers num="1.5.2" />
                <vers num="1.5.3" />
                <vers num="1.5.4" />
                <vers num="1.5.5" />
                <vers num="1.6.0" />
                <vers num="1.6.1" />
                <vers num="1.6.2" />
                <vers num="1.6.3" />
                <vers num="1.7.0" />
                <vers num="1.7.1" />
                <vers num="1.7.10" />
                <vers num="1.7.11" />
                <vers num="1.7.12" />
                <vers num="1.7.13" />
                <vers num="1.7.14" />
                <vers num="1.7.15" />
                <vers num="1.7.16" />
                <vers num="1.7.17" />
                <vers num="1.7.18" />
                <vers num="1.7.19" />
                <vers num="1.7.2" />
                <vers num="1.7.3" />
                <vers num="1.7.4" />
                <vers num="1.7.5" />
                <vers num="1.7.6" />
                <vers num="1.7.7" />
                <vers num="1.7.8" />
                <vers num="1.7.9" />
                <vers num="2.0.0" />
                <vers num="2.0.1" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="2.1.0" />
                <vers num="2.1.1" />
                <vers num="2.1.2" />
                <vers num="2.1.3" />
                <vers num="2.1.4" />
                <vers num="2.1.5" />
                <vers num="2.1.6" />
                <vers num="2.1.7" />
                <vers num="2.1.8" />
                <vers num="2.2.0" />
                <vers num="2.2.1" />
                <vers num="2.2.2" />
                <vers num="2.2.3" />
                <vers num="2.2.4" />
                <vers num="2.2.5" />
                <vers num="2.3.0" />
                <vers num="2.3.1" />
                <vers num="2.3.10" />
                <vers num="2.3.11" />
                <vers num="2.3.2" />
                <vers num="2.3.3" />
                <vers num="2.3.4" />
                <vers num="2.3.5" />
                <vers num="2.3.6" />
                <vers num="2.3.7" />
                <vers num="2.3.8" />
                <vers num="2.3.9" />
                <vers num="2.4.0" />
                <vers num="2.4.1" />
                <vers num="2.4.2" />
                <vers num="2.5.0" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.2" />
                <vers num="2.6.3" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.8.0" />
                <vers num="2.8.1" prev="1" />
            </prod>
            <prod vendor="microsoft" name="iis">
                <vers num="7.0" />
            </prod>
            <prod vendor="mozilla" name="nss">
                <vers num="3.0" />
                <vers num="3.10" />
                <vers num="3.11.2" />
                <vers num="3.11.4" />
                <vers num="3.11.7" />
                <vers num="3.11.8" />
                <vers num="3.12" />
                <vers num="3.12.1" />
                <vers num="3.12.2" prev="1" />
                <vers num="3.2" />
                <vers num="3.2.1" />
                <vers num="3.3" />
                <vers num="3.3.1" />
                <vers num="3.3.2" />
                <vers num="3.4" />
                <vers num="3.4.1" />
                <vers num="3.4.2" />
                <vers num="3.4.3" />
                <vers num="3.5" />
                <vers num="3.6" />
                <vers num="3.6.1" />
                <vers num="3.7" />
                <vers num="3.7.1" />
                <vers num="3.7.2" />
                <vers num="3.7.3" />
                <vers num="3.7.5" />
                <vers num="3.7.7" />
                <vers num="3.8" />
                <vers num="3.9" />
                <vers num="3.9.5" />
            </prod>
            <prod vendor="openssl" name="openssl">
                <vers num="0.9.1c" />
                <vers num="0.9.2b" />
                <vers num="0.9.3" />
                <vers num="0.9.3a" />
                <vers num="0.9.4" />
                <vers edition="beta1" num="0.9.5" />
                <vers edition="beta2" num="0.9.5" />
                <vers edition="beta1" num="0.9.5a" />
                <vers edition="beta2" num="0.9.5a" />
                <vers edition="beta1" num="0.9.6" />
                <vers edition="beta2" num="0.9.6" />
                <vers edition="beta3" num="0.9.6" />
                <vers edition="beta1" num="0.9.6a" />
                <vers edition="beta2" num="0.9.6a" />
                <vers edition="beta3" num="0.9.6a" />
                <vers num="0.9.6b" />
                <vers num="0.9.6c" />
                <vers num="0.9.6d" />
                <vers num="0.9.6e" />
                <vers num="0.9.6f" />
                <vers num="0.9.6g" />
                <vers num="0.9.6h" />
                <vers num="0.9.6i" />
                <vers num="0.9.6j" />
                <vers num="0.9.6k" />
                <vers num="0.9.6l" />
                <vers num="0.9.6m" />
                <vers edition="beta1" num="0.9.7" />
                <vers edition="beta2" num="0.9.7" />
                <vers edition="beta3" num="0.9.7" />
                <vers edition="beta4" num="0.9.7" />
                <vers edition="beta5" num="0.9.7" />
                <vers edition="beta6" num="0.9.7" />
                <vers num="0.9.7a" />
                <vers num="0.9.7b" />
                <vers num="0.9.7c" />
                <vers num="0.9.7d" />
                <vers num="0.9.7e" />
                <vers num="0.9.7f" />
                <vers num="0.9.7g" />
                <vers num="0.9.7h" />
                <vers num="0.9.7i" />
                <vers num="0.9.7j" />
                <vers num="0.9.7k" />
                <vers num="0.9.7l" />
                <vers num="0.9.7m" />
                <vers num="0.9.8" />
                <vers num="0.9.8a" />
                <vers num="0.9.8b" />
                <vers num="0.9.8c" />
                <vers num="0.9.8d" />
                <vers num="0.9.8e" />
                <vers num="0.9.8f" />
                <vers num="0.9.8g" />
                <vers num="0.9.8h" prev="1" />
                <vers edition="" num="1.0" />
                <vers edition=":openvms" num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-2841" seq="2009-2841" severity="Medium" type="CVE" published="2009-11-13" CVSS_version="2.0" CVSS_score="5.0" modified="2010-02-05">
        <desc>
            <descript source="cve">WebKit in Apple Safari before 4.0.4 on Mac OS X does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://support.apple.com/kb/HT3949" adv="1">http://support.apple.com/kb/HT3949</ref>
            <ref source="APPLE" patch="1" url="http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.html" adv="1">APPLE-SA-2009-11-11-1</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54242">safari-5media-security-bypass(54242)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3217">ADV-2009-3217</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023167">1023167</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36996">36996</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4013">http://support.apple.com/kb/HT4013</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37346">37346</ref>
            <ref source="OSVDB" url="http://osvdb.org/59941">59941</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html">APPLE-SA-2010-02-02-1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="safari">
                <vers num="0.8" />
                <vers num="0.9" />
                <vers edition="beta" num="1.0" />
                <vers edition="beta2" num="1.0" />
                <vers num="1.0.0" />
                <vers num="1.0.0b1" />
                <vers num="1.0.0b2" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.1.0" />
                <vers num="1.1.1" />
                <vers num="1.2" />
                <vers num="1.2.0" />
                <vers num="1.2.1" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
                <vers num="1.3" />
                <vers num="1.3.0" />
                <vers num="1.3.1" />
                <vers num="1.3.2" />
                <vers num="2" />
                <vers num="2.0" />
                <vers num="2.0.0" />
                <vers num="2.0.1" />
                <vers num="2.0.2" />
                <vers edition="417.8" num="2.0.3" />
                <vers edition="417.9" num="2.0.3" />
                <vers edition="417.9.2" num="2.0.3" />
                <vers edition="417.9.3" num="2.0.3" />
                <vers num="2.0.3_417.9.3" />
                <vers num="2.0.4" />
                <vers num="2.0.4_419.3" />
                <vers num="2.0_pre" />
                <vers num="3" />
                <vers num="3.0" />
                <vers num="3.0.0" />
                <vers num="3.0.0b" />
                <vers edition="beta" num="3.0.1" />
                <vers num="3.0.1b" />
                <vers num="3.0.2" />
                <vers num="3.0.2b" />
                <vers num="3.0.3" />
                <vers num="3.0.3b" />
                <vers num="3.0.4" />
                <vers num="3.0.4_beta" />
                <vers num="3.0.4b" />
                <vers num="3.1" />
                <vers num="3.1.0" />
                <vers num="3.1.0b" />
                <vers num="3.1.1" />
                <vers num="3.1.2" />
                <vers num="3.2" />
                <vers num="3.2.0" />
                <vers num="3.2.1" />
                <vers num="3.2.2" />
                <vers num="3.2.3" />
                <vers edition="beta" num="4.0" />
                <vers num="4.0.0b" />
                <vers num="4.0.1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3384" seq="2009-3384" severity="High" type="CVE" published="2009-11-13" CVSS_version="2.0" CVSS_score="10.0" modified="2010-02-05">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://support.apple.com/kb/HT3949" adv="1">http://support.apple.com/kb/HT3949</ref>
            <ref source="APPLE" patch="1" url="http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.html" adv="1">APPLE-SA-2009-11-11-1</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00549.html">FEDORA-2009-11491</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00545.html">FEDORA-2009-11487</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=525788">https://bugzilla.redhat.com/show_bug.cgi?id=525788</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54241">safari-ftp-code-execution(54241)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3217">ADV-2009-3217</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023166">1023166</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36995">36995</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4013">http://support.apple.com/kb/HT4013</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37397">37397</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37393">37393</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37346">37346</ref>
            <ref source="OSVDB" url="http://osvdb.org/59943">59943</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html">APPLE-SA-2010-02-02-1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="safari">
                <vers num="0.8" />
                <vers num="0.9" />
                <vers edition="beta" num="1.0" />
                <vers edition="beta2" num="1.0" />
                <vers num="1.0.0" />
                <vers num="1.0.0b1" />
                <vers num="1.0.0b2" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.1.0" />
                <vers num="1.1.1" />
                <vers num="1.2" />
                <vers num="1.2.0" />
                <vers num="1.2.1" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
                <vers num="1.3" />
                <vers num="1.3.0" />
                <vers num="1.3.1" />
                <vers num="1.3.2" />
                <vers num="2" />
                <vers num="2.0" />
                <vers num="2.0.0" />
                <vers num="2.0.1" />
                <vers num="2.0.2" />
                <vers edition="417.8" num="2.0.3" />
                <vers edition="417.9" num="2.0.3" />
                <vers edition="417.9.2" num="2.0.3" />
                <vers edition="417.9.3" num="2.0.3" />
                <vers num="2.0.3_417.9.3" />
                <vers num="2.0.4" />
                <vers num="2.0.4_419.3" />
                <vers num="2.0_pre" />
                <vers num="3" />
                <vers num="3.0" />
                <vers num="3.0.0" />
                <vers num="3.0.0b" />
                <vers edition="beta" num="3.0.1" />
                <vers num="3.0.1b" />
                <vers num="3.0.2" />
                <vers num="3.0.2b" />
                <vers num="3.0.3" />
                <vers num="3.0.3b" />
                <vers num="3.0.4" />
                <vers num="3.0.4_beta" />
                <vers num="3.0.4b" />
                <vers num="3.1" />
                <vers num="3.1.0" />
                <vers num="3.1.0b" />
                <vers num="3.1.1" />
                <vers num="3.1.2" />
                <vers num="3.2" />
                <vers num="3.2.0" />
                <vers num="3.2.1" />
                <vers num="3.2.2" />
                <vers num="3.2.3" />
                <vers edition="beta" num="4.0" />
                <vers num="4.0.0b" />
                <vers num="4.0.1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:C/A:C)" CVSS_base_score="6.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="9.2" name="CVE-2009-3889" seq="2009-3889" severity="Medium" type="CVE" published="2009-11-16" CVSS_version="2.0" CVSS_score="6.6" modified="2010-02-02">
        <desc>
            <descript source="cve">The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which allows local users to change the (1) behavior and (2) logging level of the driver by modifying this file.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2010-0046.html">RHSA-2010:0046</ref>
            <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=526068">https://bugzilla.redhat.com/show_bug.cgi?id=526068</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/13/4">[oss-security] 20091113 Re: CVE request: kernel: bad permissions on megaraid_sas sysfs files</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/13/1">[oss-security] 20091113 CVE request: kernel: bad permissions on megaraid_sas sysfs files</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37909">37909</ref>
            <ref source="OSVDB" url="http://osvdb.org/60202">60202</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html">SUSE-SA:2009:064</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html">SUSE-SA:2009:061</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=66dca9b8c50b5e59d3bea8b21cee5c6dae6c9c46">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=66dca9b8c50b5e59d3bea8b21cee5c6dae6c9c46</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers num="2.6.25" />
                <vers num="2.6.26" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:C/A:C)" CVSS_base_score="6.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="9.2" name="CVE-2009-3939" seq="2009-3939" severity="Medium" type="CVE" published="2009-11-16" CVSS_version="2.0" CVSS_score="6.6" modified="2010-02-02">
        <desc>
            <descript source="cve">The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2010-0046.html">RHSA-2010:0046</ref>
            <ref source="MISC" url="https://bugzilla.redhat.com/show_bug.cgi?id=526068">https://bugzilla.redhat.com/show_bug.cgi?id=526068</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/13/1">[oss-security] 20091113 CVE request: kernel: bad permissions on megaraid_sas sysfs files</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38017">38017</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37909">37909</ref>
            <ref source="OSVDB" url="http://osvdb.org/60201">60201</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html">SUSE-SA:2010:001</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html">SUSE-SA:2009:064</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html">SUSE-SA:2009:061</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers num="2.6.25" />
                <vers num="2.6.25.1" />
                <vers num="2.6.25.10" />
                <vers num="2.6.25.11" />
                <vers num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers num="2.6.25.3" />
                <vers num="2.6.25.4" />
                <vers num="2.6.25.5" />
                <vers num="2.6.25.6" />
                <vers num="2.6.25.7" />
                <vers num="2.6.25.8" />
                <vers num="2.6.25.9" />
                <vers num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.13" />
                <vers num="2.6.27.14" />
                <vers num="2.6.27.15" />
                <vers num="2.6.27.16" />
                <vers num="2.6.27.17" />
                <vers num="2.6.27.18" />
                <vers num="2.6.27.19" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.20" />
                <vers num="2.6.27.21" />
                <vers num="2.6.27.22" />
                <vers num="2.6.27.23" />
                <vers num="2.6.27.24" />
                <vers num="2.6.27.25" />
                <vers num="2.6.27.26" />
                <vers num="2.6.27.27" />
                <vers num="2.6.27.28" />
                <vers num="2.6.27.29" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.30" />
                <vers num="2.6.27.31" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.10" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers num="2.6.29" />
                <vers num="2.6.29.1" />
                <vers num="2.6.29.2" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.4" />
                <vers num="2.6.29.5" />
                <vers num="2.6.29.6" />
                <vers num="2.6.3" />
                <vers num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.3" />
                <vers num="2.6.30.4" />
                <vers num="2.6.30.5" />
                <vers num="2.6.30.6" />
                <vers num="2.6.30.7" />
                <vers num="2.6.30.8" />
                <vers num="2.6.30.9" />
                <vers num="2.6.31" />
                <vers num="2.6.31.1" />
                <vers num="2.6.31.2" />
                <vers num="2.6.31.3" />
                <vers num="2.6.31.4" />
                <vers num="2.6.31.5" />
                <vers num="2.6.31.6" prev="1" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" name="CVE-2009-3942" seq="2009-3942" severity="Medium" type="CVE" published="2009-11-16" CVSS_version="2.0" CVSS_score="6.4" modified="2010-01-28">
        <desc>
            <descript source="cve">Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3224" adv="1">ADV-2009-3224</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37321" adv="1">37321</ref>
            <ref source="CONFIRM" url="http://msmtp.sourceforge.net/news.html">http://msmtp.sourceforge.net/news.html</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html">SUSE-SR:2010:001</ref>
        </refs>
        <vuln_soft>
            <prod vendor="martin_lambers" name="msmtp">
                <vers num="0.2.5" />
                <vers num="0.2.6" />
                <vers num="0.3.0" />
                <vers num="0.3.1" />
                <vers num="0.4.0" />
                <vers num="0.4.1" />
                <vers num="0.4.2" />
                <vers num="0.5.0" />
                <vers num="0.5.1" />
                <vers num="0.5.2" />
                <vers num="0.5.3" />
                <vers num="0.6.0" />
                <vers num="0.6.1" />
                <vers num="0.6.2" />
                <vers num="0.6.3" />
                <vers num="0.6.4" />
                <vers num="0.6.5" />
                <vers num="0.6.6" />
                <vers num="0.7.0" />
                <vers num="0.7.1" />
                <vers num="0.7.2" />
                <vers num="1.0.0" />
                <vers num="1.2.1" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.4.0" />
                <vers num="1.4.1" />
                <vers num="1.4.10" />
                <vers num="1.4.12" />
                <vers num="1.4.13" />
                <vers num="1.4.14" />
                <vers num="1.4.15" />
                <vers num="1.4.16" />
                <vers num="1.4.17" />
                <vers num="1.4.18" prev="1" />
                <vers num="1.4.2" />
                <vers num="1.4.3" />
                <vers num="1.4.4" />
                <vers num="1.4.5" />
                <vers num="1.4.6" />
                <vers num="1.4.7" />
                <vers num="1.4.8" />
                <vers num="1.4.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3553" seq="2009-3553" severity="Medium" type="CVE" published="2009-11-19" CVSS_version="2.0" CVSS_score="5.0" modified="2010-01-23">
        <desc>
            <descript source="cve">Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count.  NOTE: some of these details are obtained from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://www.cups.org/str.php?L3200" adv="1">http://www.cups.org/str.php?L3200</ref>
            <ref source="MISC" patch="1" url="http://www.cups.org/newsgroups.php/newsgroups.php?v6055+gcups.bugs" adv="1">http://www.cups.org/newsgroups.php/newsgroups.php?v6055+gcups.bugs</ref>
            <ref source="MISC" patch="1" url="http://www.cups.org/newsgroups.php/newsgroups.php?v5996+gcups.bugs" adv="1">http://www.cups.org/newsgroups.php/newsgroups.php?v5996+gcups.bugs</ref>
            <ref source="MISC" patch="1" url="http://www.cups.org/newsgroups.php/newsgroups.php?v5994+gcups.bugs" adv="1">http://www.cups.org/newsgroups.php/newsgroups.php?v5994+gcups.bugs</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00332.html">FEDORA-2009-12652</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=530111">https://bugzilla.redhat.com/show_bug.cgi?id=530111</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0173">ADV-2010-0173</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37048">37048</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1595.html">RHSA-2009:1595</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4004">http://support.apple.com/kb/HT4004</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38241">38241</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37364" adv="1">37364</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37360" adv="1">37360</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html">APPLE-SA-2010-01-19-1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apple" name="cups">
                <vers num="1.3.10" />
                <vers num="1.3.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2009-3080" seq="2009-3080" severity="High" type="CVE" published="2009-11-20" CVSS_version="2.0" CVSS_score="7.2" modified="2010-02-02">
        <desc>
            <descript source="cve">Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=690e744869f3262855b83b4fb59199cf142765b0">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=690e744869f3262855b83b4fb59199cf142765b0</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00777.html">FEDORA-2009-13098</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2010-0046.html">RHSA-2010:0046</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37068">37068</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2010-0041.html">RHSA-2010:0041</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc8" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc8</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38017">38017</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37909">37909</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37720">37720</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37435" adv="1">37435</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html">SUSE-SA:2010:001</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html">SUSE-SA:2009:064</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html">SUSE-SA:2009:061</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers num="2.6.25" />
                <vers num="2.6.25.1" />
                <vers num="2.6.25.10" />
                <vers num="2.6.25.11" />
                <vers num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers num="2.6.25.3" />
                <vers num="2.6.25.4" />
                <vers num="2.6.25.5" />
                <vers num="2.6.25.6" />
                <vers num="2.6.25.7" />
                <vers num="2.6.25.8" />
                <vers num="2.6.25.9" />
                <vers num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.13" />
                <vers num="2.6.27.14" />
                <vers num="2.6.27.15" />
                <vers num="2.6.27.16" />
                <vers num="2.6.27.17" />
                <vers num="2.6.27.18" />
                <vers num="2.6.27.19" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.20" />
                <vers num="2.6.27.21" />
                <vers num="2.6.27.22" />
                <vers num="2.6.27.23" />
                <vers num="2.6.27.24" />
                <vers num="2.6.27.25" />
                <vers num="2.6.27.26" />
                <vers num="2.6.27.27" />
                <vers num="2.6.27.28" />
                <vers num="2.6.27.29" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.30" />
                <vers num="2.6.27.31" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.10" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers num="2.6.29" />
                <vers num="2.6.29.1" />
                <vers num="2.6.29.2" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.4" />
                <vers num="2.6.29.5" />
                <vers num="2.6.29.6" />
                <vers num="2.6.3" />
                <vers edition="rc1" num="2.6.30" />
                <vers edition="rc2" num="2.6.30" />
                <vers edition="rc3" num="2.6.30" />
                <vers edition="rc4" num="2.6.30" />
                <vers edition="rc4:x86_32" num="2.6.30" />
                <vers edition="rc5" num="2.6.30" />
                <vers edition="rc6" num="2.6.30" />
                <vers edition="rc7-git6" num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.3" />
                <vers num="2.6.30.4" />
                <vers num="2.6.30.5" />
                <vers num="2.6.30.6" />
                <vers num="2.6.30.7" />
                <vers num="2.6.30.8" />
                <vers num="2.6.30.9" />
                <vers edition="rc1" num="2.6.31" />
                <vers edition="rc2" num="2.6.31" />
                <vers edition="rc3" num="2.6.31" />
                <vers edition="rc4" num="2.6.31" />
                <vers edition="rc5" num="2.6.31" />
                <vers edition="rc6" num="2.6.31" />
                <vers edition="rc7" num="2.6.31" />
                <vers edition="rc8" num="2.6.31" />
                <vers num="2.6.31.1" />
                <vers num="2.6.31.2" />
                <vers num="2.6.31.3" />
                <vers num="2.6.31.4" />
                <vers num="2.6.31.5" />
                <vers num="2.6.31.6" />
                <vers edition="rc1" num="2.6.32" prev="1" />
                <vers edition="rc3" num="2.6.32" prev="1" />
                <vers edition="rc4" num="2.6.32" prev="1" />
                <vers edition="rc5" num="2.6.32" prev="1" />
                <vers edition="rc6" num="2.6.32" prev="1" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2009-3897" seq="2009-3897" severity="Medium" type="CVE" published="2009-11-24" CVSS_version="2.0" CVSS_score="4.6" modified="2010-01-28">
        <desc>
            <descript source="cve">Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3306" adv="1">ADV-2009-3306</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/37084">37084</ref>
            <ref source="MLIST" patch="1" url="http://www.dovecot.org/list/dovecot-news/2009-November/000143.html" adv="1">[dovecot-news] 20091120 v1.2.8 released</ref>
            <ref source="MLIST" patch="1" url="http://marc.info/?l=oss-security&amp;m=125900267208712&amp;w=2">[oss-security] 20091123 Re: CVE request: v1.2.8 released to fix the 0777 base_dir creation issue</ref>
            <ref source="MLIST" patch="1" url="http://marc.info/?l=oss-security&amp;m=125871729029145&amp;w=2">[oss-security] 20091120 CVE request: v1.2.8 released to fix the 0777 base_dir creation issue</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54363">dovecot-basedir-privilege-escalation(54363)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/60316">60316</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:306">MDVSA-2009:306</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37443" adv="1">37443</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125900271508796&amp;w=2">[oss-security] 20091123 Re: CVE Request - Dovecot - 1.2.8</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125881481222441&amp;w=2">[oss-security] 20091121 CVE Request - Dovecot - 1.2.8</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html">SUSE-SR:2010:001</ref>
        </refs>
        <vuln_soft>
            <prod vendor="dovecot" name="dovecot">
                <vers num="1.2.0" />
                <vers num="1.2.1" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
                <vers num="1.2.6" />
                <vers num="1.2.7" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" name="CVE-2009-4021" seq="2009-4021" severity="Medium" type="CVE" published="2009-11-25" CVSS_version="2.0" CVSS_score="4.9" modified="2010-02-02">
        <desc>
            <descript source="cve">The fuse_direct_io function in fs/fuse/file.c in the fuse subsystem in the Linux kernel before 2.6.32-rc7 might allow attackers to cause a denial of service (invalid pointer dereference and OOPS) via vectors possibly related to a memory-consumption attack.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2010-0046.html">RHSA-2010:0046</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=538734">https://bugzilla.redhat.com/show_bug.cgi?id=538734</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54358">kernel-fusedirectio-dos(54358)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37069">37069</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2010-0041.html">RHSA-2010:0041</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/24/5">[oss-security] 20091124 Re: CVE request: kernel: fuse: prevent fuse_put_request on invalid pointer</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/19/1">[oss-security] 20091119 CVE request: kernel: fuse: prevent fuse_put_request on invalid pointer</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38017">38017</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37909">37909</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html">SUSE-SA:2010:001</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00005.html">SUSE-SA:2009:064</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00002.html">SUSE-SA:2009:061</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f60311d5f7670d9539b424e4ed8b5c0872fc9e83">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f60311d5f7670d9539b424e4ed8b5c0872fc9e83</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers num="2.6.25" />
                <vers num="2.6.25.1" />
                <vers num="2.6.25.10" />
                <vers num="2.6.25.11" />
                <vers num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers num="2.6.25.3" />
                <vers num="2.6.25.4" />
                <vers num="2.6.25.5" />
                <vers num="2.6.25.6" />
                <vers num="2.6.25.7" />
                <vers num="2.6.25.8" />
                <vers num="2.6.25.9" />
                <vers num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.13" />
                <vers num="2.6.27.14" />
                <vers num="2.6.27.15" />
                <vers num="2.6.27.16" />
                <vers num="2.6.27.17" />
                <vers num="2.6.27.18" />
                <vers num="2.6.27.19" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.20" />
                <vers num="2.6.27.21" />
                <vers num="2.6.27.22" />
                <vers num="2.6.27.23" />
                <vers num="2.6.27.24" />
                <vers num="2.6.27.25" />
                <vers num="2.6.27.26" />
                <vers num="2.6.27.27" />
                <vers num="2.6.27.28" />
                <vers num="2.6.27.29" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.30" />
                <vers num="2.6.27.31" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.10" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers num="2.6.29" />
                <vers num="2.6.29.1" />
                <vers num="2.6.29.2" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.4" />
                <vers num="2.6.29.5" />
                <vers num="2.6.29.6" />
                <vers num="2.6.3" />
                <vers num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.3" />
                <vers num="2.6.30.4" />
                <vers num="2.6.30.5" />
                <vers num="2.6.30.6" />
                <vers num="2.6.30.7" />
                <vers num="2.6.30.8" />
                <vers num="2.6.30.9" />
                <vers edition="rc1" num="2.6.31" />
                <vers edition="rc2" num="2.6.31" />
                <vers edition="rc3" num="2.6.31" />
                <vers edition="rc4" num="2.6.31" />
                <vers edition="rc5" num="2.6.31" />
                <vers edition="rc6" num="2.6.31" />
                <vers edition="rc7" num="2.6.31" />
                <vers edition="rc8" num="2.6.31" />
                <vers num="2.6.31.1" />
                <vers num="2.6.31.2" />
                <vers num="2.6.31.3" />
                <vers num="2.6.31.4" />
                <vers num="2.6.31.5" />
                <vers num="2.6.31.6" />
                <vers edition="rc1" num="2.6.32" prev="1" />
                <vers edition="rc3" num="2.6.32" prev="1" />
                <vers edition="rc4" num="2.6.32" prev="1" />
                <vers edition="rc5" num="2.6.32" prev="1" />
                <vers edition="rc6" num="2.6.32" prev="1" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:P)" CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" name="CVE-2009-4022" seq="2009-4022" severity="Medium" type="CVE" published="2009-11-25" CVSS_version="2.0" CVSS_score="4.0" modified="2010-01-28">
        <desc>
            <descript source="cve">Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=538744">https://bugzilla.redhat.com/show_bug.cgi?id=538744</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01188.html">FEDORA-2009-12233</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01172.html">FEDORA-2009-12218</ref>
            <ref source="CONFIRM" url="https://www.isc.org/advisories/CVE2009-4022">https://www.isc.org/advisories/CVE2009-4022</ref>
            <ref source="CONFIRM" url="https://www.isc.org/advisories/CVE-2009-4022v6">https://www.isc.org/advisories/CVE-2009-4022v6</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54416">bind-dnssec-cache-poisoning(54416)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0176">ADV-2010-0176</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3335">ADV-2009-3335</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-888-1">USN-888-1</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37118">37118</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1620.html">RHSA-2009:1620</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/24/8">[oss-security] 20091124 Re: a new bind issue</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/24/2">[oss-security] 20091124 CVE request: BIND 9 bug involving DNSSEC and the additional section</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/11/24/1">[oss-security] 20091124 a new bind issue</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:304">MDVSA-2009:304</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38240">38240</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38219">38219</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37491">37491</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37426">37426</ref>
            <ref source="OSVDB" url="http://osvdb.org/60493">60493</ref>
        </refs>
        <vuln_soft>
            <prod vendor="isc" name="bind">
                <vers edition="rc1" num="9.4.0" />
                <vers num="9.4.0a1" />
                <vers num="9.4.0a2" />
                <vers num="9.4.0a3" />
                <vers num="9.4.0a4" />
                <vers num="9.4.0a5" />
                <vers num="9.4.0a6" />
                <vers num="9.4.0b1" />
                <vers num="9.4.0b2" />
                <vers num="9.4.0b3" />
                <vers num="9.4.0b4" />
                <vers num="9.4.1" />
                <vers num="9.4.2" />
                <vers edition="p2" num="9.4.3" />
                <vers edition="rc1" num="9.4.3" />
                <vers num="9.4.3b1" />
                <vers num="9.4.3b2" />
                <vers num="9.4.3b3" />
                <vers num="9.5" />
                <vers edition="rc1" num="9.5.0" />
                <vers num="9.5.0-p1" />
                <vers num="9.5.0-p2" />
                <vers num="9.5.0-p2-w1" />
                <vers num="9.5.0-p2-w2" />
                <vers num="9.5.0a1" />
                <vers num="9.5.0a2" />
                <vers num="9.5.0a3" />
                <vers num="9.5.0a4" />
                <vers num="9.5.0a5" />
                <vers num="9.5.0a6" />
                <vers num="9.5.0a7" />
                <vers num="9.5.0b1" />
                <vers num="9.5.0b2" />
                <vers num="9.5.0b3" />
                <vers edition="rc1" num="9.5.1" />
                <vers edition="rc2" num="9.5.1" />
                <vers num="9.5.1b1" />
                <vers num="9.5.1b2" />
                <vers num="9.5.1b3" />
                <vers edition="p1" num="9.6.0" />
                <vers edition="rc1" num="9.6.0" />
                <vers edition="rc2" num="9.6.0" />
                <vers num="9.6.0a1" />
                <vers num="9.6.0b1" />
                <vers edition="p1" num="9.6.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-4074" seq="2009-4074" severity="Medium" type="CVE" published="2009-11-25" CVSS_version="2.0" CVSS_score="4.3" modified="2010-01-28">
        <desc>
            <descript source="cve">The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka "XSS Filter Script Handling Vulnerability."</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="MISC" url="http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/">http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37135">37135</ref>
            <ref source="MISC" url="http://www.owasp.org/images/5/50/OWASP-Italy_Day_IV_Maone.pdf">http://www.owasp.org/images/5/50/OWASP-Italy_Day_IV_Maone.pdf</ref>
            <ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx">MS10-002</ref>
            <ref source="MISC" url="http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/">http://hackademix.net/2009/11/21/ies-xss-filter-creates-xss-vulnerabilities/</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="ie">
                <vers num="8" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3560" seq="2009-3560" severity="Medium" type="CVE" published="2009-12-04" CVSS_version="2.0" CVSS_score="5.0" modified="2010-01-28">
        <desc>
            <descript source="cve">The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=533174">https://bugzilla.redhat.com/show_bug.cgi?id=533174</ref>
            <ref source="CONFIRM" patch="1" url="http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?view=log#rev1.165">http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?view=log#rev1.165</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00413.html">FEDORA-2009-12737</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00394.html">FEDORA-2009-12716</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00370.html">FEDORA-2009-12690</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023278">1023278</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37203">37203</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:316">MDVSA-2009:316</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1953">DSA-1953</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-273630-1">273630</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37537">37537</ref>
            <ref source="MLIST" url="http://mail.python.org/pipermail/expat-bugs/2009-November/002846.html">[expat-bugs] 20091108 [ expat-Bugs-2894085 ] expat: buffer over-read and crash in big2_toUtf8()</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html">SUSE-SR:2010:001</ref>
            <ref source="CONFIRM" url="http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&amp;r2=1.165">http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&amp;r2=1.165</ref>
        </refs>
        <vuln_soft>
            <prod vendor="james_clark" name="expat">
                <vers num="2.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" name="CVE-2009-4020" seq="2009-4020" severity="High" type="CVE" published="2009-12-04" CVSS_version="2.0" CVSS_score="7.8" modified="2010-02-02">
        <desc>
            <descript source="cve">Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://userweb.kernel.org/~akpm/mmotm/broken-out/hfs-fix-a-potential-buffer-overflow.patch">http://userweb.kernel.org/~akpm/mmotm/broken-out/hfs-fix-a-potential-buffer-overflow.patch</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2010-0046.html">RHSA-2010:0046</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=540736">https://bugzilla.redhat.com/show_bug.cgi?id=540736</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/12/04/1">[oss-security] 20091204 CVE-2009-4020 kernel: hfs buffer overflow</ref>
            <ref source="MLIST" url="http://marc.info/?l=linux-mm-commits&amp;m=125987755823047&amp;w=2">[linux-mm-commits] 20091203 + hfs-fix-a-potential-buffer-overflow.patch added to -mm tree</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.32" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3794" seq="2009-3794" severity="High" type="CVE" published="2009-12-10" CVSS_version="2.0" CVSS_score="9.3" modified="2010-01-23">
        <desc>
            <descript source="cve">Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-343A.html">TA09-343A</ref>
            <ref source="MISC" patch="1" url="http://zerodayinitiative.com/advisories/ZDI-09-092/">http://zerodayinitiative.com/advisories/ZDI-09-092/</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3456" adv="1">ADV-2009-3456</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2009-1658.html">RHSA-2009:1658</ref>
            <ref source="CONFIRM" patch="1" url="http://www.adobe.com/support/security/bulletins/apsb09-19.html" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-19.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=543857">https://bugzilla.redhat.com/show_bug.cgi?id=543857</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54631">flash-air-jpeg-code-execution(54631)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0173">ADV-2010-0173</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37199">37199</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/508336/100/0/threaded">20091209 ZDI-09-092: Adobe Flash Player JPEG Parsing Heap Overflow Vulnerability</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2009-1657.html">RHSA-2009:1657</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4004">http://support.apple.com/kb/HT4004</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023307">1023307</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023306">1023306</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38241">38241</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37902">37902</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37584" adv="1">37584</ref>
            <ref source="OSVDB" url="http://osvdb.org/60885">60885</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00003.html">SUSE-SA:2009:062</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html">APPLE-SA-2010-01-19-1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="adobe_air">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.1" />
                <vers num="1.5.1" />
                <vers num="1.5.2" prev="1" />
            </prod>
            <prod vendor="adobe" name="flash_player">
                <vers num="10.0.0.584" />
                <vers num="10.0.12.10" />
                <vers num="10.0.12.36" />
                <vers num="10.0.22.87" />
                <vers num="10.0.32.18" prev="1" />
                <vers num="7" />
                <vers num="7.0" />
                <vers num="7.0.1" />
                <vers num="7.0.25" />
                <vers num="7.0.63" />
                <vers num="7.0.69.0" />
                <vers num="7.0.70.0" />
                <vers num="7.1" />
                <vers num="7.1.1" />
                <vers num="7.2" />
                <vers edition="" num="8" />
                <vers edition=":professional" num="8" />
                <vers edition=":pro" num="8" />
                <vers edition="" num="8.0" />
                <vers edition=":pro" num="8.0" />
                <vers edition=":basic" num="8.0" />
                <vers num="8.0.24.0" />
                <vers num="8.0.34.0" />
                <vers num="8.0.35.0" />
                <vers num="8.0.39.0" />
                <vers num="9" />
                <vers num="9.0.112.0" />
                <vers num="9.0.114.0" />
                <vers num="9.0.115.0" />
                <vers num="9.0.124.0" />
                <vers num="9.0.155.0" />
                <vers num="9.0.159.0" />
                <vers num="9.0.16" />
                <vers num="9.0.18d60" />
                <vers num="9.0.20" />
                <vers num="9.0.20.0" />
                <vers num="9.0.28" />
                <vers num="9.0.28.0" />
                <vers num="9.0.31" />
                <vers num="9.0.31.0" />
                <vers num="9.0.45.0" />
                <vers num="9.0.47.0" />
                <vers num="9.125.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3796" seq="2009-3796" severity="High" type="CVE" published="2009-12-10" CVSS_version="2.0" CVSS_score="9.3" modified="2010-01-23">
        <desc>
            <descript source="cve">Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors, related to a "data injection vulnerability."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-343A.html">TA09-343A</ref>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=543857">https://bugzilla.redhat.com/show_bug.cgi?id=543857</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3456" adv="1">ADV-2009-3456</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2009-1658.html">RHSA-2009:1658</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2009-1657.html">RHSA-2009:1657</ref>
            <ref source="CONFIRM" patch="1" url="http://www.adobe.com/support/security/bulletins/apsb09-19.html" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-19.html</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1023307">1023307</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1023306">1023306</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54632">flash-air-data-code-execution(54632)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0173">ADV-2010-0173</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37199">37199</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4004">http://support.apple.com/kb/HT4004</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38241">38241</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37902">37902</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37584" adv="1">37584</ref>
            <ref source="OSVDB" url="http://osvdb.org/60886">60886</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00003.html">SUSE-SA:2009:062</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html">APPLE-SA-2010-01-19-1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="adobe_air">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.1" />
                <vers num="1.5.1" />
                <vers num="1.5.2" prev="1" />
            </prod>
            <prod vendor="adobe" name="flash_player">
                <vers num="10.0.0.584" />
                <vers num="10.0.12.10" />
                <vers num="10.0.12.36" />
                <vers num="10.0.22.87" />
                <vers num="10.0.32.18" prev="1" />
                <vers num="7" />
                <vers num="7.0" />
                <vers num="7.0.1" />
                <vers num="7.0.25" />
                <vers num="7.0.63" />
                <vers num="7.0.69.0" />
                <vers num="7.0.70.0" />
                <vers num="7.1" />
                <vers num="7.1.1" />
                <vers num="7.2" />
                <vers edition="" num="8" />
                <vers edition=":professional" num="8" />
                <vers edition=":pro" num="8" />
                <vers edition="" num="8.0" />
                <vers edition=":pro" num="8.0" />
                <vers edition=":basic" num="8.0" />
                <vers num="8.0.24.0" />
                <vers num="8.0.34.0" />
                <vers num="8.0.35.0" />
                <vers num="8.0.39.0" />
                <vers num="9" />
                <vers num="9.0.112.0" />
                <vers num="9.0.114.0" />
                <vers num="9.0.115.0" />
                <vers num="9.0.124.0" />
                <vers num="9.0.155.0" />
                <vers num="9.0.159.0" />
                <vers num="9.0.16" />
                <vers num="9.0.18d60" />
                <vers num="9.0.20" />
                <vers num="9.0.20.0" />
                <vers num="9.0.28" />
                <vers num="9.0.28.0" />
                <vers num="9.0.31" />
                <vers num="9.0.31.0" />
                <vers num="9.0.45.0" />
                <vers num="9.0.47.0" />
                <vers num="9.125.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3797" seq="2009-3797" severity="High" type="CVE" published="2009-12-10" CVSS_version="2.0" CVSS_score="9.3" modified="2010-01-23">
        <desc>
            <descript source="cve">Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-343A.html">TA09-343A</ref>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=543857">https://bugzilla.redhat.com/show_bug.cgi?id=543857</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3456" adv="1">ADV-2009-3456</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2009-1657.html">RHSA-2009:1657</ref>
            <ref source="CONFIRM" patch="1" url="http://www.adobe.com/support/security/bulletins/apsb09-19.html" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-19.html</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1023307">1023307</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1023306">1023306</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54633">flash-air-corruption-code-execution(54633)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0173">ADV-2010-0173</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37199">37199</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4004">http://support.apple.com/kb/HT4004</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38241">38241</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37902">37902</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37584" adv="1">37584</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00003.html">SUSE-SA:2009:062</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html">APPLE-SA-2010-01-19-1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="adobe_air">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.1" />
                <vers num="1.5.1" />
                <vers num="1.5.2" prev="1" />
            </prod>
            <prod vendor="adobe" name="flash_player">
                <vers num="10.0.0.584" />
                <vers num="10.0.12.10" />
                <vers num="10.0.12.36" />
                <vers num="10.0.22.87" />
                <vers num="10.0.32.18" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3798" seq="2009-3798" severity="High" type="CVE" published="2009-12-10" CVSS_version="2.0" CVSS_score="9.3" modified="2010-01-23">
        <desc>
            <descript source="cve">Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-343A.html">TA09-343A</ref>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=543857">https://bugzilla.redhat.com/show_bug.cgi?id=543857</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3456" adv="1">ADV-2009-3456</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2009-1658.html">RHSA-2009:1658</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2009-1657.html">RHSA-2009:1657</ref>
            <ref source="CONFIRM" patch="1" url="http://www.adobe.com/support/security/bulletins/apsb09-19.html" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-19.html</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1023307">1023307</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1023306">1023306</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54634">flash-air-unspecified-code-execution(54634)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0173">ADV-2010-0173</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37199">37199</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4004">http://support.apple.com/kb/HT4004</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38241">38241</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37902">37902</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37584" adv="1">37584</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00003.html">SUSE-SA:2009:062</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html">APPLE-SA-2010-01-19-1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="adobe_air">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.1" />
                <vers num="1.5.1" />
                <vers num="1.5.2" prev="1" />
            </prod>
            <prod vendor="adobe" name="flash_player">
                <vers num="10.0.0.584" />
                <vers num="10.0.12.10" />
                <vers num="10.0.12.36" />
                <vers num="10.0.22.87" />
                <vers num="10.0.32.18" prev="1" />
                <vers num="7" />
                <vers num="7.0" />
                <vers num="7.0.1" />
                <vers num="7.0.25" />
                <vers num="7.0.63" />
                <vers num="7.0.69.0" />
                <vers num="7.0.70.0" />
                <vers num="7.1" />
                <vers num="7.1.1" />
                <vers num="7.2" />
                <vers edition="" num="8" />
                <vers edition=":professional" num="8" />
                <vers edition=":pro" num="8" />
                <vers edition="" num="8.0" />
                <vers edition=":pro" num="8.0" />
                <vers edition=":basic" num="8.0" />
                <vers num="8.0.24.0" />
                <vers num="8.0.34.0" />
                <vers num="8.0.35.0" />
                <vers num="8.0.39.0" />
                <vers num="9" />
                <vers num="9.0.112.0" />
                <vers num="9.0.114.0" />
                <vers num="9.0.115.0" />
                <vers num="9.0.124.0" />
                <vers num="9.0.155.0" />
                <vers num="9.0.159.0" />
                <vers num="9.0.16" />
                <vers num="9.0.18d60" />
                <vers num="9.0.20" />
                <vers num="9.0.20.0" />
                <vers num="9.0.28" />
                <vers num="9.0.28.0" />
                <vers num="9.0.31" />
                <vers num="9.0.31.0" />
                <vers num="9.0.45.0" />
                <vers num="9.0.47.0" />
                <vers num="9.125.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3799" seq="2009-3799" severity="High" type="CVE" published="2009-12-10" CVSS_version="2.0" CVSS_score="9.3" modified="2010-01-23">
        <desc>
            <descript source="cve">Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory corruption, related to "generation of ActionScript exception handlers."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-343A.html">TA09-343A</ref>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=543857">https://bugzilla.redhat.com/show_bug.cgi?id=543857</ref>
            <ref source="MISC" patch="1" url="http://zerodayinitiative.com/advisories/ZDI-09-093/">http://zerodayinitiative.com/advisories/ZDI-09-093/</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3456" adv="1">ADV-2009-3456</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2009-1658.html">RHSA-2009:1658</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2009-1657.html">RHSA-2009:1657</ref>
            <ref source="CONFIRM" patch="1" url="http://www.adobe.com/support/security/bulletins/apsb09-19.html" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-19.html</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1023307">1023307</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1023306">1023306</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54635">flash-air-unspecified-overflow(54635)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0173">ADV-2010-0173</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37199">37199</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/508334/100/0/threaded">20091209 ZDI-09-093: Adobe Flash Player ActionScript Exception Handler Integer Overflow Vulnerability</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4004">http://support.apple.com/kb/HT4004</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38241">38241</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37902">37902</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37584" adv="1">37584</ref>
            <ref source="OSVDB" url="http://osvdb.org/60889">60889</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00003.html">SUSE-SA:2009:062</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html">APPLE-SA-2010-01-19-1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="adobe_air">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.1" />
                <vers num="1.5.1" />
                <vers num="1.5.2" prev="1" />
            </prod>
            <prod vendor="adobe" name="flash_player">
                <vers num="10.0.0.584" />
                <vers num="10.0.12.10" />
                <vers num="10.0.12.36" />
                <vers num="10.0.22.87" />
                <vers num="10.0.32.18" prev="1" />
                <vers num="7" />
                <vers num="7.0" />
                <vers num="7.0.1" />
                <vers num="7.0.25" />
                <vers num="7.0.63" />
                <vers num="7.0.69.0" />
                <vers num="7.0.70.0" />
                <vers num="7.1" />
                <vers num="7.1.1" />
                <vers num="7.2" />
                <vers edition="" num="8" />
                <vers edition=":professional" num="8" />
                <vers edition=":pro" num="8" />
                <vers edition="" num="8.0" />
                <vers edition=":pro" num="8.0" />
                <vers edition=":basic" num="8.0" />
                <vers num="8.0.24.0" />
                <vers num="8.0.34.0" />
                <vers num="8.0.35.0" />
                <vers num="8.0.39.0" />
                <vers num="9" />
                <vers num="9.0.112.0" />
                <vers num="9.0.114.0" />
                <vers num="9.0.115.0" />
                <vers num="9.0.124.0" />
                <vers num="9.0.155.0" />
                <vers num="9.0.159.0" />
                <vers num="9.0.16" />
                <vers num="9.0.18d60" />
                <vers num="9.0.20" />
                <vers num="9.0.20.0" />
                <vers num="9.0.28" />
                <vers num="9.0.28.0" />
                <vers num="9.0.31" />
                <vers num="9.0.31.0" />
                <vers num="9.0.45.0" />
                <vers num="9.0.47.0" />
                <vers num="9.125.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3800" seq="2009-3800" severity="High" type="CVE" published="2009-12-10" CVSS_version="2.0" CVSS_score="9.3" modified="2010-01-23">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allow attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-343A.html">TA09-343A</ref>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=543857">https://bugzilla.redhat.com/show_bug.cgi?id=543857</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3456" adv="1">ADV-2009-3456</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2009-1658.html">RHSA-2009:1658</ref>
            <ref source="REDHAT" patch="1" url="http://www.redhat.com/support/errata/RHSA-2009-1657.html">RHSA-2009:1657</ref>
            <ref source="CONFIRM" patch="1" url="http://www.adobe.com/support/security/bulletins/apsb09-19.html" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-19.html</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1023307">1023307</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1023306">1023306</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54636">flash-air-multiple-code-execution(54636)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0173">ADV-2010-0173</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37199">37199</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4004">http://support.apple.com/kb/HT4004</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38241">38241</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37902">37902</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37584" adv="1">37584</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00003.html">SUSE-SA:2009:062</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html">APPLE-SA-2010-01-19-1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="adobe_air">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.1" />
                <vers num="1.5.1" />
                <vers num="1.5.2" prev="1" />
            </prod>
            <prod vendor="adobe" name="flash_player">
                <vers num="10.0.0.584" />
                <vers num="10.0.12.10" />
                <vers num="10.0.12.36" />
                <vers num="10.0.22.87" />
                <vers num="10.0.32.18" prev="1" />
                <vers num="7" />
                <vers num="7.0" />
                <vers num="7.0.1" />
                <vers num="7.0.25" />
                <vers num="7.0.63" />
                <vers num="7.0.69.0" />
                <vers num="7.0.70.0" />
                <vers num="7.1" />
                <vers num="7.1.1" />
                <vers num="7.2" />
                <vers edition="" num="8" />
                <vers edition=":professional" num="8" />
                <vers edition=":pro" num="8" />
                <vers edition="" num="8.0" />
                <vers edition=":pro" num="8.0" />
                <vers edition=":basic" num="8.0" />
                <vers num="8.0.24.0" />
                <vers num="8.0.34.0" />
                <vers num="8.0.35.0" />
                <vers num="8.0.39.0" />
                <vers num="9" />
                <vers num="9.0.112.0" />
                <vers num="9.0.114.0" />
                <vers num="9.0.115.0" />
                <vers num="9.0.124.0" />
                <vers num="9.0.155.0" />
                <vers num="9.0.159.0" />
                <vers num="9.0.16" />
                <vers num="9.0.18d60" />
                <vers num="9.0.20" />
                <vers num="9.0.20.0" />
                <vers num="9.0.28" />
                <vers num="9.0.28.0" />
                <vers num="9.0.31" />
                <vers num="9.0.31.0" />
                <vers num="9.0.45.0" />
                <vers num="9.0.47.0" />
                <vers num="9.125.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" name="CVE-2009-3951" seq="2009-3951" severity="High" type="CVE" published="2009-12-10" CVSS_version="2.0" CVSS_score="7.1" modified="2010-01-23">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4820.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA09-343A.html">TA09-343A</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3456" adv="1">ADV-2009-3456</ref>
            <ref source="CONFIRM" patch="1" url="http://www.adobe.com/support/security/bulletins/apsb09-19.html" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-19.html</ref>
            <ref source="SECTRACK" patch="1" url="http://securitytracker.com/id?1023307">1023307</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54637">flash-activex-information-disclosure(54637)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0173">ADV-2010-0173</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37199">37199</ref>
            <ref source="CONFIRM" url="http://support.apple.com/kb/HT4004">http://support.apple.com/kb/HT4004</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38241">38241</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37902">37902</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37584" adv="1">37584</ref>
            <ref source="OSVDB" url="http://osvdb.org/60891">60891</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2009-12/msg00003.html">SUSE-SA:2009:062</ref>
            <ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html">APPLE-SA-2010-01-19-1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="adobe_air">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.1" />
                <vers num="1.5.1" />
                <vers num="1.5.2" prev="1" />
            </prod>
            <prod vendor="adobe" name="flash_player">
                <vers num="10.0.0.584" />
                <vers num="10.0.12.10" />
                <vers num="10.0.12.36" />
                <vers num="10.0.22.87" />
                <vers num="10.0.32.18" prev="1" />
                <vers num="7" />
                <vers num="7.0" />
                <vers num="7.0.1" />
                <vers num="7.0.25" />
                <vers num="7.0.63" />
                <vers num="7.0.69.0" />
                <vers num="7.0.70.0" />
                <vers num="7.1" />
                <vers num="7.1.1" />
                <vers num="7.2" />
                <vers edition="" num="8" />
                <vers edition=":professional" num="8" />
                <vers edition=":pro" num="8" />
                <vers edition="" num="8.0" />
                <vers edition=":pro" num="8.0" />
                <vers edition=":basic" num="8.0" />
                <vers num="8.0.24.0" />
                <vers num="8.0.34.0" />
                <vers num="8.0.35.0" />
                <vers num="8.0.39.0" />
                <vers num="9" />
                <vers num="9.0.112.0" />
                <vers num="9.0.114.0" />
                <vers num="9.0.115.0" />
                <vers num="9.0.124.0" />
                <vers num="9.0.155.0" />
                <vers num="9.0.159.0" />
                <vers num="9.0.16" />
                <vers num="9.0.18d60" />
                <vers num="9.0.20" />
                <vers num="9.0.20.0" />
                <vers num="9.0.28" />
                <vers num="9.0.28.0" />
                <vers num="9.0.31" />
                <vers num="9.0.31.0" />
                <vers num="9.0.45.0" />
                <vers num="9.0.47.0" />
                <vers num="9.0.48.0" />
                <vers num="9.125.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-4324" seq="2009-4324" severity="High" type="CVE" published="2009-12-14" CVSS_version="2.0" CVSS_score="9.3" modified="2010-02-02">
        <desc>
            <descript source="cve">Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA10-013A.html">TA10-013A</ref>
            <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/508357">VU#508357</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54747">acro-reader-unspecifed-code-execution(54747)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0103">ADV-2010-0103</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3518" adv="1">ADV-2009-3518</ref>
            <ref source="MISC" url="http://www.symantec.com/connect/blogs/zero-day-xmas-present">http://www.symantec.com/connect/blogs/zero-day-xmas-present</ref>
            <ref source="MISC" url="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214">http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20091214</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37331">37331</ref>
            <ref source="MISC" url="http://www.metasploit.com/redmine/projects/framework/repository/revisions/7881/entry/modules/exploits/windows/fileformat/adobe_media_newplayer.rb">http://www.metasploit.com/redmine/projects/framework/repository/revisions/7881/entry/modules/exploits/windows/fileformat/adobe_media_newplayer.rb</ref>
            <ref source="CONFIRM" url="http://www.adobe.com/support/security/bulletins/apsb10-02.html">http://www.adobe.com/support/security/bulletins/apsb10-02.html</ref>
            <ref source="CONFIRM" url="http://www.adobe.com/support/security/advisories/apsa09-07.html" adv="1">http://www.adobe.com/support/security/advisories/apsa09-07.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37690" adv="1">37690</ref>
            <ref source="OSVDB" url="http://osvdb.org/60980">60980</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html">SUSE-SA:2010:008</ref>
            <ref source="MISC" url="http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.html">http://contagiodump.blogspot.com/2009/12/virustotal-httpwww.html</ref>
            <ref source="MISC" url="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html" adv="1">http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="acrobat">
                <vers num="6.0" />
                <vers num="6.0.1" />
                <vers num="6.0.2" />
                <vers num="6.0.3" />
                <vers num="6.0.4" />
                <vers num="6.0.5" />
                <vers num="7.0" />
                <vers num="7.0.1" />
                <vers num="7.0.2" />
                <vers num="7.0.3" />
                <vers num="7.0.4" />
                <vers num="7.0.5" />
                <vers num="7.0.6" />
                <vers num="7.0.7" />
                <vers num="7.0.8" />
                <vers num="7.0.9" />
                <vers num="8.0.0" />
                <vers num="8.1" />
                <vers num="8.1.1" />
                <vers num="8.1.2" />
            </prod>
            <prod vendor="adobe" name="acrobat_reader">
                <vers num="3.0" />
                <vers num="4.0" />
                <vers num="4.0.5" />
                <vers num="4.0.5a" />
                <vers num="4.0.5c" />
                <vers num="4.5" />
                <vers num="5.0" />
                <vers num="5.0.10" />
                <vers num="5.0.11" />
                <vers num="5.0.5" />
                <vers num="5.0.6" />
                <vers num="5.0.7" />
                <vers num="5.0.9" />
                <vers num="5.1" />
                <vers num="6.0" />
                <vers num="6.0.1" />
                <vers num="6.0.2" />
                <vers num="6.0.3" />
                <vers num="6.0.4" />
                <vers num="6.0.5" />
                <vers num="7.0" />
                <vers num="7.0.1" />
                <vers num="7.0.2" />
                <vers num="7.0.3" />
                <vers num="7.0.4" />
                <vers num="7.0.5" />
                <vers num="7.0.6" />
                <vers num="7.0.7" />
                <vers num="7.0.8" />
                <vers num="7.0.9" />
                <vers num="8.0" />
                <vers num="8.1" />
                <vers num="8.1.1" />
                <vers num="8.1.2" />
                <vers num="9.0" />
                <vers num="9.1" />
                <vers num="9.2" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" name="CVE-2009-4034" seq="2009-4034" severity="Medium" type="CVE" published="2009-12-15" CVSS_version="2.0" CVSS_score="5.8" modified="2010-01-28">
        <desc>
            <descript source="cve">PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based PostgreSQL servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended client-hostname restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.postgresql.org/docs/current/static/release-8-4-2.html" adv="1">http://www.postgresql.org/docs/current/static/release-8-4-2.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.postgresql.org/docs/current/static/release-8-3-9.html" adv="1">http://www.postgresql.org/docs/current/static/release-8-3-9.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.postgresql.org/docs/current/static/release-8-2-15.html" adv="1">http://www.postgresql.org/docs/current/static/release-8-2-15.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.postgresql.org/docs/current/static/release-8-1-19.html" adv="1">http://www.postgresql.org/docs/current/static/release-8-1-19.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.postgresql.org/docs/current/static/release-8-0-23.html" adv="1">http://www.postgresql.org/docs/current/static/release-8-0-23.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.postgresql.org/docs/current/static/release-7-4-27.html" adv="1">http://www.postgresql.org/docs/current/static/release-7-4-27.html</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01056.html">FEDORA-2009-13381</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01035.html">FEDORA-2009-13363</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3519">ADV-2009-3519</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023325">1023325</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37334">37334</ref>
            <ref source="CONFIRM" url="http://www.postgresql.org/support/security.html" adv="1">http://www.postgresql.org/support/security.html</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:333">MDVSA-2009:333</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37663">37663</ref>
            <ref source="OSVDB" url="http://osvdb.org/61038">61038</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html">SUSE-SR:2010:001</ref>
        </refs>
        <vuln_soft>
            <prod vendor="postgresql" name="postgresql">
                <vers num="7.4.1" />
                <vers num="7.4.10" />
                <vers num="7.4.11" />
                <vers num="7.4.12" />
                <vers num="7.4.13" />
                <vers num="7.4.14" />
                <vers num="7.4.15" />
                <vers num="7.4.16" />
                <vers num="7.4.17" />
                <vers num="7.4.18" />
                <vers num="7.4.19" />
                <vers num="7.4.2" />
                <vers num="7.4.20" />
                <vers num="7.4.21" />
                <vers num="7.4.22" />
                <vers num="7.4.23" />
                <vers num="7.4.24" />
                <vers num="7.4.25" />
                <vers num="7.4.26" />
                <vers num="7.4.3" />
                <vers num="7.4.4" />
                <vers num="7.4.5" />
                <vers num="7.4.6" />
                <vers num="7.4.7" />
                <vers num="7.4.8" />
                <vers num="7.4.9" />
                <vers num="8.0.0" />
                <vers num="8.0.1" />
                <vers num="8.0.10" />
                <vers num="8.0.11" />
                <vers num="8.0.12" />
                <vers num="8.0.13" />
                <vers num="8.0.14" />
                <vers num="8.0.15" />
                <vers num="8.0.16" />
                <vers num="8.0.17" />
                <vers num="8.0.18" />
                <vers num="8.0.19" />
                <vers num="8.0.2" />
                <vers num="8.0.20" />
                <vers num="8.0.21" />
                <vers num="8.0.22" />
                <vers num="8.0.3" />
                <vers num="8.0.4" />
                <vers num="8.0.5" />
                <vers num="8.0.6" />
                <vers num="8.0.7" />
                <vers num="8.0.8" />
                <vers num="8.0.9" />
                <vers num="8.1.0" />
                <vers num="8.1.1" />
                <vers num="8.1.10" />
                <vers num="8.1.11" />
                <vers num="8.1.12" />
                <vers num="8.1.13" />
                <vers num="8.1.14" />
                <vers num="8.1.15" />
                <vers num="8.1.16" />
                <vers num="8.1.17" />
                <vers num="8.1.18" />
                <vers num="8.1.2" />
                <vers num="8.1.3" />
                <vers num="8.1.4" />
                <vers num="8.1.5" />
                <vers num="8.1.6" />
                <vers num="8.1.7" />
                <vers num="8.1.8" />
                <vers num="8.1.9" />
                <vers num="8.2" />
                <vers num="8.2.1" />
                <vers num="8.2.10" />
                <vers num="8.2.11" />
                <vers num="8.2.12" />
                <vers num="8.2.13" />
                <vers num="8.2.14" />
                <vers num="8.2.2" />
                <vers num="8.2.3" />
                <vers num="8.2.4" />
                <vers num="8.2.5" />
                <vers num="8.2.6" />
                <vers num="8.2.7" />
                <vers num="8.2.8" />
                <vers num="8.2.9" />
                <vers num="8.3.1" />
                <vers num="8.3.2" />
                <vers num="8.3.3" />
                <vers num="8.3.4" />
                <vers num="8.3.5" />
                <vers num="8.3.6" />
                <vers num="8.3.7" />
                <vers num="8.3.8" />
                <vers num="8.4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" name="CVE-2009-4136" seq="2009-4136" severity="Medium" type="CVE" published="2009-12-15" CVSS_version="2.0" CVSS_score="6.5" modified="2010-01-28">
        <desc>
            <descript source="cve">PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution of an index function by a database superuser, which allows remote authenticated users to gain privileges via a table with crafted index functions, as demonstrated by functions that modify (1) search_path or (2) a prepared statement, a related issue to CVE-2007-6600 and CVE-2009-3230.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=546321">https://bugzilla.redhat.com/show_bug.cgi?id=546321</ref>
            <ref source="CONFIRM" patch="1" url="http://www.postgresql.org/docs/current/static/release-8-4-2.html" adv="1">http://www.postgresql.org/docs/current/static/release-8-4-2.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.postgresql.org/docs/current/static/release-8-3-9.html" adv="1">http://www.postgresql.org/docs/current/static/release-8-3-9.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.postgresql.org/docs/current/static/release-8-2-15.html" adv="1">http://www.postgresql.org/docs/current/static/release-8-2-15.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.postgresql.org/docs/current/static/release-8-1-19.html" adv="1">http://www.postgresql.org/docs/current/static/release-8-1-19.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.postgresql.org/docs/current/static/release-8-0-23.html" adv="1">http://www.postgresql.org/docs/current/static/release-8-0-23.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.postgresql.org/docs/current/static/release-7-4-27.html" adv="1">http://www.postgresql.org/docs/current/static/release-7-4-27.html</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01056.html">FEDORA-2009-13381</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01035.html">FEDORA-2009-13363</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3519">ADV-2009-3519</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023326">1023326</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37333">37333</ref>
            <ref source="CONFIRM" url="http://www.postgresql.org/support/security.html" adv="1">http://www.postgresql.org/support/security.html</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:333">MDVSA-2009:333</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37663">37663</ref>
            <ref source="OSVDB" url="http://osvdb.org/61039">61039</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html">SUSE-SR:2010:001</ref>
        </refs>
        <vuln_soft>
            <prod vendor="postgresql" name="postgresql">
                <vers num="7.4.1" />
                <vers num="7.4.10" />
                <vers num="7.4.11" />
                <vers num="7.4.12" />
                <vers num="7.4.13" />
                <vers num="7.4.14" />
                <vers num="7.4.15" />
                <vers num="7.4.16" />
                <vers num="7.4.17" />
                <vers num="7.4.18" />
                <vers num="7.4.19" />
                <vers num="7.4.2" />
                <vers num="7.4.20" />
                <vers num="7.4.21" />
                <vers num="7.4.22" />
                <vers num="7.4.23" />
                <vers num="7.4.24" />
                <vers num="7.4.25" />
                <vers num="7.4.26" />
                <vers num="7.4.3" />
                <vers num="7.4.4" />
                <vers num="7.4.5" />
                <vers num="7.4.6" />
                <vers num="7.4.7" />
                <vers num="7.4.8" />
                <vers num="7.4.9" />
                <vers num="8.0.0" />
                <vers num="8.0.1" />
                <vers num="8.0.10" />
                <vers num="8.0.11" />
                <vers num="8.0.12" />
                <vers num="8.0.13" />
                <vers num="8.0.14" />
                <vers num="8.0.15" />
                <vers num="8.0.16" />
                <vers num="8.0.17" />
                <vers num="8.0.18" />
                <vers num="8.0.19" />
                <vers num="8.0.2" />
                <vers num="8.0.20" />
                <vers num="8.0.21" />
                <vers num="8.0.22" />
                <vers num="8.0.3" />
                <vers num="8.0.4" />
                <vers num="8.0.5" />
                <vers num="8.0.6" />
                <vers num="8.0.7" />
                <vers num="8.0.8" />
                <vers num="8.0.9" />
                <vers num="8.1.0" />
                <vers num="8.1.1" />
                <vers num="8.1.10" />
                <vers num="8.1.11" />
                <vers num="8.1.12" />
                <vers num="8.1.13" />
                <vers num="8.1.14" />
                <vers num="8.1.15" />
                <vers num="8.1.16" />
                <vers num="8.1.17" />
                <vers num="8.1.18" />
                <vers num="8.1.2" />
                <vers num="8.1.3" />
                <vers num="8.1.4" />
                <vers num="8.1.5" />
                <vers num="8.1.6" />
                <vers num="8.1.7" />
                <vers num="8.1.8" />
                <vers num="8.1.9" />
                <vers num="8.2" />
                <vers num="8.2.1" />
                <vers num="8.2.10" />
                <vers num="8.2.11" />
                <vers num="8.2.12" />
                <vers num="8.2.13" />
                <vers num="8.2.14" />
                <vers num="8.2.2" />
                <vers num="8.2.3" />
                <vers num="8.2.4" />
                <vers num="8.2.5" />
                <vers num="8.2.6" />
                <vers num="8.2.7" />
                <vers num="8.2.8" />
                <vers num="8.2.9" />
                <vers num="8.3.1" />
                <vers num="8.3.2" />
                <vers num="8.3.3" />
                <vers num="8.3.4" />
                <vers num="8.3.5" />
                <vers num="8.3.6" />
                <vers num="8.3.7" />
                <vers num="8.3.8" />
                <vers num="8.4.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_base_score="4.7" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.9" name="CVE-2009-4138" seq="2009-4138" severity="Medium" type="CVE" published="2009-12-16" CVSS_version="2.0" CVSS_score="4.7" modified="2010-02-02">
        <desc>
            <descript source="cve">drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ioctl associated with receiving an ISO packet that contains zero in the payload-length field.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=547236">https://bugzilla.redhat.com/show_bug.cgi?id=547236</ref>
            <ref source="MLIST" patch="1" url="http://www.openwall.com/lists/oss-security/2009/12/15/1">[oss-security] 20091215 CVE-2009-4138 kernel: firewire: ohci: handle receive packets with a data length of zero</ref>
            <ref source="CONFIRM" patch="1" url="http://patchwork.kernel.org/patch/66747/">http://patchwork.kernel.org/patch/66747/</ref>
            <ref source="CONFIRM" patch="1" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8c0c0cc2d9f4c523fde04bdfe41e4380dec8ee54">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8c0c0cc2d9f4c523fde04bdfe41e4380dec8ee54</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2010-0046.html">RHSA-2010:0046</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37339">37339</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.32-git9.log">http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.32-git9.log</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38017">38017</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html">SUSE-SA:2010:001</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers num="2.6.25" />
                <vers num="2.6.25.1" />
                <vers num="2.6.25.10" />
                <vers num="2.6.25.11" />
                <vers num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers num="2.6.25.3" />
                <vers num="2.6.25.4" />
                <vers num="2.6.25.5" />
                <vers num="2.6.25.6" />
                <vers num="2.6.25.7" />
                <vers num="2.6.25.8" />
                <vers num="2.6.25.9" />
                <vers num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.13" />
                <vers num="2.6.27.14" />
                <vers num="2.6.27.15" />
                <vers num="2.6.27.16" />
                <vers num="2.6.27.17" />
                <vers num="2.6.27.18" />
                <vers num="2.6.27.19" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.20" />
                <vers num="2.6.27.21" />
                <vers num="2.6.27.22" />
                <vers num="2.6.27.23" />
                <vers num="2.6.27.24" />
                <vers num="2.6.27.25" />
                <vers num="2.6.27.26" />
                <vers num="2.6.27.27" />
                <vers num="2.6.27.28" />
                <vers num="2.6.27.29" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.30" />
                <vers num="2.6.27.31" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.10" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers num="2.6.29" />
                <vers num="2.6.29.1" />
                <vers num="2.6.29.2" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.4" />
                <vers num="2.6.29.5" />
                <vers num="2.6.29.6" />
                <vers num="2.6.3" />
                <vers num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.3" />
                <vers num="2.6.30.4" />
                <vers num="2.6.30.5" />
                <vers num="2.6.30.6" />
                <vers num="2.6.30.7" />
                <vers num="2.6.30.8" />
                <vers num="2.6.30.9" />
                <vers edition="rc1" num="2.6.31" />
                <vers edition="rc2" num="2.6.31" />
                <vers edition="rc3" num="2.6.31" />
                <vers edition="rc4" num="2.6.31" />
                <vers edition="rc5" num="2.6.31" />
                <vers edition="rc6" num="2.6.31" />
                <vers edition="rc7" num="2.6.31" />
                <vers edition="rc8" num="2.6.31" />
                <vers num="2.6.31.1" />
                <vers num="2.6.31.2" />
                <vers num="2.6.31.3" />
                <vers num="2.6.31.4" />
                <vers num="2.6.31.5" />
                <vers num="2.6.31.6" />
                <vers edition="rc1" num="2.6.32" prev="1" />
                <vers edition="rc3" num="2.6.32" prev="1" />
                <vers edition="rc4" num="2.6.32" prev="1" />
                <vers edition="rc5" num="2.6.32" prev="1" />
                <vers edition="rc6" num="2.6.32" prev="1" />
                <vers edition="rc7" num="2.6.32" prev="1" />
                <vers edition="rc8" num="2.6.32" prev="1" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-4377" seq="2009-4377" severity="Medium" type="CVE" published="2009-12-21" CVSS_version="2.0" CVSS_score="4.3" modified="2010-02-05">
        <desc>
            <descript source="cve">The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01248.html">FEDORA-2009-13592</ref>
            <ref source="CONFIRM" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4301">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4301</ref>
            <ref source="CONFIRM" url="http://www.wireshark.org/security/wnpa-sec-2009-09.html" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-09.html</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3596" adv="1">ADV-2009-3596</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023374">1023374</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37407">37407</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1983">DSA-1983</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37916">37916</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37842" adv="1">37842</ref>
            <ref source="OSVDB" url="http://osvdb.org/61178">61178</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wireshark" name="wireshark">
                <vers num="0.9.10" />
                <vers num="0.9.14" />
                <vers num="0.9.2" />
                <vers num="0.9.5" />
                <vers num="0.9.6" />
                <vers num="0.9.7" />
                <vers num="0.9.8" />
                <vers num="0.99" />
                <vers num="0.99.0" />
                <vers num="0.99.1" />
                <vers num="0.99.2" />
                <vers num="0.99.3" />
                <vers num="0.99.4" />
                <vers num="0.99.5" />
                <vers num="0.99.6" />
                <vers num="0.99.6a" />
                <vers num="0.99.7" />
                <vers num="0.99.8" />
                <vers num="0.99.9" />
                <vers num="1.0" />
                <vers num="1.0.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.0.9" />
                <vers num="1.2" />
                <vers num="1.2.0" />
                <vers num="1.2.1" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-4463" seq="2009-4463" severity="High" type="CVE" published="2009-12-30" CVSS_version="2.0" CVSS_score="10.0" modified="2010-01-27">
        <desc>
            <descript source="cve">The firmware for Intellicom NetBiter WebSCADA uses hard-coded passwords, which makes it easier for remote attackers to obtain access.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/508449/100/0/threaded">20091214 Exposing HMS HICP Protocol + Intellicom NetBiterConfig.exe Remote Buffer Overflow (Not patched)</ref>
            <ref source="MISC" url="http://reversemode.com/index.php?option=com_content&amp;task=view&amp;id=65&amp;Itemid=1">http://reversemode.com/index.php?option=com_content&amp;task=view&amp;id=65&amp;Itemid=1</ref>
        </refs>
        <vuln_soft>
            <prod vendor="intellicom" name="netbiter_webscada_firmware">
                <vers num="3.11.0" />
                <vers num="3.11.1" />
                <vers num="3.11.2" />
                <vers num="3.12.4" />
                <vers num="3.12.6" />
                <vers edition="beta" num="3.13.0" />
                <vers num="3.13.1" />
                <vers num="3.13.2" />
                <vers num="3.20.0" />
                <vers num="3.30.0" />
                <vers num="3.30.1" />
                <vers edition="b184" num="3.30.2" />
            </prod>
            <prod vendor="intellicom" name="netbiter_webscada_ws100">
                <vers num="" />
            </prod>
            <prod vendor="intellicom" name="netbiter_webscada_ws200">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-4484" seq="2009-4484" severity="High" type="CVE" published="2009-12-30" CVSS_version="2.0" CVSS_score="7.5" modified="2010-02-05">
        <desc>
            <descript source="cve">Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=555313">https://bugzilla.redhat.com/show_bug.cgi?id=555313</ref>
            <ref source="CONFIRM" url="http://yassl.cvs.sourceforge.net/viewvc/yassl/yassl/taocrypt/src/asn.cpp?r1=1.13&amp;r2=1.14">http://yassl.cvs.sourceforge.net/viewvc/yassl/yassl/taocrypt/src/asn.cpp?r1=1.13&amp;r2=1.14</ref>
            <ref source="CONFIRM" url="http://www.yassl.com/release.html">http://www.yassl.com/release.html</ref>
            <ref source="CONFIRM" url="http://www.yassl.com/news.html#yassl199">http://www.yassl.com/news.html#yassl199</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0236">ADV-2010-0236</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0233">ADV-2010-0233</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37974">37974</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37943">37943</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37640">37640</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/61956">61956</ref>
            <ref source="MISC" url="http://www.metasploit.com/modules/exploit/linux/mysql/mysql_yassl_getname">http://www.metasploit.com/modules/exploit/linux/mysql/mysql_yassl_getname</ref>
            <ref source="MISC" url="http://www.intevydis.com/blog/?p=57">http://www.intevydis.com/blog/?p=57</ref>
            <ref source="MISC" url="http://www.intevydis.com/blog/?p=106">http://www.intevydis.com/blog/?p=106</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023513">1023513</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023402">1023402</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38364">38364</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38344">38344</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37493">37493</ref>
            <ref source="MLIST" url="http://lists.mysql.com/commits/96697">[commits] 20100113 bzr commit into mysql-5.0-bugteam branch (ramil:2838) Bug#50227</ref>
            <ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2010-January/006020.html">[dailydave] 20100126 New db bugs</ref>
            <ref source="MISC" url="http://isc.sans.org/diary.html?storyid=7900">http://isc.sans.org/diary.html?storyid=7900</ref>
            <ref source="MISC" url="http://intevydis.com/mysql_overflow1.py.txt">http://intevydis.com/mysql_overflow1.py.txt</ref>
            <ref source="MISC" url="http://intevydis.com/mysql_demo.html">http://intevydis.com/mysql_demo.html</ref>
            <ref source="MISC" url="http://intevydis.blogspot.com/2010/01/mysq-yassl-stack-overflow.html">http://intevydis.blogspot.com/2010/01/mysq-yassl-stack-overflow.html</ref>
            <ref source="CONFIRM" url="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-43.html">http://dev.mysql.com/doc/refman/5.1/en/news-5-1-43.html</ref>
            <ref source="CONFIRM" url="http://dev.mysql.com/doc/refman/5.0/en/news-5-0-90.html">http://dev.mysql.com/doc/refman/5.0/en/news-5-0-90.html</ref>
            <ref source="CONFIRM" url="http://bugs.mysql.com/bug.php?id=50227">http://bugs.mysql.com/bug.php?id=50227</ref>
            <ref source="CONFIRM" url="http://bazaar.launchpad.net/~mysql/mysql-server/mysql-5.0/revision/2837.1.1">http://bazaar.launchpad.net/~mysql/mysql-server/mysql-5.0/revision/2837.1.1</ref>
            <ref source="MLIST" url="http://archives.neohapsis.com/archives/dailydave/2010-q1/0002.html">[dailydave] 20100106 0day demos</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mysql" name="mysql">
                <vers num="5.0.51a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-4499" seq="2009-4499" severity="High" type="CVE" published="2009-12-31" CVSS_version="2.0" CVSS_score="7.5" modified="2010-02-02">
        <desc>
            <descript source="cve">SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to execute arbitrary SQL commands via a crafted request, possibly related to the send_history_last_id function in zabbix_server/trapper/nodehistory.c.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://support.zabbix.com/browse/ZBX-1031" adv="1">https://support.zabbix.com/browse/ZBX-1031</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3514" adv="1">ADV-2009-3514</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/508436/30/60/threaded">20091213 Zabbix Server : Multiple remote vulnerabilities</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37740" adv="1">37740</ref>
        </refs>
        <vuln_soft>
            <prod vendor="zabbix" name="zabbix">
                <vers num="1.1.2" />
                <vers num="1.1.3" />
                <vers num="1.1.4" />
                <vers num="1.1.5" />
                <vers num="1.4.2" />
                <vers num="1.4.3" />
                <vers num="1.4.4" />
                <vers num="1.4.6" />
                <vers num="1.6.6" />
                <vers num="1.6.7" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2010-0158" seq="2010-0158" severity="High" type="CVE" published="2010-01-06" CVSS_version="2.0" CVSS_score="7.5" modified="2010-02-05">
        <desc>
            <descript source="cve">** DISPUTED **  SQL injection vulnerability in the JoomlaBamboo (JB) Simpla Admin template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to the com_content component, reachable through index.php.  NOTE: the vendor disputes this report, saying: "JoomlaBamboo has investigated this report, and it is incorrect.  There is no SQL injection vulnerability involving the id parameter in an article view, and there never was. JoomlaBamboo customers have no reason to be concerned about this report."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2010/0014" adv="1">ADV-2010-0014</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37579">37579</ref>
            <ref source="MISC" url="http://www.exploit-db.com/exploits/10971">http://www.exploit-db.com/exploits/10971</ref>
            <ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2010-February/002320.html">[VIM] 20100203 Re: disputed: CVE-2010-0158 JoomlaBamboo (JB) Simpla Admin SQL injection</ref>
            <ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2010-February/002319.html">[VIM] 20100203 disputed: CVE-2010-0158 JoomlaBamboo (JB) Simpla Admin SQL injection</ref>
            <ref source="MISC" url="http://packetstormsecurity.org/1001-exploits/joomlabamboo-sql.txt">http://packetstormsecurity.org/1001-exploits/joomlabamboo-sql.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="joomlabamboo" name="jb_simpla">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2010-0012" seq="2010-0012" severity="Medium" type="CVE" published="2010-01-08" CVSS_version="2.0" CVSS_score="6.8" modified="2010-02-02">
        <desc>
            <descript source="cve">Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://launchpad.net/bugs/500625">https://launchpad.net/bugs/500625</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2010/01/06/4">[oss-security] 20100106 Re: CVE Request: Transmission</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2010/01/06/2">[oss-security] 20100106 CVE Request: Transmission</ref>
            <ref source="MLIST" url="http://www.mail-archive.com/debian-devel-changes@lists.debian.org/msg264483.html">[debian-devel-changes] 20100105 Accepted transmission 1.77-1 (source all amd64)</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2010/dsa-1967">DSA-1967</ref>
            <ref source="CONFIRM" url="http://trac.transmissionbt.com/wiki/Changes#version-1.77">http://trac.transmissionbt.com/wiki/Changes#version-1.77</ref>
            <ref source="CONFIRM" url="http://trac.transmissionbt.com/changeset/9829/">http://trac.transmissionbt.com/changeset/9829/</ref>
            <ref source="CONFIRM" url="http://security.debian.org/pool/updates/main/t/transmission/transmission_1.22-1+lenny2.diff.gz">http://security.debian.org/pool/updates/main/t/transmission/transmission_1.22-1+lenny2.diff.gz</ref>
            <ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html">SUSE-SA:2010:008</ref>
        </refs>
        <vuln_soft>
            <prod vendor="transmissionbt" name="transmission">
                <vers num="1.22" />
                <vers num="1.34" />
                <vers num="1.75" />
                <vers num="1.76" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" name="CVE-2009-4536" seq="2009-4536" severity="High" type="CVE" published="2010-01-12" CVSS_version="2.0" CVSS_score="7.8" modified="2010-01-28">
        <desc>
            <descript source="cve">drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which allows remote attackers to bypass packet filters via a large packet with a crafted payload.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1385.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=552126">https://bugzilla.redhat.com/show_bug.cgi?id=552126</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37519">37519</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2010-0041.html">RHSA-2010:0041</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2010-0020.html">RHSA-2010:0020</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2010-0019.html">RHSA-2010:0019</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/12/31/1">[oss-security] 20091231 Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/12/29/2">[oss-security] 20091229 Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/12/28/1">[oss-security] 20091228 CVE requests - kernel security regressions for CVE-2009-1385/and -1389</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023420">1023420</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38031" adv="1">38031</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35265" adv="1">35265</ref>
            <ref source="CONFIRM" url="http://marc.info/?t=126203102000001&amp;r=1&amp;w=2">http://marc.info/?t=126203102000001&amp;r=1&amp;w=2</ref>
            <ref source="MISC" url="http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html">http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html</ref>
            <ref source="MISC" url="http://blog.c22.cc/2009/12/27/26c3-cat-procsysnetipv4fuckups/">http://blog.c22.cc/2009/12/27/26c3-cat-procsysnetipv4fuckups/</ref>
        </refs>
        <vuln_soft>
            <prod vendor="intel" name="e1000">
                <vers num="5.2.22" />
                <vers num="5.2.30.1" />
                <vers num="5.2.52" />
                <vers num="5.3.19" />
                <vers num="5.4.11" />
                <vers num="5.5.4" />
                <vers num="5.6.10" />
                <vers num="5.6.10.1" />
                <vers num="5.7.6" />
                <vers num="6.0.54" />
                <vers num="6.0.60" />
                <vers num="6.1.16" />
                <vers num="6.2.15" />
                <vers num="6.3.9" />
                <vers num="7.0.33" />
                <vers num="7.0.41" />
                <vers num="7.1.9" />
                <vers num="7.2.7" />
                <vers num="7.2.9" />
                <vers num="7.3.15" />
                <vers num="7.3.20" />
                <vers num="7.4.27" />
                <vers num="7.4.35" prev="1" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.24.7" />
                <vers num="2.6.25.15" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.6" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.22_rc1" />
                <vers num="2.6.22_rc7" />
                <vers num="2.6.23" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers num="2.6.23_rc1" />
                <vers num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24_rc1" />
                <vers num="2.6.24_rc4" />
                <vers num="2.6.24_rc5" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.27" />
                <vers num="2.6.28" prev="1" />
                <vers edition="git1" num="2.6.29" />
                <vers edition="rc1" num="2.6.29" />
                <vers edition="rc2" num="2.6.29" />
                <vers edition="rc2_git7" num="2.6.29" />
                <vers edition="rc8-kk" num="2.6.29" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.rc1" />
                <vers num="2.6.29.rc2-git1" />
                <vers edition="rc1" num="2.6.30" prev="1" />
                <vers edition="rc2" num="2.6.30" prev="1" />
                <vers edition="rc3" num="2.6.30" prev="1" />
                <vers edition="rc7-git6" num="2.6.30" prev="1" />
                <vers edition="git-6" num="2.6.32" />
                <vers edition="rc1" num="2.6.32" />
                <vers edition="rc3" num="2.6.32" />
                <vers edition="rc4" num="2.6.32" />
                <vers edition="rc5" num="2.6.32" />
                <vers edition="rc6" num="2.6.32" />
                <vers edition="rc7" num="2.6.32" />
                <vers edition="rc8" num="2.6.32" />
                <vers num="2.6.32.1" />
                <vers num="2.6.32.2" />
                <vers num="2.6.32.3" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" name="CVE-2009-4537" seq="2009-4537" severity="High" type="CVE" published="2010-01-12" CVSS_version="2.0" CVSS_score="7.8" modified="2010-01-28">
        <desc>
            <descript source="cve">drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=550907">https://bugzilla.redhat.com/show_bug.cgi?id=550907</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/37521">37521</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2010-0041.html">RHSA-2010:0041</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2010-0020.html">RHSA-2010:0020</ref>
            <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2010-0019.html">RHSA-2010:0019</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/12/31/1">[oss-security] 20091231 Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/12/29/2">[oss-security] 20091229 Re: CVE requests - kernel security regressions for CVE-2009-1385/and -1389</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/12/28/1">[oss-security] 20091228 CVE requests - kernel security regressions for CVE-2009-1385/and -1389</ref>
            <ref source="MISC" url="http://twitter.com/dakami/statuses/7104238406">http://twitter.com/dakami/statuses/7104238406</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023419">1023419</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/38031" adv="1">38031</ref>
            <ref source="CONFIRM" url="http://marc.info/?t=126202986900002&amp;r=1&amp;w=2">http://marc.info/?t=126202986900002&amp;r=1&amp;w=2</ref>
            <ref source="MLIST" url="http://marc.info/?l=linux-netdev&amp;m=126202972828626&amp;w=2">[linux-netdev] 20091228 [PATCH RFC] r8169: straighten out overlength frame detection</ref>
            <ref source="MISC" url="http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html">http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html</ref>
            <ref source="MISC" url="http://blog.c22.cc/2009/12/27/26c3-cat-procsysnetipv4fuckups/">http://blog.c22.cc/2009/12/27/26c3-cat-procsysnetipv4fuckups/</ref>
        </refs>
        <vuln_soft>
            <prod vendor="intel" name="e1000">
                <vers num="5.2.22" />
                <vers num="5.2.30.1" />
                <vers num="5.2.52" />
                <vers num="5.3.19" />
                <vers num="5.4.11" />
                <vers num="5.5.4" />
                <vers num="5.6.10" />
                <vers num="5.6.10.1" />
                <vers num="5.7.6" />
                <vers num="6.0.54" />
                <vers num="6.0.60" />
                <vers num="6.1.16" />
                <vers num="6.2.15" />
                <vers num="6.3.9" />
                <vers num="7.0.33" />
                <vers num="7.0.41" />
                <vers num="7.1.9" />
                <vers num="7.2.7" />
                <vers num="7.2.9" />
                <vers num="7.3.15" />
                <vers num="7.3.20" />
                <vers num="7.4.27" />
                <vers num="7.4.35" prev="1" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.24.7" />
                <vers num="2.6.25.15" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.6" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers num="2.6.22_rc1" />
                <vers num="2.6.22_rc7" />
                <vers num="2.6.23" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers num="2.6.23_rc1" />
                <vers num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24_rc1" />
                <vers num="2.6.24_rc4" />
                <vers num="2.6.24_rc5" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.27" />
                <vers num="2.6.28" prev="1" />
                <vers edition="git1" num="2.6.29" />
                <vers edition="rc1" num="2.6.29" />
                <vers edition="rc2" num="2.6.29" />
                <vers edition="rc2_git7" num="2.6.29" />
                <vers edition="rc8-kk" num="2.6.29" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.rc1" />
                <vers num="2.6.29.rc2-git1" />
                <vers edition="rc1" num="2.6.30" prev="1" />
                <vers edition="rc2" num="2.6.30" prev="1" />
                <vers edition="rc3" num="2.6.30" prev="1" 