<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2013-06-19" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="Medium" seq="2012-6564" published="2013-06-17" name="CVE-2012-6564" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in REDCap before 4.14.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers prev="1" num="4.14.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2012-6565" published="2013-06-17" name="CVE-2012-6565" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in REDCap before 4.14.3 allows remote authenticated users to inject arbitrary web script or HTML via uppercase characters in JavaScript events within user-defined labels.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers prev="1" num="4.14.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-6566" published="2013-06-17" name="CVE-2012-6566" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in REDCap before 4.14.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.14.0"/>
        <vers prev="1" num="4.14.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2012-6567" published="2013-06-17" name="CVE-2012-6567" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">REDCap before 4.14.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the logic of a custom rule.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers prev="1" num="4.13.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-0148" published="2013-06-16" name="CVE-2013-0148" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The Data Camouflage (aka Faircom Standard Encryption) algorithm in Faircom c-treeACE does not ensure that a decryption key is needed for accessing database contents, which allows context-dependent attackers to read cleartext database records by copying a database to another system that has a certain default configuration.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/900031" source="CERT-VN">VU#900031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="faircom" name="c-treeace">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-0484" published="2013-06-19" name="CVE-2013-0484" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The server process in IBM Cognos TM1 10.1.x before 10.1.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via an undocumented API call that triggers the transmission of unexpected data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/81612" source="XF">tm1-undocumented-api(81612)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21637655" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21637655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="cognos_tm1">
        <vers num="10.1.0"/>
        <vers num="10.1.0.1"/>
        <vers num="10.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1093" published="2013-06-17" name="CVE-2013-1093" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the directToPage parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012499" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012499</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012025" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="zenworks_configuration_management">
        <vers num="11.2"/>
        <vers num="11.2.1"/>
        <vers num="11.2.2"/>
        <vers num="11.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1094" published="2013-06-17" name="CVE-2013-1094" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in a ZCC page in zenworks-core in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via an invalid locale.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012501" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012501</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012025" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="zenworks_configuration_management">
        <vers num="11.2"/>
        <vers num="11.2.1"/>
        <vers num="11.2.2"/>
        <vers num="11.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1095" published="2013-06-17" name="CVE-2013-1095" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError event.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012500" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012500</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012025" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="zenworks_configuration_management">
        <vers num="11.2"/>
        <vers num="11.2.1"/>
        <vers num="11.2.2"/>
        <vers num="11.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1097" published="2013-06-17" name="CVE-2013-1097" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onload event.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012502" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012502</ref>
      <ref url="http://www.novell.com/support/kb/doc.php?id=7012025" source="CONFIRM" adv="1">http://www.novell.com/support/kb/doc.php?id=7012025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="zenworks_configuration_management">
        <vers num="11.2"/>
        <vers num="11.2.1"/>
        <vers num="11.2.2"/>
        <vers num="11.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1203" published="2013-06-18" name="CVE-2013-1203" modified="2013-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:C)" CVSS_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">Cisco ASA CX Context-Aware Security Software allows remote attackers to cause a denial of service (device reload) via crafted TCP packets that appear to have been forwarded by a Cisco Adaptive Security Appliances (ASA) device, aka Bug ID CSCue88386.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1203" source="CISCO">20130617 Cisco ASA CX TCP Traffic Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_cx_context-aware_security_software">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-1331" published="2013-06-11" name="CVE-2013-1331" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-051" source="MS" patch="1" adv="1">MS13-051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp3"/>
        <vers num="2011" edition=""/>
        <vers num="2011" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-1339" published="2013-06-11" name="CVE-2013-1339" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-050" source="MS" patch="1" adv="1">MS13-050</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x86"/>
        <vers num="-" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_8">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="-:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_rt">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2012">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2013-1355" reject="1" published="2013-06-13" name="CVE-2013-1355" modified="2013-06-13">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: The CNA or individual who requested this candidate subsequently withdrew it.  Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-1500" published="2013-06-18" name="CVE-2013-1500" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows local users to affect confidentiality and integrity via unknown vectors related to 2D.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This issue cannot be exploited through sandboxed Java Web Start applications and sandboxed Java applets. Local access is required to leverage this issue.'</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1571" published="2013-06-18" name="CVE-2013-1571" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, and JavaFX 2.2.21 and earlier allows remote attackers to affect integrity via unknown vectors related to Javadoc.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to the Javadoc tool and documentation generated by the tool. This vulnerability can be exploited only through Javadoc output hosted on a web server. This addresses CERT/CC VU#225657.'</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="javafx">
        <vers num="2.0"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers prev="1" num="2.2.21"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.7"/>
      </prod>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1981" published="2013-06-15" name="CVE-2013-1981" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XQueryFont, (2) _XF86BigfontQueryFont, (3) XListFontsWithInfo, (4) XGetMotionEvents, (5) XListHosts, (6) XGetModifierMapping, (7) XGetPointerMapping, (8) XGetKeyboardMapping, (9) XGetWindowProperty, (10) XGetImage, (11) LoadColornameDB, (12) XrmGetFileDatabase, (13) _XimParseStringFile, or (14) TransFileName functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libx11">
        <vers num="1.5.0"/>
        <vers prev="1" num="1.5.99.901"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1982" published="2013-06-15" name="CVE-2013-1982" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXext 1.3.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XcupGetReservedColormapEntries, (2) XcupStoreColors, (3) XdbeGetVisualInfo, (4) XeviGetVisualInfo, (5) XShapeGetRectangles, and (6) XSyncListSystemCounters functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" patch="1" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxext">
        <vers num="1.0.99.2"/>
        <vers num="1.0.99.3"/>
        <vers num="1.0.99.4"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.3.0"/>
        <vers prev="1" num="1.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1983" published="2013-06-15" name="CVE-2013-1983" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in X.org libXfixes 5.0 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XFixesGetCursorImage function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxfixes">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers prev="1" num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1984" published="2013-06-15" name="CVE-2013-1984" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXi 1.7.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XGetDeviceControl, (2) XGetFeedbackControl, (3) XGetDeviceDontPropagateList, (4) XGetDeviceMotionEvents, (5) XIGetProperty, (6) XIGetSelectedEvents, (7) XGetDeviceProperties, and (8) XListInputDevices functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxi">
        <vers num="1.5.0"/>
        <vers num="1.5.99.2"/>
        <vers num="1.5.99.3"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.99.1"/>
        <vers num="1.7"/>
        <vers prev="1" num="1.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1985" published="2013-06-15" name="CVE-2013-1985" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in X.org libXinerama 1.1.2 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XineramaQueryScreens function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxinerama">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.99.1"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers prev="1" num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1986" published="2013-06-15" name="CVE-2013-1986" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXrandr 1.4.0 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRRQueryOutputProperty and (2) XRRQueryProviderProperty functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxrandr">
        <vers num="1.2.3"/>
        <vers num="1.2.99.1"/>
        <vers num="1.2.99.2"/>
        <vers num="1.2.99.3"/>
        <vers num="1.2.99.4"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers prev="1" num="1.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1987" published="2013-06-15" name="CVE-2013-1987" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRender QueryFilters, (2) XRenderQueryFormats, and (3) XRenderQueryPictIndexValues functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxrender">
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers prev="1" num="0.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1988" published="2013-06-15" name="CVE-2013-1988" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXRes 1.0.6 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XResQueryClients and (2) XResQueryClientResources functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxres">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers prev="1" num="1.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1989" published="2013-06-15" name="CVE-2013-1989" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXv 1.0.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XvQueryPortAttributes, (2) XvListImageFormats, and (3) XvCreateImage function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxv">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers prev="1" num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1990" published="2013-06-15" name="CVE-2013-1990" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXvMC 1.0.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XvMCListSurfaceTypes and (2) XvMCListSubpictureTypes functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxvmc">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers prev="1" num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1991" published="2013-06-15" name="CVE-2013-1991" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXxf86dga 1.1.3 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XDGAQueryModes and (2) XDGASetMode functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxxf86dga">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.99.1"/>
        <vers num="1.0.99.2"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers prev="1" num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1992" published="2013-06-15" name="CVE-2013-1992" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libdmx 1.1.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) DMXGetScreenAttributes, (2) DMXGetWindowAttributes, and (3) DMXGetInputAttributes functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libdmx">
        <vers num="1.0.2"/>
        <vers num="1.0.99.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers prev="1" num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1993" published="2013-06-15" name="CVE-2013-1993" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mesa3d.org" name="mesa">
        <vers num="9.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.1"/>
        <vers prev="1" num="9.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1994" published="2013-06-15" name="CVE-2013-1994" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libchromeXvMC and libchromeXvMCPro in openChrome 0.3.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) uniDRIOpenConnection and (2) uniDRIGetClientDriverName functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openchrome" name="openchrome">
        <vers prev="1" num="0.3.2"/>
      </prod>
      <prod vendor="x" name="libchromexvmc">
        <vers num="-"/>
      </prod>
      <prod vendor="x" name="libchromexvmcpro">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1995" published="2013-06-15" name="CVE-2013-1995" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">X.org libXi 1.7.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the XListInputDevices function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxi">
        <vers num="1.5.0"/>
        <vers num="1.5.99.2"/>
        <vers num="1.5.99.3"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.99.1"/>
        <vers num="1.7"/>
        <vers prev="1" num="1.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1996" published="2013-06-15" name="CVE-2013-1996" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">X.org libFS 1.0.4 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the FSOpenServer function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libfs">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers prev="1" num="1.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1997" published="2013-06-15" name="CVE-2013-1997" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XAllocColorCells, (2) _XkbReadGetDeviceInfoReply, (3) _XkbReadGeomShapes, (4) _XkbReadGetGeometryReply, (5) _XkbReadKeySyms, (6) _XkbReadKeyActions, (7) _XkbReadKeyBehaviors, (8) _XkbReadModifierMap, (9) _XkbReadExplicitComponents, (10) _XkbReadVirtualModMap, (11) _XkbReadGetNamesReply, (12) _XkbReadGetMapReply, (13) _XimXGetReadData, (14) XListFonts, (15) XListExtensions, and (16) XGetFontPath functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libx11">
        <vers num="1.5.0"/>
        <vers prev="1" num="1.5.99.901"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1998" published="2013-06-15" name="CVE-2013-1998" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (2) XIPassiveGrabDevice, and (3) XQueryDeviceState functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxi">
        <vers num="1.5.0"/>
        <vers num="1.5.99.2"/>
        <vers num="1.5.99.3"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.99.1"/>
        <vers num="1.7"/>
        <vers prev="1" num="1.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-1999" published="2013-06-15" name="CVE-2013-1999" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in X.org libXvMC 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvMCGetDRInfo function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxvmc">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers prev="1" num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2000" published="2013-06-15" name="CVE-2013-2000" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in X.org libXxf86dga 1.1.3 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XDGAQueryModes and (2) XDGASetMode functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxxf86dga">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.99.1"/>
        <vers num="1.0.99.2"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers prev="1" num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2001" published="2013-06-15" name="CVE-2013-2001" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in X.org libXxf86vm 1.1.2 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XF86VidModeGetGammaRamp function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxxf86vm">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.99.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers prev="1" num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2002" published="2013-06-15" name="CVE-2013-2002" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in X.org libXt 1.1.3 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the _XtResourceConfigurationEH function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxt">
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers prev="1" num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2003" published="2013-06-15" name="CVE-2013-2003" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in X.org libXcursor 1.1.13 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the _XcursorFileHeaderCreate function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxcursor">
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers prev="1" num="1.1.13"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2004" published="2013-06-15" name="CVE-2013-2004" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The (1) GetDatabase and (2) _XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier do not restrict the recursion depth when processing directives to include files, which allows X servers to cause a denial of service (stack consumption) via a crafted file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libx11">
        <vers num="1.5.0"/>
        <vers prev="1" num="1.5.99.901"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2005" published="2013-06-15" name="CVE-2013-2005" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxt">
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers prev="1" num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2062" published="2013-06-15" name="CVE-2013-2062" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in X.org libXp 1.0.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XpGetAttributes, (2) XpGetOneAttribute, (3) XpGetPrinterList, and (4) XpQueryScreens functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxp">
        <vers num="1.0.0"/>
        <vers prev="1" num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2063" published="2013-06-15" name="CVE-2013-2063" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in X.org libXtst 1.2.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XRecordGetContext function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxtst">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.99.1"/>
        <vers num="1.0.99.2"/>
        <vers num="1.1.0"/>
        <vers num="1.2.0"/>
        <vers prev="1" num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2064" published="2013-06-15" name="CVE-2013-2064" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxcb">
        <vers num="1.1.90.1"/>
        <vers num="1.1.91"/>
        <vers num="1.1.92"/>
        <vers num="1.1.93"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.8.1"/>
        <vers prev="1" num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2066" published="2013-06-15" name="CVE-2013-2066" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in X.org libXv 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvQueryPortAttributes function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.x.org/wiki/Development/Security/Advisory-2013-05-23" source="CONFIRM" adv="1">http://www.x.org/wiki/Development/Security/Advisory-2013-05-23</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2013/05/23/3" source="MLIST">[oss-security] 20130523 Fwd: [ANNOUNCE] X.Org Security Advisory: Protocol handling issues  in X Window System client libraries</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="libxv">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers prev="1" num="1.0.7"/>
      </prod>
      <prod vendor="x.org" name="libxv">
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2309" published="2013-06-16" name="CVE-2013-2309" modified="2013-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the management screen in OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before 3.8.5.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the "mobile version color scheme."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.openpne.jp/archives/11096/" source="CONFIRM" patch="1" adv="1">http://www.openpne.jp/archives/11096/</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000038" source="JVNDB">JVNDB-2013-000038</ref>
      <ref url="http://jvn.jp/en/jp/JVN18501376/index.html" source="JVN">JVN#18501376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tejimaya" name="openpne">
        <vers num="3.4" edition="rc1"/>
        <vers num="3.4.0"/>
        <vers num="3.4.0.1"/>
        <vers num="3.4.1"/>
        <vers num="3.4.1.1"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.11.1"/>
        <vers num="3.4.12"/>
        <vers num="3.4.12.1"/>
        <vers num="3.4.13"/>
        <vers num="3.4.14"/>
        <vers num="3.4.14.1"/>
        <vers num="3.4.15"/>
        <vers num="3.4.15.1"/>
        <vers num="3.4.16"/>
        <vers num="3.4.17"/>
        <vers num="3.4.18"/>
        <vers num="3.4.19"/>
        <vers num="3.4.2"/>
        <vers num="3.4.21"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.4.1"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.6.1"/>
        <vers num="3.4.6.2"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.4.9.1"/>
        <vers num="3.4.9.2"/>
        <vers num="3.4b"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.8.0"/>
        <vers num="3.8.1"/>
        <vers num="3.8.2"/>
        <vers num="3.8.3"/>
        <vers num="3.8.4"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-2310" published="2013-06-16" name="CVE-2013-2310" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">SoftBank Wi-Fi Spot Configuration Software, as used on SoftBank SHARP 3G handsets, SoftBank Panasonic 3G handsets, SoftBank NEC 3G handsets, SoftBank Samsung 3G handsets, SoftBank mobile Wi-Fi routers, SoftBank Android smartphones with the Wi-Fi application before 1.7.1, SoftBank Windows Mobile smartphones with the WISPrClient application before 1.3.1, SoftBank Disney Mobile Android smartphones with the Wi-Fi application before 1.7.1, and WILLCOM Android smartphones with the Wi-Fi application before 1.7.1, does not properly connect to access points, which allows remote attackers to obtain sensitive information by leveraging access to an 802.11 network.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000039" source="JVNDB">JVNDB-2013-000039</ref>
      <ref url="http://jvn.jp/en/jp/JVN85371480/index.html" source="JVN">JVN#85371480</ref>
      <ref url="http://jvn.jp/en/jp/JVN85371480/995417/index.html" source="CONFIRM">http://jvn.jp/en/jp/JVN85371480/995417/index.html</ref>
      <ref url="http://jvn.jp/en/jp/JVN85371480/995319/index.html" source="CONFIRM">http://jvn.jp/en/jp/JVN85371480/995319/index.html</ref>
      <ref url="http://jvn.jp/en/jp/JVN85371480/397327/index.html" source="CONFIRM">http://jvn.jp/en/jp/JVN85371480/397327/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softbank" name="wi-fi_application">
        <vers prev="1" num="1.7.0"/>
      </prod>
      <prod vendor="softbank" name="wi-fi_spot_configuration_software">
        <vers num="-"/>
      </prod>
      <prod vendor="softbank" name="wisprclient">
        <vers prev="1" num="1.3.0"/>
      </prod>
      <prod vendor="willcom-inc" name="wi-fi_application">
        <vers prev="1" num="1.7.0"/>
      </prod>
      <prod vendor="softbank" name="android_smartphone">
        <vers num="001dl"/>
        <vers num="001ht"/>
        <vers num="003p"/>
        <vers num="003sh"/>
        <vers num="003z"/>
        <vers num="005sh"/>
        <vers num="006sh"/>
        <vers num="007hw"/>
        <vers num="007sh" edition="j"/>
        <vers num="007sh" edition="kt"/>
        <vers num="008z"/>
        <vers num="009sh" edition="y"/>
        <vers num="009z"/>
        <vers num="101dl"/>
        <vers num="101f"/>
        <vers num="101k"/>
        <vers num="101n"/>
        <vers num="101p"/>
        <vers num="101sh"/>
        <vers num="102p"/>
        <vers num="102sh" edition="ii"/>
        <vers num="103sh"/>
        <vers num="104sh"/>
        <vers num="106sh"/>
        <vers num="107sh"/>
        <vers num="200sh"/>
        <vers num="201hw"/>
        <vers num="201k"/>
        <vers num="201m"/>
        <vers num="x06ht" edition="ii"/>
      </prod>
      <prod vendor="softbank" name="disney_mobile_android_smartphone">
        <vers num="dm009sh"/>
        <vers num="dm010sh"/>
        <vers num="dm011sh"/>
        <vers num="dm012sh"/>
        <vers num="dm013sh"/>
      </prod>
      <prod vendor="softbank" name="mobile_wi-fi_router">
        <vers num="101sb"/>
        <vers num="102hw"/>
        <vers num="102z"/>
      </prod>
      <prod vendor="softbank" name="nec_3g_handset">
        <vers num="001n"/>
        <vers num="931n"/>
        <vers num="940n"/>
      </prod>
      <prod vendor="softbank" name="panasonic_3g_handset">
        <vers num="001p"/>
        <vers num="941p"/>
        <vers num="942p"/>
      </prod>
      <prod vendor="softbank" name="samsung_3g_handset">
        <vers num="941sc"/>
      </prod>
      <prod vendor="softbank" name="sharp_3g_handset">
        <vers num="001n"/>
        <vers num="001p"/>
        <vers num="002sh"/>
        <vers num="004sh"/>
        <vers num="004shp3"/>
        <vers num="931n"/>
        <vers num="940n"/>
        <vers num="940sh"/>
        <vers num="941p"/>
        <vers num="941sc"/>
        <vers num="941sh"/>
        <vers num="942p"/>
        <vers num="943sh"/>
        <vers num="944sh"/>
        <vers num="945sh"/>
        <vers num="945shg"/>
      </prod>
      <prod vendor="softbank" name="windows_mobile_smartphone">
        <vers num="x01sc"/>
        <vers num="x02t"/>
        <vers num="x04ht"/>
        <vers num="x05ht"/>
      </prod>
      <prod vendor="willcom-inc" name="android_smartphone">
        <vers num="wx04k"/>
        <vers num="wx06k"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2336" published="2013-06-14" name="CVE-2013-2336" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HP Service Manager 7.11, 9.21, 9.30, and 9.31, and ServiceCenter 6.2.8, allows remote attackers to obtain sensitive information via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03784101" source="HP" adv="1">HPSBMU02884</ref>
      <ref url="http://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03784101" source="HP" adv="1">SSRT101207</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="service_center">
        <vers num="6.2.8"/>
      </prod>
      <prod vendor="hp" name="service_manager">
        <vers num="7.11"/>
        <vers num="9.21"/>
      </prod>
      <prod vendor="hp" name="service_manager">
        <vers num="9.30"/>
        <vers num="9.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2337" published="2013-06-14" name="CVE-2013-2337" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HP Service Manager 7.11, 9.21, 9.30, and 9.31, and ServiceCenter 6.2.8, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03784101" source="HP" adv="1">HPSBMU02884</ref>
      <ref url="http://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03784101" source="HP" adv="1">SSRT101208</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="service_center">
        <vers num="6.2.8"/>
      </prod>
      <prod vendor="hp" name="service_manager">
        <vers num="7.11"/>
        <vers num="9.21"/>
      </prod>
      <prod vendor="hp" name="service_manager">
        <vers num="9.30"/>
        <vers num="9.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2338" published="2013-06-14" name="CVE-2013-2338" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability on HP Integrated Lights-Out 3 (aka iLO3) cards with firmware before 1.57 and 4 (aka iLO4) cards with firmware before 1.22, when Single-Sign-On (SSO) is used, allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03787836" source="HP" adv="1">HPSBHF02885</ref>
      <ref url="https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03787836" source="HP" adv="1">SSRT101180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="integrated_lights-out_3_firmware">
        <vers num="1.00"/>
        <vers num="1.05"/>
        <vers num="1.20"/>
        <vers num="1.26"/>
        <vers num="1.28"/>
        <vers num="1.50"/>
        <vers prev="1" num="1.55"/>
      </prod>
      <prod vendor="hp" name="integrated_lights-out_4_firmware">
        <vers num="1.11"/>
        <vers num="1.13"/>
        <vers prev="1" num="1.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2400" published="2013-06-18" name="CVE-2013-2400" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-3744.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2407" published="2013-06-18" name="CVE-2013-2407" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality and availability via unknown vectors related to Libraries.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2412" published="2013-06-18" name="CVE-2013-2412" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Serviceability.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2437" published="2013-06-18" name="CVE-2013-2437" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Deployment.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2442" published="2013-06-18" name="CVE-2013-2442" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2466 and CVE-2013-2468.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2443" published="2013-06-18" name="CVE-2013-2443" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2452 and CVE-2013-2455.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2444" published="2013-06-18" name="CVE-2013-2444" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, and JavaFX 2.2.21 and earlier allows remote attackers to affect availability via vectors related to AWT.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="javafx">
        <vers num="2.0"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers prev="1" num="2.2.21"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.7"/>
      </prod>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2445" published="2013-06-18" name="CVE-2013-2445" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect availability via unknown vectors related to Hotspot.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2446" published="2013-06-18" name="CVE-2013-2446" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via vectors related to CORBA.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2447" published="2013-06-18" name="CVE-2013-2447" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Networking.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2448" published="2013-06-18" name="CVE-2013-2448" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2449" published="2013-06-18" name="CVE-2013-2449" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2450" published="2013-06-18" name="CVE-2013-2450" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect availability via unknown vectors related to Serialization.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2013-2451" published="2013-06-18" name="CVE-2013-2451" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html


'Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2452" published="2013-06-18" name="CVE-2013-2452" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2443 and CVE-2013-2455.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2453" published="2013-06-18" name="CVE-2013-2453" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect integrity via vectors related to JMX.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2454" published="2013-06-18" name="CVE-2013-2454" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality and integrity via vectors related to JDBC.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2455" published="2013-06-18" name="CVE-2013-2455" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2443 and CVE-2013-2452.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2456" published="2013-06-18" name="CVE-2013-2456" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Serialization.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2457" published="2013-06-18" name="CVE-2013-2457" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect integrity via vectors related to JMX.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.'</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2458" published="2013-06-18" name="CVE-2013-2458" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2459" published="2013-06-18" name="CVE-2013-2459" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2460" published="2013-06-18" name="CVE-2013-2460" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2461" published="2013-06-18" name="CVE-2013-2461" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2462" published="2013-06-18" name="CVE-2013-2462" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2463" published="2013-06-18" name="CVE-2013-2463" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2464" published="2013-06-18" name="CVE-2013-2464" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2465" published="2013-06-18" name="CVE-2013-2465" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2466" published="2013-06-18" name="CVE-2013-2466" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2442 and CVE-2013-2468.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2467" published="2013-06-18" name="CVE-2013-2467" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 5.0 Update 45 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Java installer.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to the Java installer only. This issue cannot be exploited through sandboxed Java Web Start applications and sandboxed Java applets. Local access is required to leverage this issue.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2468" published="2013-06-18" name="CVE-2013-2468" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2442 and CVE-2013-2466.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2469" published="2013-06-18" name="CVE-2013-2469" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2470" published="2013-06-18" name="CVE-2013-2470" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2471, CVE-2013-2472, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2471" published="2013-06-18" name="CVE-2013-2471" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2472, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2472" published="2013-06-18" name="CVE-2013-2472" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2473.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2473" published="2013-06-18" name="CVE-2013-2473" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2464, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, and CVE-2013-2472.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-2783" published="2013-06-14" name="CVE-2013-2783" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The DNP3 driver in IOServer drivers 1.0.19.0 allows remote attackers to cause a denial of service (infinite loop) or obtain unspecified control via crafted data to TCP port 20000.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://ics-cert.us-cert.gov/advisories/ICSA-13-161-01" source="MISC" patch="1">http://ics-cert.us-cert.gov/advisories/ICSA-13-161-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ioserver" name="ioserver">
        <vers num="1.0.19.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2013-2866" published="2013-06-19" name="CVE-2013-2866" modified="2013-06-19">
    <desc>
      <descript source="cve">The Flash plug-in in Google Chrome before 27.0.1453.116 does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's physical environment via a clickjacking attack, as demonstrated by an attack using a crafted Cascading Style Sheets (CSS) opacity property.</descript>
    </desc>
    <refs>
      <ref url="https://src.chromium.org/viewvc/chrome?revision=206188&amp;view=revision" source="CONFIRM">https://src.chromium.org/viewvc/chrome?revision=206188&amp;view=revision</ref>
      <ref url="https://code.google.com/p/chromium/issues/detail?id=249335" source="CONFIRM">https://code.google.com/p/chromium/issues/detail?id=249335</ref>
      <ref url="http://habrahabr.ru/post/182706/" source="MISC">http://habrahabr.ru/post/182706/</ref>
      <ref url="http://googlechromereleases.blogspot.com/2013/06/stable-channel-update_18.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2013/06/stable-channel-update_18.html</ref>
    </refs>
  </entry>
  <entry type="CVE" seq="2013-2968" published="2013-06-19" name="CVE-2013-2968" modified="2013-06-19">
    <desc>
      <descript source="cve">An unspecified buffer-read method in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to cause a denial of service via a large file that lacks end-of-line characters.</descript>
    </desc>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83859" source="XF">sterling-cve20132968-dos(83859)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21640348" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21640348</ref>
    </refs>
  </entry>
  <entry type="CVE" seq="2013-2969" published="2013-06-19" name="CVE-2013-2969" modified="2013-06-19">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters.</descript>
    </desc>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83860" source="XF">sterling-cve20132969-xss(83860)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21640348" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21640348</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2980" published="2013-06-17" name="CVE-2013-2980" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to hijack the authentication of arbitrary users for requests that access monitored database information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/84113" source="XF">datastudio-cve20132980-csrf(84113)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21638733" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21638733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="data_studio">
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-2981" published="2013-06-17" name="CVE-2013-2981" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to read arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/83973" source="XF">datastudio-cve20132981-dir-traversal(83973)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21638734" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21638734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="data_studio">
        <vers num="3.1.0"/>
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3026" published="2013-06-16" name="CVE-2013-3026" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Lotus Quickr for Domino ActiveX control in qp2.cab in IBM Lotus Quickr 8.1 before FP 8.1.0.32-001a, 8.2 before FP 8.2.0.28-001a, and 8.5.1 before FP 8.5.1.39-002a for Domino allows remote attackers to execute arbitrary code via a crafted web site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/84381" source="XF">quickr-qp2-activex-bo(84381)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21639643" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21639643</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_quickr_for_domino">
        <vers num="8.1.0"/>
        <vers num="8.2.0"/>
        <vers num="8.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3110" published="2013-06-11" name="CVE-2013-3110" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3141.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3111" published="2013-06-11" name="CVE-2013-3111" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3123.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3112" published="2013-06-11" name="CVE-2013-3112" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3113, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3113" published="2013-06-11" name="CVE-2013-3113" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3114" published="2013-06-11" name="CVE-2013-3114" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3119.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3116" published="2013-06-11" name="CVE-2013-3116" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3117" published="2013-06-11" name="CVE-2013-3117" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3122 and CVE-2013-3124.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3118" published="2013-06-11" name="CVE-2013-3118" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3120 and CVE-2013-3125.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3119" published="2013-06-11" name="CVE-2013-3119" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3114.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3120" published="2013-06-11" name="CVE-2013-3120" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3125.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3121" published="2013-06-11" name="CVE-2013-3121" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3139, and CVE-2013-3142.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3122" published="2013-06-11" name="CVE-2013-3122" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3117 and CVE-2013-3124.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3123" published="2013-06-11" name="CVE-2013-3123" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3111.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3124" published="2013-06-11" name="CVE-2013-3124" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3117 and CVE-2013-3122.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3125" published="2013-06-11" name="CVE-2013-3125" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3120.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3126" published="2013-06-11" name="CVE-2013-3126" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 9 and 10, when script debugging is enabled, does not properly handle objects in memory during the processing of script, which allows remote attackers to execute arbitrary code via a crafted web site, aka "Internet Explorer Script Debug Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3136" published="2013-06-11" name="CVE-2013-3136" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:N/A:N)" CVSS_score="4.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="2.7" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-048" source="MS" patch="1" adv="1">MS13-048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_8">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="-" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3138" published="2013-06-11" name="CVE-2013-3138" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-049" source="MS" patch="1" adv="1">MS13-049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp1:x86"/>
      </prod>
      <prod vendor="microsoft" name="windows_8">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x86"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_rt">
        <vers num="-"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x86"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3139" published="2013-06-11" name="CVE-2013-3139" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3142.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3141" published="2013-06-11" name="CVE-2013-3141" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3110.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3142" published="2013-06-11" name="CVE-2013-3142" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3139.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://technet.microsoft.com/security/bulletin/MS13-047" source="MS" patch="1" adv="1">MS13-047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="10"/>
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3343" published="2013-06-11" name="CVE-2013-3343" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Adobe Flash Player before 10.3.183.90 and 11.x before 11.7.700.224 on Windows, before 10.3.183.90 and 11.x before 11.7.700.225 on Mac OS X, before 10.3.183.90 and 11.x before 11.2.202.291 on Linux, before 11.1.111.59 on Android 2.x and 3.x, and before 11.1.115.63 on Android 4.x; Adobe AIR before 3.7.0.2090 on Windows and Android and before 3.7.0.2100 on Mac OS X; and Adobe AIR SDK &amp; Compiler before 3.7.0.2090 on Windows and before 3.7.0.2100 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb13-16.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb13-16.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="adobe_air">
        <vers num="3.0.0.408"/>
        <vers num="3.0.0.4080"/>
        <vers num="3.1.0.485"/>
        <vers num="3.1.0.488"/>
        <vers num="3.1.0.4880"/>
        <vers num="3.2.0.207"/>
        <vers num="3.2.0.2070"/>
        <vers num="3.3.0.3670"/>
        <vers num="3.4.0.2540"/>
        <vers num="3.4.0.2710"/>
        <vers num="3.5.0.1060"/>
        <vers num="3.5.0.600"/>
        <vers num="3.5.0.880"/>
        <vers num="3.5.0.890"/>
        <vers num="3.6.0.597"/>
        <vers num="3.6.0.6090"/>
        <vers num="3.7.0.1530"/>
        <vers prev="1" num="3.7.0.1860"/>
      </prod>
      <prod vendor="adobe" name="adobe_air_sdk">
        <vers num="3.0.0.4080"/>
        <vers num="3.1.0.488"/>
        <vers num="3.2.0.2070"/>
        <vers num="3.3.0.3650"/>
        <vers num="3.3.0.3690"/>
        <vers num="3.4.0.2540"/>
        <vers num="3.4.0.2710"/>
        <vers num="3.5.0.1060"/>
        <vers num="3.5.0.600"/>
        <vers num="3.5.0.880"/>
        <vers num="3.5.0.890"/>
        <vers num="3.6.0.599"/>
        <vers num="3.6.0.6090"/>
        <vers num="3.7.0.1530"/>
        <vers prev="1" num="3.7.0.1860"/>
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="10.0.0.584"/>
        <vers num="10.0.12.10"/>
        <vers num="10.0.12.36"/>
        <vers num="10.0.15.3"/>
        <vers num="10.0.2.54"/>
        <vers num="10.0.22.87"/>
        <vers num="10.0.32.18"/>
        <vers num="10.0.42.34"/>
        <vers num="10.0.45.2"/>
        <vers num="10.1"/>
        <vers num="10.1.102.64"/>
        <vers num="10.1.105.6"/>
        <vers num="10.1.106.16"/>
        <vers num="10.1.106.17"/>
        <vers num="10.1.52.14"/>
        <vers num="10.1.52.14.1"/>
        <vers num="10.1.52.15"/>
        <vers num="10.1.53.64"/>
        <vers num="10.1.82.76"/>
        <vers num="10.1.85.3"/>
        <vers num="10.1.92.10"/>
        <vers num="10.1.92.8"/>
        <vers num="10.1.95.1"/>
        <vers num="10.1.95.2"/>
        <vers num="10.2.152"/>
        <vers num="10.2.152.26"/>
        <vers num="10.2.152.32"/>
        <vers num="10.2.152.33"/>
        <vers num="10.2.153.1"/>
        <vers num="10.2.154.13"/>
        <vers num="10.2.154.25"/>
        <vers num="10.2.156.12"/>
        <vers num="10.2.157.51"/>
        <vers num="10.2.159.1"/>
        <vers num="10.3.181.14"/>
        <vers num="10.3.181.16"/>
        <vers num="10.3.181.22"/>
        <vers num="10.3.181.23"/>
        <vers num="10.3.181.26"/>
        <vers num="10.3.181.34"/>
        <vers num="10.3.183.10"/>
        <vers num="10.3.183.11"/>
        <vers num="10.3.183.15"/>
        <vers num="10.3.183.16"/>
        <vers num="10.3.183.18"/>
        <vers num="10.3.183.19"/>
        <vers num="10.3.183.20"/>
        <vers num="10.3.183.23"/>
        <vers num="10.3.183.25"/>
        <vers num="10.3.183.29"/>
        <vers num="10.3.183.43"/>
        <vers num="10.3.183.48"/>
        <vers num="10.3.183.5"/>
        <vers num="10.3.183.50"/>
        <vers num="10.3.183.51"/>
        <vers num="10.3.183.61"/>
        <vers num="10.3.183.63"/>
        <vers num="10.3.183.67"/>
        <vers num="10.3.183.68"/>
        <vers num="10.3.183.7"/>
        <vers num="10.3.183.75"/>
        <vers prev="1" num="10.3.183.86"/>
        <vers num="11.0"/>
        <vers num="11.0.1.152"/>
        <vers num="11.0.1.153"/>
        <vers num="11.1"/>
        <vers num="11.1.102.55"/>
        <vers num="11.1.102.59"/>
        <vers num="11.1.102.62"/>
        <vers num="11.1.102.63"/>
        <vers num="11.1.111.44"/>
        <vers num="11.1.111.50"/>
        <vers prev="1" num="11.1.111.54"/>
        <vers num="11.1.111.8"/>
        <vers num="11.1.115.34"/>
        <vers num="11.1.115.48"/>
        <vers num="11.1.115.54"/>
        <vers num="11.1.115.58"/>
        <vers num="11.1.115.7"/>
        <vers num="11.2.202.223"/>
        <vers num="11.2.202.228"/>
        <vers num="11.2.202.233"/>
        <vers num="11.2.202.235"/>
        <vers num="11.2.202.236"/>
        <vers num="11.2.202.238"/>
        <vers num="11.2.202.243"/>
        <vers num="11.2.202.251"/>
        <vers num="11.2.202.258"/>
        <vers num="11.2.202.261"/>
        <vers num="11.2.202.262"/>
        <vers num="11.2.202.270"/>
        <vers num="11.2.202.273"/>
        <vers num="11.2.202.275"/>
        <vers num="11.2.202.280"/>
        <vers num="11.2.202.285"/>
        <vers num="11.3.300.257"/>
        <vers num="11.3.300.262"/>
        <vers num="11.3.300.265"/>
        <vers num="11.3.300.268"/>
        <vers num="11.3.300.270"/>
        <vers num="11.3.300.271"/>
        <vers num="11.3.300.273"/>
        <vers num="11.4.402.265"/>
        <vers num="11.4.402.278"/>
        <vers num="11.4.402.287"/>
        <vers num="11.5.502.110"/>
        <vers num="11.5.502.135"/>
        <vers num="11.5.502.136"/>
        <vers num="11.5.502.146"/>
        <vers num="11.5.502.149"/>
        <vers num="11.6.602.167"/>
        <vers num="11.6.602.168"/>
        <vers num="11.6.602.171"/>
        <vers num="11.6.602.180"/>
        <vers num="11.7.700.169"/>
        <vers prev="1" num="11.7.700.202"/>
        <vers prev="1" num="11.7.700.203"/>
        <vers num="6.0.21.0"/>
        <vers num="6.0.79"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.14.0"/>
        <vers num="7.0.19.0"/>
        <vers num="7.0.24.0"/>
        <vers num="7.0.25"/>
        <vers num="7.0.53.0"/>
        <vers num="7.0.60.0"/>
        <vers num="7.0.61.0"/>
        <vers num="7.0.63"/>
        <vers num="7.0.66.0"/>
        <vers num="7.0.67.0"/>
        <vers num="7.0.68.0"/>
        <vers num="7.0.69.0"/>
        <vers num="7.0.70.0"/>
        <vers num="7.0.73.0"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.2"/>
        <vers num="8.0"/>
        <vers num="8.0.22.0"/>
        <vers num="8.0.24.0"/>
        <vers num="8.0.33.0"/>
        <vers num="8.0.34.0"/>
        <vers num="8.0.35.0"/>
        <vers num="8.0.39.0"/>
        <vers num="8.0.42.0"/>
        <vers num="9.0"/>
        <vers num="9.0.112.0"/>
        <vers num="9.0.114.0"/>
        <vers num="9.0.115.0"/>
        <vers num="9.0.124.0"/>
        <vers num="9.0.125.0"/>
        <vers num="9.0.151.0"/>
        <vers num="9.0.152.0"/>
        <vers num="9.0.155.0"/>
        <vers num="9.0.159.0"/>
        <vers num="9.0.16"/>
        <vers num="9.0.18d60"/>
        <vers num="9.0.20"/>
        <vers num="9.0.20.0"/>
        <vers num="9.0.246.0"/>
        <vers num="9.0.260.0"/>
        <vers num="9.0.262.0"/>
        <vers num="9.0.277.0"/>
        <vers num="9.0.28"/>
        <vers num="9.0.28.0"/>
        <vers num="9.0.280"/>
        <vers num="9.0.283.0"/>
        <vers num="9.0.31"/>
        <vers num="9.0.31.0"/>
        <vers num="9.0.45.0"/>
        <vers num="9.0.47.0"/>
        <vers num="9.0.48.0"/>
        <vers num="9.0.8.0"/>
        <vers num="9.0.9.0"/>
        <vers num="9.125.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3375" published="2013-06-14" name="CVE-2013-3375" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the portal page in Cisco Prime Central for Hosted Collaboration Solution allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCue23798.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3375" source="CISCO" adv="1">20130613 Cisco Prime Central for Hosted Collaboration Solution Cross-Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="prime_central_for_hosted_collaboration_solution">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3376" published="2013-06-14" name="CVE-2013-3376" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCty74490.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3376" source="CISCO" adv="1">20130612 Cisco Video Surveillance Operations Manager Help Page Allows Loading Remote Sites</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="video_surveillance_operations_manager">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3380" published="2013-06-11" name="CVE-2013-3380" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The administrative web interface in the Access Control Server in Cisco Secure Access Control System (ACS) does not properly restrict the report view page, which allows remote authenticated users to obtain sensitive information via a direct request, aka Bug ID CSCue79279.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3380" source="CISCO" adv="1">20130610 Cisco Access Control Server Privilege Escalation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3381" published="2013-06-11" name="CVE-2013-3381" modified="2013-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Hosted Collaboration Mediation allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed UDP packets on port 162, aka Bug ID CSCug85756.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3381" source="CISCO" adv="1">20130610 Cisco Hosted Collaboration Mediation Excessive CPU Utilization Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="hosted_collaboration_solution">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3520" published="2013-06-16" name="CVE-2013-3520" modified="2013-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2013-0008.html" source="CONFIRM" adv="1">http://www.vmware.com/security/advisories/VMSA-2013-0008.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="vcenter_chargeback_manager">
        <vers num="1.5.0"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers prev="1" num="2.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3573" published="2013-06-14" name="CVE-2013-3573" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">HP Insight Diagnostics 9.4.0.4710 allows remote attackers to conduct unspecified injection attacks via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/324668" source="CERT-VN">VU#324668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_diagnostics">
        <vers num="9.4.0.4710"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3574" published="2013-06-14" name="CVE-2013-3574" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full pathname in the argument to the devicePath (aka mount) parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/324668" source="CERT-VN">VU#324668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_diagnostics">
        <vers num="9.4.0.4710"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3575" published="2013-06-14" name="CVE-2013-3575" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows remote attackers to include arbitrary hpdiags/frontend2/help/ .html files via the path parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/324668" source="CERT-VN">VU#324668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_diagnostics">
        <vers num="9.4.0.4710"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3576" published="2013-06-14" name="CVE-2013-3576" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to execute arbitrary commands via shell metacharacters in the PATH_INFO to smhutil/snmpchp.php.en.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/735364" source="CERT-VN">VU#735364</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="system_management_homepage">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3642" published="2013-06-16" name="CVE-2013-3642" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Angel Browser application 1.47b and earlier for Android 1.6 through 2.1, 1.62b and earlier for Android 2.2 through 2.3.4, 1.68b and earlier for Android 3.0 through 4.0.3, and 1.76b and earlier for Android 4.1 through 4.2 does not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000055" source="JVNDB">JVNDB-2013-000055</ref>
      <ref url="http://jvn.jp/en/jp/JVN79301570/index.html" source="JVN">JVN#79301570</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adgjm" name="angel_browser">
        <vers prev="1" num="1.47b"/>
        <vers prev="1" num="1.62b"/>
        <vers prev="1" num="1.68b"/>
        <vers prev="1" num="1.76b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3643" published="2013-06-16" name="CVE-2013-3643" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Galapagos Browser application for Android does not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000056" source="JVNDB">JVNDB-2013-000056</ref>
      <ref url="http://jvn.jp/en/jp/JVN99813183/index.html" source="JVN">JVN#99813183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adgjm" name="galapagos_browser">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2013-3644" published="2013-06-18" name="CVE-2013-3644" modified="2013-06-18">
    <desc>
      <descript source="cve">Unspecified vulnerability in JustSystems Ichitaro 2006 through 2013; Ichitaro Pro through 2; Ichitaro Government 6, 7, and 2006 through 2010; Ichitaro Portable with oreplug; Ichitaro Viewer; and Ichitaro JUST School through 2010 allows remote attackers to execute arbitrary code via a crafted document.</descript>
    </desc>
    <refs>
      <ref url="http://www.justsystems.com/jp/info/js13002.html" source="CONFIRM">http://www.justsystems.com/jp/info/js13002.html</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000058" source="JVNDB">JVNDB-2013-000058</ref>
      <ref url="http://jvn.jp/en/jp/JVN98712361/index.html" source="JVN">JVN#98712361</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3645" published="2013-06-14" name="CVE-2013-3645" modified="2013-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Orchard.Comments module in Orchard before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://docs.orchardproject.net/Documentation/Patch-4-30-2013" source="CONFIRM" patch="1" adv="1">http://docs.orchardproject.net/Documentation/Patch-4-30-2013</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000057" source="JVNDB">JVNDB-2013-000057</ref>
      <ref url="http://jvn.jp/en/jp/JVN53622030/index.html" source="JVN">JVN#53622030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orchardproject" name="orchard">
        <vers num="0.1"/>
        <vers num="0.5"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.41"/>
        <vers num="1.42"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers prev="1" num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3646" published="2013-06-18" name="CVE-2013-3646" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Cybozu Live application before 2.0.1 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site. NOTE: this vulnerability exists because of a CVE-2012-4008 regression.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://live.cybozu.co.jp/trouble.html?q=2530" source="CONFIRM" adv="1">https://live.cybozu.co.jp/trouble.html?q=2530</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000059" source="JVNDB">JVNDB-2013-000059</ref>
      <ref url="http://jvn.jp/en/jp/JVN63428218/index.html" source="JVN">JVN#63428218</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cybozu" name="cybozu_live">
        <vers num="1.0.4" edition="-"/>
        <vers num="1.0.4" edition="-:~~~android~~"/>
        <vers prev="1" num="2.0.0" edition="-"/>
        <vers prev="1" num="2.0.0" edition="-:~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3647" published="2013-06-18" name="CVE-2013-3647" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The WebView class in the Cybozu Live application before 2.0.1 for Android allows attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL.  NOTE: this vulnerability exists because of a CVE-2012-4009 regression.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://live.cybozu.co.jp/trouble.html?q=2530" source="CONFIRM" adv="1">https://live.cybozu.co.jp/trouble.html?q=2530</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2013-000060" source="JVNDB">JVNDB-2013-000060</ref>
      <ref url="http://jvn.jp/en/jp/JVN19740283/index.html" source="JVN">JVN#19740283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cybozu" name="cybozu_live">
        <vers num="1.0.4" edition="-"/>
        <vers num="1.0.4" edition="-:~~~android~~"/>
        <vers prev="1" num="2.0.0" edition="-"/>
        <vers prev="1" num="2.0.0" edition="-:~~~android~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3743" published="2013-06-18" name="CVE-2013-3743" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 45 and earlier and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.5.0" edition="update_36"/>
        <vers prev="1" num="1.5.0" edition="update_38"/>
        <vers prev="1" num="1.5.0" edition="update_39"/>
        <vers prev="1" num="1.5.0" edition="update_40"/>
        <vers prev="1" num="1.5.0" edition="update_41"/>
        <vers prev="1" num="1.5.0" edition="update_45"/>
        <vers prev="1" num="1.6.0" edition="update_22"/>
        <vers prev="1" num="1.6.0" edition="update_23"/>
        <vers prev="1" num="1.6.0" edition="update_24"/>
        <vers prev="1" num="1.6.0" edition="update_25"/>
        <vers prev="1" num="1.6.0" edition="update_26"/>
        <vers prev="1" num="1.6.0" edition="update_27"/>
        <vers prev="1" num="1.6.0" edition="update_29"/>
        <vers prev="1" num="1.6.0" edition="update_30"/>
        <vers prev="1" num="1.6.0" edition="update_31"/>
        <vers prev="1" num="1.6.0" edition="update_32"/>
        <vers prev="1" num="1.6.0" edition="update_33"/>
        <vers prev="1" num="1.6.0" edition="update_34"/>
        <vers prev="1" num="1.6.0" edition="update_35"/>
        <vers prev="1" num="1.6.0" edition="update_37"/>
        <vers prev="1" num="1.6.0" edition="update_38"/>
        <vers prev="1" num="1.6.0" edition="update_39"/>
        <vers prev="1" num="1.6.0" edition="update_41"/>
        <vers prev="1" num="1.6.0" edition="update_43"/>
        <vers prev="1" num="1.6.0" edition="update_45"/>
      </prod>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update11_b03"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update7_b03"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update1"/>
        <vers num="1.6.0" edition="update1_b06"/>
        <vers num="1.6.0" edition="update2"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1"/>
        <vers num="1.5.0" edition="update10"/>
        <vers num="1.5.0" edition="update11"/>
        <vers num="1.5.0" edition="update12"/>
        <vers num="1.5.0" edition="update13"/>
        <vers num="1.5.0" edition="update14"/>
        <vers num="1.5.0" edition="update15"/>
        <vers num="1.5.0" edition="update16"/>
        <vers num="1.5.0" edition="update17"/>
        <vers num="1.5.0" edition="update18"/>
        <vers num="1.5.0" edition="update19"/>
        <vers num="1.5.0" edition="update2"/>
        <vers num="1.5.0" edition="update20"/>
        <vers num="1.5.0" edition="update21"/>
        <vers num="1.5.0" edition="update22"/>
        <vers num="1.5.0" edition="update23"/>
        <vers num="1.5.0" edition="update24"/>
        <vers num="1.5.0" edition="update25"/>
        <vers num="1.5.0" edition="update26"/>
        <vers num="1.5.0" edition="update27"/>
        <vers num="1.5.0" edition="update28"/>
        <vers num="1.5.0" edition="update29"/>
        <vers num="1.5.0" edition="update3"/>
        <vers num="1.5.0" edition="update31"/>
        <vers num="1.5.0" edition="update33"/>
        <vers num="1.5.0" edition="update4"/>
        <vers num="1.5.0" edition="update5"/>
        <vers num="1.5.0" edition="update6"/>
        <vers num="1.5.0" edition="update7"/>
        <vers num="1.5.0" edition="update8"/>
        <vers num="1.5.0" edition="update9"/>
        <vers num="1.6.0" edition="update_1"/>
        <vers num="1.6.0" edition="update_10"/>
        <vers num="1.6.0" edition="update_11"/>
        <vers num="1.6.0" edition="update_12"/>
        <vers num="1.6.0" edition="update_13"/>
        <vers num="1.6.0" edition="update_14"/>
        <vers num="1.6.0" edition="update_15"/>
        <vers num="1.6.0" edition="update_16"/>
        <vers num="1.6.0" edition="update_17"/>
        <vers num="1.6.0" edition="update_18"/>
        <vers num="1.6.0" edition="update_19"/>
        <vers num="1.6.0" edition="update_2"/>
        <vers num="1.6.0" edition="update_20"/>
        <vers num="1.6.0" edition="update_21"/>
        <vers num="1.6.0" edition="update_3"/>
        <vers num="1.6.0" edition="update_4"/>
        <vers num="1.6.0" edition="update_5"/>
        <vers num="1.6.0" edition="update_6"/>
        <vers num="1.6.0" edition="update_7"/>
        <vers num="1.6.0" edition="update_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3744" published="2013-06-18" name="CVE-2013-3744" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2400.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

'Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.'</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html" source="CONFIRM" adv="1">http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.7.0" edition="update1"/>
        <vers prev="1" num="1.7.0" edition="update10"/>
        <vers prev="1" num="1.7.0" edition="update11"/>
        <vers prev="1" num="1.7.0" edition="update13"/>
        <vers prev="1" num="1.7.0" edition="update15"/>
        <vers prev="1" num="1.7.0" edition="update17"/>
        <vers prev="1" num="1.7.0" edition="update2"/>
        <vers prev="1" num="1.7.0" edition="update21"/>
        <vers prev="1" num="1.7.0" edition="update3"/>
        <vers prev="1" num="1.7.0" edition="update4"/>
        <vers prev="1" num="1.7.0" edition="update5"/>
        <vers prev="1" num="1.7.0" edition="update6"/>
        <vers prev="1" num="1.7.0" edition="update7"/>
        <vers prev="1" num="1.7.0" edition="update9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3927" published="2013-06-18" name="CVE-2013-3927" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the client library in Siemens COMOS 9.2 before 9.2.0.6.10 and 10.0 before 10.0.3.0.4 allows local users to obtain unintended write access to the database by leveraging read access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-194865.pdf" source="CONFIRM" adv="1">http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-194865.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="comos">
        <vers num="10.0"/>
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3957" published="2013-06-14" name="CVE-2013-3957" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf" source="CONFIRM" adv="1">http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="simatic_pcs7">
        <vers prev="1" num="8.0" edition="sp1"/>
      </prod>
      <prod vendor="siemens" name="wincc">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.1" edition="sp1"/>
        <vers prev="1" num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-3958" published="2013-06-14" name="CVE-2013-3958" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for remote attackers to obtain access via an unspecified request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf" source="CONFIRM" adv="1">http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="simatic_pcs7">
        <vers prev="1" num="8.0" edition="sp1"/>
      </prod>
      <prod vendor="siemens" name="wincc">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.1" edition="sp1"/>
        <vers prev="1" num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3959" published="2013-06-14" name="CVE-2013-3959" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the user account exists, which allows remote authenticated users to enumerate account names via crafted URL parameters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf" source="CONFIRM" adv="1">http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="simatic_pcs7">
        <vers prev="1" num="8.0" edition="sp1"/>
      </prod>
      <prod vendor="siemens" name="wincc">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.1" edition="sp1"/>
        <vers prev="1" num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-3970" published="2013-06-13" name="CVE-2013-3970" modified="2013-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 include a test Certification Authority (CA) certificate in the Trusted Server CAs list, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging control over that test CA.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://kb.juniper.net/JSA10571" source="CONFIRM" patch="1" adv="1">http://kb.juniper.net/JSA10571</ref>
    </refs>
    <vuln_soft>
      <prod vendor="juniper" name="junos_pulse_access_control_service">
        <vers num="4.1r1"/>
        <vers num="4.1r1.1"/>
        <vers num="4.1r2"/>
        <vers num="4.1r3"/>
        <vers num="4.1r4"/>
        <vers num="4.1r5"/>
      </prod>
      <prod vendor="juniper" name="junos_pulse_secure_access_service">
        <vers num="7.0r2"/>
        <vers num="7.0r3"/>
        <vers num="7.0r4"/>
        <vers num="7.0r5"/>
        <vers num="7.0r5.1"/>
        <vers num="7.0r6"/>
        <vers num="7.0r7"/>
        <vers num="7.0r8"/>
        <vers num="7.1r1"/>
        <vers num="7.1r1.1"/>
        <vers num="7.1r2"/>
        <vers num="7.1r3"/>
        <vers num="7.1r4"/>
        <vers num="7.1r5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-4608" published="2013-06-17" name="CVE-2013-4608" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in REDCap before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving the Graphical Data View &amp; Descriptive Stats page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.13.18"/>
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers num="4.14.4"/>
        <vers num="4.14.5"/>
        <vers num="4.14.6"/>
        <vers num="4.15.0"/>
        <vers num="4.15.1"/>
        <vers num="4.15.2"/>
        <vers num="4.15.3"/>
        <vers num="4.15.4"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-4609" published="2013-06-17" name="CVE-2013-4609" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.13.18"/>
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers num="4.14.4"/>
        <vers num="4.14.5"/>
        <vers num="4.14.6"/>
        <vers num="4.15.0"/>
        <vers num="4.15.1"/>
        <vers num="4.15.2"/>
        <vers num="4.15.3"/>
        <vers num="4.15.4"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers prev="1" num="5.0.3"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
        <vers num="5.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-4610" published="2013-06-17" name="CVE-2013-4610" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.13.18"/>
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers num="4.14.4"/>
        <vers num="4.14.5"/>
        <vers num="4.14.6"/>
        <vers num="4.15.0"/>
        <vers num="4.15.1"/>
        <vers num="4.15.2"/>
        <vers num="4.15.3"/>
        <vers num="4.15.4"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers prev="1" num="5.0.2"/>
        <vers num="5.0.6"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-4611" published="2013-06-17" name="CVE-2013-4611" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the Online Designer page or (2) the Manage Survey Participants page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.13.18"/>
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers num="4.14.4"/>
        <vers num="4.14.5"/>
        <vers num="4.14.6"/>
        <vers num="4.15.0"/>
        <vers num="4.15.1"/>
        <vers num="4.15.2"/>
        <vers num="4.15.3"/>
        <vers num="4.15.4"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers prev="1" num="5.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2013-4612" published="2013-06-17" name="CVE-2013-4612" modified="2013-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in REDCap before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving different modules.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf" source="CONFIRM">http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="project-redcap" name="redcap">
        <vers num="4.13.18"/>
        <vers num="4.14.0"/>
        <vers num="4.14.1"/>
        <vers num="4.14.2"/>
        <vers num="4.14.3"/>
        <vers num="4.14.4"/>
        <vers num="4.14.5"/>
        <vers num="4.14.6"/>
        <vers num="4.15.0"/>
        <vers num="4.15.1"/>
        <vers num="4.15.2"/>
        <vers num="4.15.3"/>
        <vers num="4.15.4"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers prev="1" num="5.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-4616" published="2013-06-18" name="CVE-2013-4616" modified="2013-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The WifiPasswordController generateDefaultPassword method in Preferences in Apple iOS 6 and earlier relies on the UITextChecker suggestWordInLanguage method for selection of Wi-Fi hotspot WPA2 PSK passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack that leverages the insufficient number of possible passphrases.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www1.cs.fau.de/hotspot" source="MISC">http://www1.cs.fau.de/hotspot</ref>
      <ref url="http://www1.cs.fau.de/filepool/projects/hotspot/hotspot.pdf" source="MISC">http://www1.cs.fau.de/filepool/projects/hotspot/hotspot.pdf</ref>
      <ref url="http://lists.owasp.org/pipermail/owasp-mobile-security-project/2013-June/000640.html" source="MLIST">[owasp-mobile-security-project] 20130617 Cracking iOS personal hotspots using a Scrabble crossword game word list</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers prev="1" num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2013-4622" published="2013-06-19" name="CVE-2013-4622" modified="2013-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The 3G Mobile Hotspot feature on the HTC Droid Incredible has a default WPA2 PSK passphrase of 1234567890, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www1.cs.fau.de/filepool/projects/hotspot/hotspot.pdf" source="MISC">http://www1.cs.fau.de/filepool/projects/hotspot/hotspot.pdf</ref>
      <ref url="http://support.verizonwireless.com/clc/devices/knowledge_base.html?id=35523" source="CONFIRM">http://support.verizonwireless.com/clc/devices/knowledge_base.html?id=35523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="htc" name="droid_incredible">
        <vers num="-"/>
        <vers num="frf91"/>
      </prod>
    </vuln_soft>
  </entry>
</nvd>