<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2009-11-07" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:N)" CVSS_base_score="6.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="9.2" name="CVE-2009-3611" seq="2009-3611" severity="Medium" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="6.6" modified="2009-10-26">
        <desc>
            <descript source="cve">common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://ftp.debian.org/debian/pool/main/b/backintime/backintime_0.9.26-3.diff.gz">http://ftp.debian.org/debian/pool/main/b/backintime/backintime_0.9.26-3.diff.gz</ref>
            <ref source="CONFIRM" patch="1" url="http://bugs.gentoo.org/show_bug.cgi?id=289047">http://bugs.gentoo.org/show_bug.cgi?id=289047</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00823.html">FEDORA-2009-9298</ref>
            <ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00821.html">FEDORA-2009-9282</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=520210">https://bugzilla.redhat.com/show_bug.cgi?id=520210</ref>
            <ref source="CONFIRM" url="https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256">https://bugs.launchpad.net/ubuntu/+source/backintime/+bug/434256</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125554894700336&amp;w=2">[oss-security] 20091014 Re: CVE Request - backintime</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125553645511436&amp;w=2">[oss-security] 20091014 CVE Request - backintime</ref>
            <ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543785">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543785</ref>
        </refs>
        <vuln_soft>
            <prod vendor="le-web" name="backintime">
                <vers num="0.9.26" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3625" seq="2009-3625" severity="High" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-31">
        <desc>
            <descript source="cve">Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=530255">https://bugzilla.redhat.com/show_bug.cgi?id=530255</ref>
            <ref source="MLIST" patch="1" url="http://www.openwall.com/lists/oss-security/2009/10/22/6">[oss-security] 20091022 Re: CVE Request -- Sahana</ref>
            <ref source="MLIST" patch="1" url="http://www.openwall.com/lists/oss-security/2009/10/22/3">[oss-security] 20091022 CVE Request -- Sahana</ref>
            <ref source="CONFIRM" patch="1" url="http://sahana.cvs.sourceforge.net/viewvc/sahana/sahana-phase2/www/index.php?r1=1.83&amp;r2=1.84">http://sahana.cvs.sourceforge.net/viewvc/sahana/sahana-phase2/www/index.php?r1=1.83&amp;r2=1.84</ref>
            <ref source="CONFIRM" url="https://fedorahosted.org/rel-eng/ticket/2635">https://fedorahosted.org/rel-eng/ticket/2635</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36826">36826</ref>
            <ref source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?thread_name=5d9043b70910191044l4bb0178fs563a5128a0f5db01%40mail.gmail.com&amp;forum_name=sahana-maindev">[sahana-maindev] 20091019 SEVERE Security Vulnerability in Sahana Identified and Patched</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sahana" name="sahana">
                <vers num="0.6.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3778" seq="2009-3778" severity="High" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-27">
        <desc>
            <descript source="cve">SQL injection vulnerability in Moodle Course List 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3001" adv="1">ADV-2009-3001</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36787">36787</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/610986" adv="1">http://drupal.org/node/610986</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53895">moodle-course-unspecified-sql-injection(53895)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37126" adv="1">37126</ref>
            <ref source="OSVDB" url="http://osvdb.org/59100">59100</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adam_gerson" name="moodle_courselist">
                <vers edition="beta1" num="6.x-1.2" />
                <vers edition="beta2" num="6.x-1.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3779" seq="2009-3779" severity="Medium" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-27">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in vCard 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the addition of the theme_vcard function to a theme and the use of default content.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3002" adv="1">ADV-2009-3002</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/610996" adv="1">http://drupal.org/node/610996</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/610420" adv="1">http://drupal.org/node/610420</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/610416" adv="1">http://drupal.org/node/610416</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53903">vcard-themevcard-xss(53903)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36789">36789</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37127" adv="1">37127</ref>
        </refs>
        <vuln_soft>
            <prod vendor="stefan_auditor" name="vcard">
                <vers num="5.x-1.0" />
                <vers num="5.x-1.1" />
                <vers num="5.x-1.2" />
                <vers num="5.x-1.3" />
                <vers num="5.x-1.x-dev" />
                <vers num="6.x-1.0" />
                <vers num="6.x-1.1" />
                <vers num="6.x-1.2" />
                <vers num="6.x-1.x-dev" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3780" seq="2009-3780" severity="Medium" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-27">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in Abuse 5.x before 5.x-2.1 and 6.x before 6.x-1.1-alpha1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36791">36791</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/611078" adv="1">http://drupal.org/node/611078</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/610900" adv="1">http://drupal.org/node/610900</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/610784" adv="1">http://drupal.org/node/610784</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53898">abuse-unspecified-xss(53898)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37129" adv="1">37129</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ashok_modi" name="abuse">
                <vers edition="beta" num="5.x-1.0" />
                <vers num="5.x-1.x-dev" />
                <vers num="5.x-2.x-dev" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3781" seq="2009-3781" severity="High" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-27">
        <desc>
            <descript source="cve">The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36792">36792</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/611128" adv="1">http://drupal.org/node/611128</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/609874" adv="1">http://drupal.org/node/609874</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/516104" adv="1">http://drupal.org/node/516104</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/files/issues/filefield-node-access-fix-516104-3.patch" adv="1">http://drupal.org/files/issues/filefield-node-access-fix-516104-3.patch</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53897">filefield-nodeaccess-security-bypass(53897)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37130" adv="1">37130</ref>
        </refs>
        <vuln_soft>
            <prod vendor="quicksketch" name="filefield">
                <vers num="6.x-3.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" name="CVE-2009-3782" seq="2009-3782" severity="Low" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="3.5" modified="2009-10-27">
        <desc>
            <descript source="cve">Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints" permissions to read the userpoint data of arbitrary users via unknown attack vectors.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/2998" adv="1">ADV-2009-2998</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36786">36786</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/610828" adv="1">http://drupal.org/node/610828</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/610818" adv="1">http://drupal.org/node/610818</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53896">userpoints-userpoint-information-disclosure(53896)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37123" adv="1">37123</ref>
            <ref source="OSVDB" url="http://osvdb.org/59124">59124</ref>
        </refs>
        <vuln_soft>
            <prod vendor="2bits" name="userpoints">
                <vers num="6.x-1.0" />
                <vers num="6.x-1.x-dev" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3783" seq="2009-3783" severity="Medium" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-27">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vector.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36790">36790</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/611002" adv="1">http://drupal.org/node/611002</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/590098" adv="1">http://drupal.org/node/590098</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53905">simplenews-unspecified-xss(53905)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37128" adv="1">37128</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sjoerd_arendsen" name="simplenews_statistics">
                <vers num="6.x-1.0" />
                <vers num="6.x-1.1" />
                <vers num="6.x-1.2" />
                <vers num="6.x-1.x-dev" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2009-3784" seq="2009-3784" severity="Medium" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="6.8" modified="2009-10-27">
        <desc>
            <descript source="cve">Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36790">36790</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/611002" adv="1">http://drupal.org/node/611002</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/590098" adv="1">http://drupal.org/node/590098</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37128" adv="1">37128</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sjoerd_arendsen" name="simplenews_statistics">
                <vers num="6.x-1.0" />
                <vers num="6.x-1.1" />
                <vers num="6.x-1.2" />
                <vers num="6.x-1.x-dev" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" name="CVE-2009-3785" seq="2009-3785" severity="Medium" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="6.8" modified="2009-10-27">
        <desc>
            <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allow remote attackers to hijack the authentication of arbitrary users via unknown vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36790">36790</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/611002" adv="1">http://drupal.org/node/611002</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/590098" adv="1">http://drupal.org/node/590098</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53906">simplenews-unspecified-csrf(53906)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37128" adv="1">37128</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sjoerd_arendsen" name="simplenews_statistics">
                <vers num="6.x-1.0" />
                <vers num="6.x-1.1" />
                <vers num="6.x-1.2" />
                <vers num="6.x-1.x-dev" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3786" seq="2009-3786" severity="Medium" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-27">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in Organic Groups (OG) Vocabulary 5.x before 5.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the group title.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3000" adv="1">ADV-2009-3000</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36784">36784</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/610948" adv="1">http://drupal.org/node/610948</ref>
            <ref source="CONFIRM" patch="1" url="http://drupal.org/node/605094" adv="1">http://drupal.org/node/605094</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53902">ogvocabulary-title-xss(53902)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37125" adv="1">37125</ref>
            <ref source="OSVDB" url="http://osvdb.org/59129">59129</ref>
        </refs>
        <vuln_soft>
            <prod vendor="moshe_weitzman" name="og_vocab">
                <vers num="5.x-1.0" />
                <vers num="5.x-1.x-dev" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3787" seq="2009-3787" severity="Medium" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-27">
        <desc>
            <descript source="cve">files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../" sequence.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://www.waraxe.us/advisory-75.html">http://www.waraxe.us/advisory-75.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36783">36783</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507358/100/0/threaded">20091021 [waraxe-2009-SA#075] - Remote File Disclosure in Vivvo CMS 4.1.5.1</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37117" adv="1">37117</ref>
        </refs>
        <vuln_soft>
            <prod vendor="vivvo" name="vivvo">
                <vers num="4.1.5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3788" seq="2009-3788" severity="High" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-31">
        <desc>
            <descript source="cve">SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username) parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36777">36777</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53886">opendocman-user-sql-injection(53886)</ref>
            <ref source="MISC" url="http://www.packetstormsecurity.org/0910-exploits/opendocman-sqlxss.txt">http://www.packetstormsecurity.org/0910-exploits/opendocman-sqlxss.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30750" adv="1">30750</ref>
            <ref source="OSVDB" url="http://osvdb.org/59301">59301</ref>
        </refs>
        <vuln_soft>
            <prod vendor="opendocman" name="opendocman">
                <vers num="1.2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3789" seq="2009-3789" severity="Medium" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-31">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message parameter to (1) add.php, (2) toBePublished.php, (3) index.php, and (4) admin.php; the PATH_INFO to the default URI to (5) category.php, (6) department.php, (7) profile.php, (8) rejects.php, (9) search.php, (10) toBePublished.php, (11) user.php, and (12) view_file.php; and (13) the caller parameter in a Modify User action to user.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36777">36777</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53887">opendocman-multiple-xss(53887)</ref>
            <ref source="MISC" url="http://www.packetstormsecurity.org/0910-exploits/opendocman-sqlxss.txt">http://www.packetstormsecurity.org/0910-exploits/opendocman-sqlxss.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30750" adv="1">30750</ref>
            <ref source="OSVDB" url="http://osvdb.org/59312">59312</ref>
            <ref source="OSVDB" url="http://osvdb.org/59311">59311</ref>
            <ref source="OSVDB" url="http://osvdb.org/59310">59310</ref>
            <ref source="OSVDB" url="http://osvdb.org/59309">59309</ref>
            <ref source="OSVDB" url="http://osvdb.org/59308">59308</ref>
            <ref source="OSVDB" url="http://osvdb.org/59307">59307</ref>
            <ref source="OSVDB" url="http://osvdb.org/59306">59306</ref>
            <ref source="OSVDB" url="http://osvdb.org/59305">59305</ref>
            <ref source="OSVDB" url="http://osvdb.org/59304">59304</ref>
            <ref source="OSVDB" url="http://osvdb.org/59303">59303</ref>
            <ref source="OSVDB" url="http://osvdb.org/59302">59302</ref>
        </refs>
        <vuln_soft>
            <prod vendor="opendocman" name="opendocman">
                <vers num="1.2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3790" seq="2009-3790" severity="High" type="CVE" published="2009-10-26" CVSS_version="2.0" CVSS_score="9.3" modified="2009-10-27">
        <desc>
            <descript source="cve">Heap-based buffer overflow in FormMax (formerly AcroForm) evaluation 3.5 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted FormMax import (.aim) file.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53890">formmax-aim-bo(53890)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/36943" adv="1">36943</ref>
            <ref source="OSVDB" url="http://osvdb.org/59079">59079</ref>
        </refs>
        <vuln_soft>
            <prod vendor="cutepdf" name="formmax">
                <vers num="3.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3801" seq="2009-3801" severity="High" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-28">
        <desc>
            <descript source="cve">SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password) parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" url="http://secunia.com/advisories/30750" adv="1">30750</ref>
        </refs>
        <vuln_soft>
            <prod vendor="opendocman" name="opendocman">
                <vers num="1.2.5" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3802" seq="2009-3802" severity="Medium" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-28">
        <desc>
            <descript source="cve">Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53894">amiro-index-path-disclosure(53894)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2967" adv="1">ADV-2009-2967</ref>
            <ref source="MISC" url="http://www.onsec.ru/vuln?id=12">http://www.onsec.ru/vuln?id=12</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37065" adv="1">37065</ref>
            <ref source="MISC" url="http://packetstormsecurity.org/0910-exploits/ONSEC-09-005.txt">http://packetstormsecurity.org/0910-exploits/ONSEC-09-005.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="amirocms" name="amiro.cms">
                <vers num="4.0.8.0" />
                <vers num="4.2.0.5" />
                <vers num="4.2.1.0" />
                <vers num="4.2.2.0" />
                <vers num="4.2.3.0" />
                <vers num="4.2.4" />
                <vers num="4.2.5" />
                <vers num="5.0.7" />
                <vers num="5.2" />
                <vers num="5.2.2" />
                <vers num="5.2.3" />
                <vers num="5.4.0.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3803" seq="2009-3803" severity="Medium" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-28">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the status_message parameter to (1) /news, (2) /comment, (3) /forum, (4) /blog, and (5) /tags; the status_message parameter to (6) forum.php, (7) discussion.php, (8) guestbook.php, (9) blog.php, (10) news.php, (11) srv_updates.php, (12) srv_backups.php, (13) srv_twist_prevention.php, (14) srv_tags.php, (15) srv_tags_reindex.php, (16) google_sitemap.php, (17) sitemap_history.php, (18) srv_options.php, (19) locales.php and (20) plugins_wizard.php in _admin/; a crafted IMG BBcode tag in the message body of a (21) forum, (22) guestbook, or (23) comment; (24) the content of an avatar file, which is not properly handled by Internet Explorer; and (25) the loginname parameter (aka username) in _admin/index.php.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53893">amiro-loginname-xss(53893)</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53892">amiro-statusmessage-xss(53892)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2967" adv="1">ADV-2009-2967</ref>
            <ref source="MISC" url="http://www.onsec.ru/vuln?id=11">http://www.onsec.ru/vuln?id=11</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37065" adv="1">37065</ref>
            <ref source="MISC" url="http://packetstormsecurity.org/0910-exploits/ONSEC-09-004.txt">http://packetstormsecurity.org/0910-exploits/ONSEC-09-004.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="amirocms" name="amiro.cms">
                <vers num="4.0.8.0" />
                <vers num="4.2.0.5" />
                <vers num="4.2.1.0" />
                <vers num="4.2.2.0" />
                <vers num="4.2.3.0" />
                <vers num="4.2.4" />
                <vers num="4.2.5" />
                <vers num="5.0.7" />
                <vers num="5.2" />
                <vers num="5.2.2" />
                <vers num="5.2.3" />
                <vers num="5.4.0.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" name="CVE-2009-3804" seq="2009-3804" severity="Medium" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="6.5" modified="2009-10-28">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the topic_id parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37137" adv="1">37137</ref>
            <ref source="MISC" url="http://retrogod.altervista.org/9sg_runcms_store_sql.html">http://retrogod.altervista.org/9sg_runcms_store_sql.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="runcms" name="runcms">
                <vers num="2m1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3805" seq="2009-3805" severity="Medium" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-28">
        <desc>
            <descript source="cve">gpg2.exe in Gpg4win 2.0.1, as used in KDE Kleopatra 2.0.11, allows remote attackers to cause a denial of service (application crash) via a long certificate signature.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53908">gpg4win-gpg2-dos(53908)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36781">36781</ref>
            <ref source="MISC" url="http://www.packetstormsecurity.com/0910-exploits/gpg2kleo-dos.txt">http://www.packetstormsecurity.com/0910-exploits/gpg2kleo-dos.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gpg4win" name="gpg4win">
                <vers num="2.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3806" seq="2009-3806" severity="High" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-28">
        <desc>
            <descript source="cve">SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507109/100/0/threaded">20091012 DEDECMS v5.1 Sql Injection Vulnerability</ref>
        </refs>
        <vuln_soft>
            <prod vendor="dedecms" name="dedecms">
                <vers num="5.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3807" seq="2009-3807" severity="High" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="9.3" modified="2009-10-28">
        <desc>
            <descript source="cve">Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/51715">mixvibes-vib-bo(51715)</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9147">9147</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mixvibes" name="mixvibes">
                <vers edition="" num="7.043" />
                <vers edition=":pro" num="7.043" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3808" seq="2009-3808" severity="High" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="9.3" modified="2009-10-28">
        <desc>
            <descript source="cve">MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an .mp3 playlist file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/51814">djstudio-mp3-dos(51814)</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9178">9178</ref>
        </refs>
        <vuln_soft>
            <prod vendor="kramware" name="mixsense_dj_studio">
                <vers num="1.0.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3809" seq="2009-3809" severity="Medium" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-28">
        <desc>
            <descript source="cve">Acoustica MP3 Audio Mixer 1.0 and possibly 2.471 allows remote attackers to cause a denial of service (crash) via a long string in a .sgp playlist file.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/51868">acoustica-m3u-bo(51868)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1958" adv="1">ADV-2009-1958</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9212">9212</ref>
        </refs>
        <vuln_soft>
            <prod vendor="acoustica" name="mp3_audio_mixer">
                <vers num="1.0" />
                <vers num="2.471" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3810" seq="2009-3810" severity="High" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="9.3" modified="2009-10-28">
        <desc>
            <descript source="cve">Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/51868">acoustica-m3u-bo(51868)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1958" adv="1">ADV-2009-1958</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9213">9213</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35902" adv="1">35902</ref>
            <ref source="OSVDB" url="http://osvdb.org/56033">56033</ref>
        </refs>
        <vuln_soft>
            <prod vendor="acoustica" name="mp3_audio_mixer">
                <vers num="2.471" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3811" seq="2009-3811" severity="High" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="9.3" modified="2009-10-28">
        <desc>
            <descript source="cve">Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag.  NOTE: some of these details are obtained from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/51724">musictageditor-mp3-bo(51724)</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9167">9167</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35828" adv="1">35828</ref>
            <ref source="OSVDB" url="http://osvdb.org/55861">55861</ref>
            <ref source="MISC" url="http://liquidworm.blogspot.com/2009/07/music-tag-editor-161-build-212-remote.html">http://liquidworm.blogspot.com/2009/07/music-tag-editor-161-build-212-remote.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="assistanttools" name="music_tag_editor">
                <vers num="1.61" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3812" seq="2009-3812" severity="High" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="9.3" modified="2009-10-28">
        <desc>
            <descript source="cve">Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 allows remote attackers to execute arbitrary code via a long playlist in an Ots File List (.ofl) file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/51628">otsav-multiple-olf-bo(51628)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1861" adv="1">ADV-2009-1861</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9113">9113</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35738" adv="1">35738</ref>
            <ref source="MISC" url="http://packetstormsecurity.org/0907-exploits/otsav-overflow.txt">http://packetstormsecurity.org/0907-exploits/otsav-overflow.txt</ref>
            <ref source="OSVDB" url="http://osvdb.org/55747">55747</ref>
        </refs>
        <vuln_soft>
            <prod vendor="otslabs" name="otsav_dj">
                <vers edition="trial" num="1.85.64.0" />
            </prod>
            <prod vendor="otslabs" name="otsav_radio">
                <vers edition="trial" num="1.85.64.0" />
            </prod>
            <prod vendor="otslabs" name="otsav_tv">
                <vers edition="trial" num="1.85.64.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" name="CVE-2009-3813" seq="2009-3813" severity="Medium" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="6.5" modified="2009-10-28">
        <desc>
            <descript source="cve">Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum parameter to modules/forum/post.php and possibly (2) forum_id variable to modules/forum/class/class.permissions.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37137" adv="1">37137</ref>
            <ref source="MISC" url="http://retrogod.altervista.org/9sg_runcms_forum_sql.html">http://retrogod.altervista.org/9sg_runcms_forum_sql.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="runcms" name="runcms">
                <vers num="2m1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" name="CVE-2009-3814" seq="2009-3814" severity="Medium" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="6.5" modified="2009-10-28">
        <desc>
            <descript source="cve">Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" feature, as demonstrated by modifying modules/system/cache/bademails.php using the "Prohibited: Emails" action, and other unspecified filters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://retrogod.altervista.org/9sg_runcms_forum_sql.html">http://retrogod.altervista.org/9sg_runcms_forum_sql.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="runcms" name="runcms">
                <vers num="2m1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3815" seq="2009-3815" severity="Medium" type="CVE" published="2009-10-27" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-28">
        <desc>
            <descript source="cve">RunCMS 2M1, when running with certain error_reporting levels, allows remote attackers to obtain sensitive information via (1) the op[] parameter to modules/contact/index.php or (2) uid[] parameter to userinfo.php, which leaks the installation path in an error message when these parameters are used in a call to the preg_match function.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MISC" url="http://retrogod.altervista.org/9sg_runcms_forum_sql.html">http://retrogod.altervista.org/9sg_runcms_forum_sql.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="runcms" name="runcms">
                <vers num="2m1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3816" seq="2009-3816" severity="Medium" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-28">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www-01.ibm.com/support/docview.wss?uid=swg24024303" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg24024303</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37106" adv="1">37106</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_connections">
                <vers num="2.5.0.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3817" seq="2009-3817" severity="High" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-28">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter, a different vector than CVE-2009-2637.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2969" adv="1">ADV-2009-2969</ref>
            <ref source="MISC" url="http://www.securityfocus.com/bid/36732/exploit">http://www.securityfocus.com/bid/36732/exploit</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36732">36732</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ordasoft" name="com_booklibrary">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3818" seq="2009-3818" severity="High" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-28">
        <desc>
            <descript source="cve">Unspecified vulnerability in the session handling feature in freeCap CAPTCHA (sr_freecap) extension 1.2.0 and earlier for TYPO3 has unknown impact and attack vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37094" adv="1">37094</ref>
        </refs>
        <vuln_soft>
            <prod vendor="stanislas_rolland" name="sr_freecap">
                <vers num="0.1.0" />
                <vers num="0.2.0" />
                <vers num="0.2.2" />
                <vers num="0.2.3" />
                <vers num="0.3.0" />
                <vers num="0.3.1" />
                <vers num="0.3.2" />
                <vers num="0.3.3" />
                <vers num="0.4.0" />
                <vers num="0.4.1" />
                <vers num="0.4.2" />
                <vers num="0.4.3" />
                <vers num="0.4.4" />
                <vers num="0.4.5" />
                <vers num="0.4.6" />
                <vers num="1.0.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.1.0" />
                <vers num="1.1.1" />
                <vers num="1.1.2" />
                <vers num="1.2.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3819" seq="2009-3819" severity="High" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-28">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Random Images (maag_randomimage) extension 1.6.4 and earlier for TYPO3 allows remote attackers to execute arbitrary shell commands via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37095" adv="1">37095</ref>
        </refs>
        <vuln_soft>
            <prod vendor="urs_maag" name="maag_randomimage">
                <vers num="0.0.1" />
                <vers num="0.2.0" />
                <vers num="1.0.0" />
                <vers num="1.1.0" />
                <vers num="1.1.1" />
                <vers num="1.1.3" />
                <vers num="1.1.5" />
                <vers num="1.1.6" />
                <vers num="1.2.0" />
                <vers num="1.2.1" />
                <vers num="1.2.10" />
                <vers num="1.2.11" />
                <vers num="1.2.12" />
                <vers num="1.2.13" />
                <vers num="1.2.14" />
                <vers num="1.2.2" />
                <vers num="1.2.3" />
                <vers num="1.2.4" />
                <vers num="1.2.5" />
                <vers num="1.2.6" />
                <vers num="1.2.7" />
                <vers num="1.2.8" />
                <vers num="1.2.9" />
                <vers num="1.3.0" />
                <vers num="1.3.1" />
                <vers num="1.4.0" />
                <vers num="1.4.1" />
                <vers num="1.5.0" />
                <vers num="1.5.3" />
                <vers num="1.5.4" />
                <vers num="1.5.5" />
                <vers num="1.5.6" />
                <vers num="1.5.7" />
                <vers num="1.5.8" />
                <vers num="1.6.0" />
                <vers num="1.6.1" />
                <vers num="1.6.2" />
                <vers num="1.6.3" />
                <vers num="1.6.4" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3820" seq="2009-3820" severity="High" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-28">
        <desc>
            <descript source="cve">SQL injection vulnerability in the Flagbit Filebase (fb_filebase) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/</ref>
        </refs>
        <vuln_soft>
            <prod vendor="flagbit" name="fb_filebase">
                <vers num="0.1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3821" seq="2009-3821" severity="Medium" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-28">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/</ref>
        </refs>
        <vuln_soft>
            <prod vendor="apache" name="solr">
                <vers num="1.0.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3822" seq="2009-3822" severity="High" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-28">
        <desc>
            <descript source="cve">PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter to tests/ajcuser.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/2968" adv="1">ADV-2009-2968</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36731">36731</ref>
            <ref source="MISC" url="http://www.packetstormsecurity.org/0910-exploits/joomlaajaxchat-rfi.txt">http://www.packetstormsecurity.org/0910-exploits/joomlaajaxchat-rfi.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37087" adv="1">37087</ref>
        </refs>
        <vuln_soft>
            <prod vendor="fijiwebdesign" name="com_ajaxchat">
                <vers num="1.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3823" seq="2009-3823" severity="Medium" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-28">
        <desc>
            <descript source="cve">Directory traversal vulnerability in myhtml.php in Mobilelib GOLD 3.0, when magic_quotes_gpc is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the GLOBALS[page] parameter.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/51713">mobilelib-myhtml-file-include(51713)</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9144">9144</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ac4p" name="mobilelib_gold">
                <vers num="3.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3824" seq="2009-3824" severity="High" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-29">
        <desc>
            <descript source="cve">Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content_path parameter.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/51737">greenwood-processor-file-include(51737)</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9156">9156</ref>
        </refs>
        <vuln_soft>
            <prod vendor="michael_j_greenwood" name="php_content_manager">
                <vers num="0.3.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3825" seq="2009-3825" severity="High" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-28">
        <desc>
            <descript source="cve">Multiple directory traversal vulnerabilities in GenCMS 2006 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p parameter to show.php and the (2) Template parameter to admin/pages/SiteNew.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/51653">gencms-show-file-include(51653)</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9103">9103</ref>
        </refs>
        <vuln_soft>
            <prod vendor="thomas_graber" name="gencms">
                <vers num="2006" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" name="CVE-2009-3639" seq="2009-3639" severity="Medium" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="5.8" modified="2009-10-29">
        <desc>
            <descript source="cve">The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</descript>
        </desc>
        <loss_types>
            <avail />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.redhat.com/show_bug.cgi?id=530719">https://bugzilla.redhat.com/show_bug.cgi?id=530719</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36804">36804</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53936">proftpd-modtls-security-bypass(53936)</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:288">MDVSA-2009:288</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37131" adv="1">37131</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125632960508211&amp;w=2">[oss-security] 20091023 Re: proftpd - mod_tls - Improper SSL/TLS certificate subjectAltName verification</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125630966510672&amp;w=2">[oss-security] 20091023 proftpd - mod_tls - Improper SSL/TLS certificate subjectAltName verification</ref>
            <ref source="CONFIRM" url="http://bugs.proftpd.org/show_bug.cgi?id=3275">http://bugs.proftpd.org/show_bug.cgi?id=3275</ref>
        </refs>
        <vuln_soft>
            <prod vendor="proftpd" name="proftpd">
                <vers num="1.3.1" />
                <vers edition="a" num="1.3.2" prev="1" />
                <vers edition="rc1" num="1.3.2" prev="1" />
                <vers edition="rc2" num="1.3.2" prev="1" />
                <vers edition="rc4" num="1.3.2" prev="1" />
                <vers edition="rc1" num="1.3.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3641" seq="2009-3641" severity="Medium" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-29">
        <desc>
            <descript source="cve">Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packet that uses the (1) TCP or (2) ICMP protocol.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36795">36795</ref>
            <ref source="CONFIRM" patch="1" url="http://vrt-sourcefire.blogspot.com/2009/10/snort-2851-release.html">http://vrt-sourcefire.blogspot.com/2009/10/snort-2851-release.html</ref>
            <ref source="FULLDISC" patch="1" url="http://seclists.org/fulldisclosure/2009/Oct/299">20091022 Snort &lt;= 2.8.5 IPV6 Remote DoS</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=530863">https://bugzilla.redhat.com/show_bug.cgi?id=530863</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53912">snort-ipv6-dos(53912)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3014" adv="1">ADV-2009-3014</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/59159">59159</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/10/25/5">[oss-security] 20091025 SANS: Security Thought LeadersRe: CVE Request -- Snort - 2.8.5.1</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023076">1023076</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37135" adv="1">37135</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125649553414700&amp;w=2">[oss-security] 20091025 CVE Request -- Snort - 2.8.5.1</ref>
            <ref source="CONFIRM" url="http://dl.snort.org/snort-current/release_notes_2851.txt" adv="1">http://dl.snort.org/snort-current/release_notes_2851.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="snort" name="snort">
                <vers num="1.6" />
                <vers num="1.8.0" />
                <vers num="1.8.1" />
                <vers num="1.8.2" />
                <vers num="1.8.3" />
                <vers num="1.8.4" />
                <vers num="1.8.5" />
                <vers num="1.8.6" />
                <vers num="1.8.7" />
                <vers num="1.9.0" />
                <vers num="1.9.1" />
                <vers edition="beta" num="2.0" />
                <vers edition="rc1" num="2.0" />
                <vers num="2.6.1" />
                <vers num="2.6.1.1" />
                <vers num="2.6.1.2" />
                <vers num="2.6.2" />
                <vers num="2.7_beta1" />
                <vers num="2.8.0" />
                <vers num="2.8.2.2" />
                <vers num="2.8.3" />
                <vers num="2.8.3.1" />
                <vers num="2.8.3.2" />
                <vers num="2.8.3.4" />
                <vers num="2.8.3.4.1" />
                <vers num="2.8.3.5" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3700" seq="2009-3700" severity="Medium" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-29">
        <desc>
            <descript source="cve">Buffer overflow in sgLog.c in squidGuard 1.3 and 1.4 allows remote attackers to cause a denial of service (application hang or loss of blocking functionality) via a long URL with many / (slash) characters, related to "emergency mode."</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3013" adv="1">ADV-2009-3013</ref>
            <ref source="CONFIRM" patch="1" url="http://www.squidguard.org/Downloads/Patches/1.4/Readme.Patch-20091015" adv="1">http://www.squidguard.org/Downloads/Patches/1.4/Readme.Patch-20091015</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36800">36800</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53921">squidguard-sglog-security-bypass(53921)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507440/100/0/threaded">20091026 squidGuard 1.3 &amp; 1.4 : buffer overflow</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/59163">59163</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023079">1023079</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37107" adv="1">37107</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squidguard" name="squidguard">
                <vers num="1.3" />
                <vers num="1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3826" seq="2009-3826" severity="Medium" type="CVE" published="2009-10-28" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-29">
        <desc>
            <descript source="cve">Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in Squid and (2) a redirect URL that contains information about the originally requested URL.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3013" adv="1">ADV-2009-3013</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36800">36800</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53922">squidguard-url-security-bypass(53922)</ref>
            <ref source="CONFIRM" url="http://www.squidguard.org/Downloads/Patches/1.4/Readme.Patch-20091019" adv="1">http://www.squidguard.org/Downloads/Patches/1.4/Readme.Patch-20091019</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507440/100/0/threaded">20091026 squidGuard 1.3 &amp; 1.4 : buffer overflow</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/59164">59164</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023079">1023079</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37107" adv="1">37107</ref>
        </refs>
        <vuln_soft>
            <prod vendor="squidguard" name="squidguard">
                <vers num="1.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-1563" seq="2009-1563" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-29">
        <desc>
            <descript source="cve">Array index error in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows remote attackers to execute arbitrary code via a long string that triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-59.html">http://www.mozilla.org/security/announce/2009/mfsa2009-59.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=516862">https://bugzilla.mozilla.org/show_bug.cgi?id=516862</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=516396">https://bugzilla.mozilla.org/show_bug.cgi?id=516396</ref>
            <ref source="MISC" url="http://secunia.com/secunia_research/2009-35/" adv="1">http://secunia.com/secunia_research/2009-35/</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers edition="beta5" num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.10" />
                <vers num="3.0.11" />
                <vers num="3.0.12" />
                <vers num="3.0.13" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.6" />
                <vers num="3.0.7" />
                <vers num="3.0.8" />
                <vers num="3.0.9" />
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3370" seq="2009-3370" severity="Medium" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-30">
        <desc>
            <descript source="cve">Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-52.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-52.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=511615">https://bugzilla.mozilla.org/show_bug.cgi?id=511615</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers edition="alpha" num="3.0" />
                <vers edition="beta2" num="3.0" />
                <vers edition="beta5" num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.10" />
                <vers num="3.0.11" />
                <vers num="3.0.12" />
                <vers num="3.0.13" />
                <vers num="3.0.14" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.6" />
                <vers num="3.0.7" />
                <vers num="3.0.8" />
                <vers num="3.0.9" />
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3371" seq="2009-3371" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-29">
        <desc>
            <descript source="cve">Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-54.html">http://www.mozilla.org/security/announce/2009/mfsa2009-54.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=514554">https://bugzilla.mozilla.org/show_bug.cgi?id=514554</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
                <vers num="3.5.4" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3372" seq="2009-3372" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="9.3" modified="2009-10-29">
        <desc>
            <descript source="cve">Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-55.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-55.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=500644">https://bugzilla.mozilla.org/show_bug.cgi?id=500644</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers edition="beta5" num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.10" />
                <vers num="3.0.11" />
                <vers num="3.0.12" />
                <vers num="3.0.13" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.6" />
                <vers num="3.0.7" />
                <vers num="3.0.8" />
                <vers num="3.0.9" />
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
            <prod vendor="mozilla" name="seamonkey">
                <vers edition="alpha" num="1.0" />
                <vers edition="beta" num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.0.9" />
                <vers edition="" num="1.1" />
                <vers edition=":alpha" num="1.1" />
                <vers edition=":beta" num="1.1" />
                <vers edition="alpha" num="1.1" />
                <vers edition="beta" num="1.1" />
                <vers num="1.1.1" />
                <vers num="1.1.10" />
                <vers num="1.1.11" />
                <vers num="1.1.12" />
                <vers num="1.1.13" />
                <vers num="1.1.14" />
                <vers num="1.1.15" />
                <vers num="1.1.16" />
                <vers num="1.1.17" />
                <vers num="1.1.2" />
                <vers num="1.1.3" />
                <vers num="1.1.4" />
                <vers num="1.1.5" />
                <vers num="1.1.6" />
                <vers num="1.1.7" />
                <vers num="1.1.8" />
                <vers num="1.1.9" />
                <vers num="1.5.0.10" prev="1" />
                <vers num="1.5.0.8" />
                <vers num="1.5.0.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3373" seq="2009-3373" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-30">
        <desc>
            <descript source="cve">Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-56.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-56.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=511689">https://bugzilla.mozilla.org/show_bug.cgi?id=511689</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers edition="alpha" num="3.0" />
                <vers edition="beta2" num="3.0" />
                <vers edition="beta5" num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.10" />
                <vers num="3.0.11" />
                <vers num="3.0.12" />
                <vers num="3.0.13" />
                <vers num="3.0.14" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.6" />
                <vers num="3.0.7" />
                <vers num="3.0.8" />
                <vers num="3.0.9" />
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
            <prod vendor="mozilla" name="seamonkey">
                <vers edition="alpha" num="1.0" />
                <vers edition="beta" num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.0.9" />
                <vers edition="" num="1.1" />
                <vers edition=":alpha" num="1.1" />
                <vers edition=":beta" num="1.1" />
                <vers edition="alpha" num="1.1" />
                <vers edition="beta" num="1.1" />
                <vers num="1.1.1" />
                <vers num="1.1.10" />
                <vers num="1.1.11" />
                <vers num="1.1.12" />
                <vers num="1.1.13" />
                <vers num="1.1.14" />
                <vers num="1.1.15" />
                <vers num="1.1.16" />
                <vers num="1.1.17" />
                <vers num="1.1.2" />
                <vers num="1.1.3" />
                <vers num="1.1.4" />
                <vers num="1.1.5" />
                <vers num="1.1.6" />
                <vers num="1.1.7" />
                <vers num="1.1.8" />
                <vers num="1.1.9" />
                <vers num="1.5.0.10" prev="1" />
                <vers num="1.5.0.8" />
                <vers num="1.5.0.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3374" seq="2009-3374" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="7.5" modified="2009-10-30">
        <desc>
            <descript source="cve">The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-57.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-57.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=505988">https://bugzilla.mozilla.org/show_bug.cgi?id=505988</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers edition="beta5" num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.10" />
                <vers num="3.0.11" />
                <vers num="3.0.12" />
                <vers num="3.0.13" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.6" />
                <vers num="3.0.7" />
                <vers num="3.0.8" />
                <vers num="3.0.9" />
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3375" seq="2009-3375" severity="Medium" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-30">
        <desc>
            <descript source="cve">content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-61.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-61.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=503226">https://bugzilla.mozilla.org/show_bug.cgi?id=503226</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers edition="alpha" num="3.0" />
                <vers edition="beta2" num="3.0" />
                <vers edition="beta5" num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.10" />
                <vers num="3.0.11" />
                <vers num="3.0.12" />
                <vers num="3.0.13" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.6" />
                <vers num="3.0.7" />
                <vers num="3.0.8" />
                <vers num="3.0.9" />
                <vers num="3.5" />
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3376" seq="2009-3376" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="9.3" modified="2009-10-30">
        <desc>
            <descript source="cve">Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=511521">https://bugzilla.mozilla.org/show_bug.cgi?id=511521</ref>
            <ref source="CONFIRM" url="http://www.mozilla.org/security/announce/2009/mfsa2009-62.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-62.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers edition="beta5" num="3.0" />
                <vers num="3.0.1" />
                <vers num="3.0.10" />
                <vers num="3.0.11" />
                <vers num="3.0.12" />
                <vers num="3.0.13" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.6" />
                <vers num="3.0.7" />
                <vers num="3.0.8" />
                <vers num="3.0.9" />
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
            <prod vendor="mozilla" name="seamonkey">
                <vers edition="alpha" num="1.0" />
                <vers edition="beta" num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.0.9" />
                <vers edition="" num="1.1" />
                <vers edition=":alpha" num="1.1" />
                <vers edition=":beta" num="1.1" />
                <vers edition="alpha" num="1.1" />
                <vers edition="beta" num="1.1" />
                <vers num="1.1.1" />
                <vers num="1.1.10" />
                <vers num="1.1.11" />
                <vers num="1.1.12" />
                <vers num="1.1.13" />
                <vers num="1.1.14" />
                <vers num="1.1.15" />
                <vers num="1.1.16" />
                <vers num="1.1.17" />
                <vers num="1.1.2" />
                <vers num="1.1.3" />
                <vers num="1.1.4" />
                <vers num="1.1.5" />
                <vers num="1.1.6" />
                <vers num="1.1.7" />
                <vers num="1.1.8" />
                <vers num="1.1.9" />
                <vers num="1.5.0.10" prev="1" />
                <vers num="1.5.0.8" />
                <vers num="1.5.0.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3377" seq="2009-3377" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-30">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.mozilla.org/show_bug.cgi?id=512327">https://bugzilla.mozilla.org/show_bug.cgi?id=512327</ref>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-63.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-63.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=515376">https://bugzilla.mozilla.org/show_bug.cgi?id=515376</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="3.5" />
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3378" seq="2009-3378" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="9.3" modified="2009-10-30">
        <desc>
            <descript source="cve">The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the first frame, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a crafted .ogg video file.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-63.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-63.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=500311">https://bugzilla.mozilla.org/show_bug.cgi?id=500311</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3379" seq="2009-3379" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-30">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.  NOTE: this might overlap CVE-2009-2663.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://bugzilla.mozilla.org/show_bug.cgi?id=500254">https://bugzilla.mozilla.org/show_bug.cgi?id=500254</ref>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-63.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-63.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=515889">https://bugzilla.mozilla.org/show_bug.cgi?id=515889</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=507167">https://bugzilla.mozilla.org/show_bug.cgi?id=507167</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=501279">https://bugzilla.mozilla.org/show_bug.cgi?id=501279</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=499512">https://bugzilla.mozilla.org/show_bug.cgi?id=499512</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3380" seq="2009-3380" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-30">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-64.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-64.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=522030">https://bugzilla.mozilla.org/show_bug.cgi?id=522030</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=514776">https://bugzilla.mozilla.org/show_bug.cgi?id=514776</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=509602">https://bugzilla.mozilla.org/show_bug.cgi?id=509602</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=509244">https://bugzilla.mozilla.org/show_bug.cgi?id=509244</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=508927">https://bugzilla.mozilla.org/show_bug.cgi?id=508927</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=497013">https://bugzilla.mozilla.org/show_bug.cgi?id=497013</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=489925">https://bugzilla.mozilla.org/show_bug.cgi?id=489925</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=454872">https://bugzilla.mozilla.org/show_bug.cgi?id=454872</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="3.0.1" />
                <vers num="3.0.10" />
                <vers num="3.0.11" />
                <vers num="3.0.12" />
                <vers num="3.0.13" />
                <vers num="3.0.14" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.6" />
                <vers num="3.0.7" />
                <vers num="3.0.8" />
                <vers num="3.0.9" />
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3381" seq="2009-3381" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-30">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-64.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-64.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=516709">https://bugzilla.mozilla.org/show_bug.cgi?id=516709</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=513394">https://bugzilla.mozilla.org/show_bug.cgi?id=513394</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=508057">https://bugzilla.mozilla.org/show_bug.cgi?id=508057</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=503196">https://bugzilla.mozilla.org/show_bug.cgi?id=503196</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=502168">https://bugzilla.mozilla.org/show_bug.cgi?id=502168</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3382" seq="2009-3382" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-30">
        <desc>
            <descript source="cve">layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.mozilla.org/security/announce/2009/mfsa2009-64.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-64.html</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=514960">https://bugzilla.mozilla.org/show_bug.cgi?id=514960</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="3.0.1" />
                <vers num="3.0.10" />
                <vers num="3.0.11" />
                <vers num="3.0.12" />
                <vers num="3.0.13" />
                <vers num="3.0.14" />
                <vers num="3.0.2" />
                <vers num="3.0.3" />
                <vers num="3.0.4" />
                <vers num="3.0.5" />
                <vers num="3.0.6" />
                <vers num="3.0.7" />
                <vers num="3.0.8" />
                <vers num="3.0.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3383" seq="2009-3383" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="10.0" modified="2009-10-30">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=518675">https://bugzilla.mozilla.org/show_bug.cgi?id=518675</ref>
            <ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=510987">https://bugzilla.mozilla.org/show_bug.cgi?id=510987</ref>
            <ref source="CONFIRM" url="http://www.mozilla.org/security/announce/2009/mfsa2009-64.html" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-64.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mozilla" name="firefox">
                <vers num="3.5.1" />
                <vers num="3.5.2" />
                <vers num="3.5.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3626" seq="2009-3626" severity="Medium" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="5.0" modified="2009-10-30">
        <desc>
            <descript source="cve">Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-expression match.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3023" adv="1">ADV-2009-3023</ref>
            <ref source="CONFIRM" patch="1" url="http://perl5.git.perl.org/perl.git/commit/0abd0d78a73da1c4d13b1c700526b7e5d03b32d4">http://perl5.git.perl.org/perl.git/commit/0abd0d78a73da1c4d13b1c700526b7e5d03b32d4</ref>
            <ref source="CONFIRM" url="https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225">https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53939">perl-utf8-expressions-dos(53939)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36812">36812</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/59283">59283</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/10/23/8">[oss-security] 20091023 CVE-2009-3626 assigment notification - Perl - perl-5.10.1</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023077">1023077</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37144" adv="1">37144</ref>
            <ref source="MISC" url="http://rt.perl.org/rt3/Ticket/Attachment/617489/295383/">http://rt.perl.org/rt3/Ticket/Attachment/617489/295383/</ref>
            <ref source="CONFIRM" url="http://rt.perl.org/rt3/Public/Bug/Display.html?id=69973">http://rt.perl.org/rt3/Public/Bug/Display.html?id=69973</ref>
        </refs>
        <vuln_soft>
            <prod vendor="perl" name="perl">
                <vers num="5.10.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3627" seq="2009-3627" severity="Medium" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="4.3" modified="2009-10-30">
        <desc>
            <descript source="cve">The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225">https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3022" adv="1">ADV-2009-3022</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36807">36807</ref>
            <ref source="MLIST" patch="1" url="http://www.openwall.com/lists/oss-security/2009/10/23/9">[oss-security] 20091023 CVE-2009-3627 assignment notification - HTML-Parser-3.63</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=530604">https://bugzilla.redhat.com/show_bug.cgi?id=530604</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53941">htmlparser-decodeentities-dos(53941)</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37155" adv="1">37155</ref>
            <ref source="CONFIRM" url="http://github.com/gisle/html-parser/commit/b9aae1e43eb2c8e989510187cff0ba3e996f9a4c">http://github.com/gisle/html-parser/commit/b9aae1e43eb2c8e989510187cff0ba3e996f9a4c</ref>
        </refs>
        <vuln_soft>
            <prod vendor="derrick_oswald" name="html-parser">
                <vers num="1.00" />
                <vers num="1.1" />
                <vers num="1.2" />
                <vers num="1.3" />
                <vers num="1.4" />
                <vers num="1.41" />
                <vers num="1.42" />
                <vers num="1.5" />
                <vers num="1.6" />
                <vers num="3.54" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2009-3638" seq="2009-3638" severity="High" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="7.2" modified="2009-10-30">
        <desc>
            <descript source="cve">Integer overflow in the kvm_dev_ioctl_get_supported_cpuid function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.31.4 allows local users to have an unspecified impact via a KVM_GET_SUPPORTED_CPUID request to the kvm_arch_dev_ioctl function.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=530515">https://bugzilla.redhat.com/show_bug.cgi?id=530515</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53934">linux-kernel-supportedcpuid-code-execution(53934)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36803">36803</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc4">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc4</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.4">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.4</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125632898507373&amp;w=2">[oss-security] 20091023 Re: CVE request: kvm: integer overflow in kvm_dev_ioctl_get_supported_cpuid()</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125628917011048&amp;w=2">[oss-security] 20091023 CVE request: kvm: integer overflow in kvm_dev_ioctl_get_supported_cpuid()</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6a54435560efdab1a08f429a954df4d6c740bddf">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6a54435560efdab1a08f429a954df4d6c740bddf</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.24.7" />
                <vers num="2.6.25.15" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition=":pre-2" num="2.4.18" />
                <vers edition=":pre-3" num="2.4.18" />
                <vers edition=":pre-1" num="2.4.18" />
                <vers edition=":pre-7" num="2.4.18" />
                <vers edition=":pre-6" num="2.4.18" />
                <vers edition=":pre-5" num="2.4.18" />
                <vers edition=":pre-4" num="2.4.18" />
                <vers edition=":pre-8" num="2.4.18" />
                <vers edition="" num="2.4.19" />
                <vers edition=":-pre1" num="2.4.19" />
                <vers edition=":-pre2" num="2.4.19" />
                <vers edition=":-pre5" num="2.4.19" />
                <vers edition=":-pre6" num="2.4.19" />
                <vers edition=":-pre3" num="2.4.19" />
                <vers edition=":-pre4" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="" num="2.4.21" />
                <vers edition=":-pre1" num="2.4.21" />
                <vers edition=":-pre4" num="2.4.21" />
                <vers edition=":-pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="" num="2.4.23" />
                <vers edition=":-ow2" num="2.4.23" />
                <vers edition=":-pre9" num="2.4.23" />
                <vers edition="" num="2.4.24" />
                <vers edition=":-ow1" num="2.4.24" />
                <vers num="2.4.25" />
                <vers num="2.4.26" />
                <vers edition="" num="2.4.27" />
                <vers edition=":-pre1" num="2.4.27" />
                <vers edition=":-pre2" num="2.4.27" />
                <vers edition=":-pre3" num="2.4.27" />
                <vers edition=":-pre4" num="2.4.27" />
                <vers edition=":-pre5" num="2.4.27" />
                <vers num="2.4.28" />
                <vers edition="-rc1" num="2.4.29" />
                <vers edition="-rc2" num="2.4.29" />
                <vers num="2.4.3" />
                <vers edition="rc2" num="2.4.30" />
                <vers edition="rc3" num="2.4.30" />
                <vers num="2.4.31" />
                <vers num="2.4.32" />
                <vers num="2.4.33" />
                <vers num="2.4.33.1" />
                <vers num="2.4.33.2" />
                <vers num="2.4.33.3" />
                <vers num="2.4.33.4" />
                <vers num="2.4.33.5" />
                <vers num="2.4.33.7" />
                <vers num="2.4.34" />
                <vers num="2.4.34.1" />
                <vers num="2.4.34.2" />
                <vers num="2.4.34.3" />
                <vers num="2.4.34.4" />
                <vers num="2.4.34.5" />
                <vers num="2.4.34.6" />
                <vers num="2.4.35.1" />
                <vers num="2.4.35.2" />
                <vers num="2.4.35.3" />
                <vers num="2.4.35.4" />
                <vers num="2.4.35.5" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.4.36.7" />
                <vers num="2.4.36.8" />
                <vers num="2.4.36.9" />
                <vers edition="-rc1" num="2.4.37" />
                <vers num="2.4.37.1" />
                <vers num="2.4.37.2" />
                <vers num="2.4.37.3" />
                <vers num="2.4.37.4" />
                <vers num="2.4.37.5" />
                <vers num="2.4.37.6" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers num="2.6" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers edition="-rc1" num="2.6.16.31" />
                <vers edition="-rc2" num="2.6.16.31" />
                <vers edition="-rc3" num="2.6.16.31" />
                <vers edition="-rc4" num="2.6.16.31" />
                <vers edition="-rc5" num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.2.27.13" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers edition="rc1" num="2.6.23" />
                <vers edition="rc2" num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers edition="rc1" num="2.6.24" />
                <vers edition="rc2" num="2.6.24" />
                <vers edition="rc3" num="2.6.24" />
                <vers edition="rc4" num="2.6.24" />
                <vers edition="rc5" num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers edition="rc4" num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers edition="rc1" num="2.6.27" />
                <vers edition="rc2" num="2.6.27" />
                <vers edition="rc3" num="2.6.27" />
                <vers edition="rc4" num="2.6.27" />
                <vers edition="rc5" num="2.6.27" />
                <vers edition="rc6" num="2.6.27" />
                <vers edition="rc7" num="2.6.27" />
                <vers edition="rc8" num="2.6.27" />
                <vers edition="rc9" num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.13" />
                <vers num="2.6.27.14" />
                <vers num="2.6.27.15" />
                <vers num="2.6.27.16" />
                <vers num="2.6.27.17" />
                <vers num="2.6.27.18" />
                <vers num="2.6.27.19" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.20" />
                <vers num="2.6.27.21" />
                <vers num="2.6.27.22" />
                <vers num="2.6.27.23" />
                <vers num="2.6.27.24" />
                <vers num="2.6.27.25" />
                <vers num="2.6.27.26" />
                <vers num="2.6.27.27" />
                <vers num="2.6.27.28" />
                <vers num="2.6.27.29" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.30" />
                <vers num="2.6.27.31" />
                <vers num="2.6.27.32" />
                <vers num="2.6.27.33" />
                <vers num="2.6.27.34" />
                <vers num="2.6.27.35" />
                <vers num="2.6.27.36" />
                <vers num="2.6.27.37" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers edition="git7" num="2.6.28" />
                <vers edition="rc1" num="2.6.28" />
                <vers edition="rc2" num="2.6.28" />
                <vers edition="rc3" num="2.6.28" />
                <vers edition="rc4" num="2.6.28" />
                <vers edition="rc5" num="2.6.28" />
                <vers edition="rc6" num="2.6.28" />
                <vers edition="rc7" num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.10" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers edition="git1" num="2.6.29" />
                <vers edition="rc1" num="2.6.29" />
                <vers edition="rc2" num="2.6.29" />
                <vers edition="rc2_git7" num="2.6.29" />
                <vers edition="rc8-kk" num="2.6.29" />
                <vers num="2.6.29.1" />
                <vers num="2.6.29.2" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.4" />
                <vers num="2.6.29.5" />
                <vers num="2.6.29.6" />
                <vers num="2.6.29.rc1" />
                <vers num="2.6.29.rc2" />
                <vers num="2.6.3" />
                <vers edition="rc1" num="2.6.30" />
                <vers edition="rc2" num="2.6.30" />
                <vers edition="rc3" num="2.6.30" />
                <vers edition="rc4" num="2.6.30" />
                <vers edition="rc4:x86_32" num="2.6.30" />
                <vers edition="rc5" num="2.6.30" />
                <vers edition="rc6" num="2.6.30" />
                <vers edition="rc7-git6" num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.3" />
                <vers num="2.6.30.4" />
                <vers num="2.6.30.5" />
                <vers num="2.6.30.6" />
                <vers num="2.6.30.7" />
                <vers num="2.6.30.8" />
                <vers num="2.6.30.9" />
                <vers num="2.6.31" />
                <vers num="2.6.31.1" />
                <vers num="2.6.31.2" />
                <vers num="2.6.31.3" prev="1" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" name="CVE-2009-3640" seq="2009-3640" severity="Low" type="CVE" published="2009-10-29" CVSS_version="2.0" CVSS_score="2.1" modified="2009-10-30">
        <desc>
            <descript source="cve">The update_cr8_intercept function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc1 does not properly handle the absence of an Advanced Programmable Interrupt Controller (APIC), which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via a call to the kvm_vcpu_ioctl function.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53947">kernel-updatecr8intercept-dos(53947)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36805">36805</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc1</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125640417219385&amp;w=2">[oss-security] 20091024 Re: CVE request: kvm: update_cr8_intercept() NULL pointer dereference</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125626965020571&amp;w=2">[oss-security] 20091023 CVE request: kvm: update_cr8_intercept() NULL pointer dereference</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=88c808fd42b53a7e01a2ac3253ef31fef74cb5af">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=88c808fd42b53a7e01a2ac3253ef31fef74cb5af</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.24.7" />
                <vers num="2.6.25.15" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition=":pre-2" num="2.4.18" />
                <vers edition=":pre-3" num="2.4.18" />
                <vers edition=":pre-1" num="2.4.18" />
                <vers edition=":pre-7" num="2.4.18" />
                <vers edition=":pre-6" num="2.4.18" />
                <vers edition=":pre-5" num="2.4.18" />
                <vers edition=":pre-4" num="2.4.18" />
                <vers edition=":pre-8" num="2.4.18" />
                <vers edition="" num="2.4.19" />
                <vers edition=":-pre1" num="2.4.19" />
                <vers edition=":-pre2" num="2.4.19" />
                <vers edition=":-pre5" num="2.4.19" />
                <vers edition=":-pre6" num="2.4.19" />
                <vers edition=":-pre3" num="2.4.19" />
                <vers edition=":-pre4" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="" num="2.4.21" />
                <vers edition=":-pre1" num="2.4.21" />
                <vers edition=":-pre4" num="2.4.21" />
                <vers edition=":-pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="" num="2.4.23" />
                <vers edition=":-ow2" num="2.4.23" />
                <vers edition=":-pre9" num="2.4.23" />
                <vers edition="" num="2.4.24" />
                <vers edition=":-ow1" num="2.4.24" />
                <vers num="2.4.25" />
                <vers num="2.4.26" />
                <vers edition="" num="2.4.27" />
                <vers edition=":-pre1" num="2.4.27" />
                <vers edition=":-pre2" num="2.4.27" />
                <vers edition=":-pre3" num="2.4.27" />
                <vers edition=":-pre4" num="2.4.27" />
                <vers edition=":-pre5" num="2.4.27" />
                <vers num="2.4.28" />
                <vers edition="-rc1" num="2.4.29" />
                <vers edition="-rc2" num="2.4.29" />
                <vers num="2.4.3" />
                <vers edition="rc2" num="2.4.30" />
                <vers edition="rc3" num="2.4.30" />
                <vers num="2.4.31" />
                <vers num="2.4.32" />
                <vers num="2.4.33" />
                <vers num="2.4.33.1" />
                <vers num="2.4.33.2" />
                <vers num="2.4.33.3" />
                <vers num="2.4.33.4" />
                <vers num="2.4.33.5" />
                <vers num="2.4.33.7" />
                <vers num="2.4.34" />
                <vers num="2.4.34.1" />
                <vers num="2.4.34.2" />
                <vers num="2.4.34.3" />
                <vers num="2.4.34.4" />
                <vers num="2.4.34.5" />
                <vers num="2.4.34.6" />
                <vers num="2.4.35.1" />
                <vers num="2.4.35.2" />
                <vers num="2.4.35.3" />
                <vers num="2.4.35.4" />
                <vers num="2.4.35.5" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.4.36.7" />
                <vers num="2.4.36.8" />
                <vers num="2.4.36.9" />
                <vers edition="-rc1" num="2.4.37" />
                <vers num="2.4.37.1" />
                <vers num="2.4.37.2" />
                <vers num="2.4.37.3" />
                <vers num="2.4.37.4" />
                <vers num="2.4.37.5" />
                <vers num="2.4.37.6" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers num="2.6" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers edition="-rc1" num="2.6.16.31" />
                <vers edition="-rc2" num="2.6.16.31" />
                <vers edition="-rc3" num="2.6.16.31" />
                <vers edition="-rc4" num="2.6.16.31" />
                <vers edition="-rc5" num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.2.27.13" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers edition="rc1" num="2.6.23" />
                <vers edition="rc2" num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers edition="rc1" num="2.6.24" />
                <vers edition="rc2" num="2.6.24" />
                <vers edition="rc3" num="2.6.24" />
                <vers edition="rc4" num="2.6.24" />
                <vers edition="rc5" num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers edition="rc4" num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers edition="rc1" num="2.6.27" />
                <vers edition="rc2" num="2.6.27" />
                <vers edition="rc3" num="2.6.27" />
                <vers edition="rc4" num="2.6.27" />
                <vers edition="rc5" num="2.6.27" />
                <vers edition="rc6" num="2.6.27" />
                <vers edition="rc7" num="2.6.27" />
                <vers edition="rc8" num="2.6.27" />
                <vers edition="rc9" num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.13" />
                <vers num="2.6.27.14" />
                <vers num="2.6.27.15" />
                <vers num="2.6.27.16" />
                <vers num="2.6.27.17" />
                <vers num="2.6.27.18" />
                <vers num="2.6.27.19" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.20" />
                <vers num="2.6.27.21" />
                <vers num="2.6.27.22" />
                <vers num="2.6.27.23" />
                <vers num="2.6.27.24" />
                <vers num="2.6.27.25" />
                <vers num="2.6.27.26" />
                <vers num="2.6.27.27" />
                <vers num="2.6.27.28" />
                <vers num="2.6.27.29" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.30" />
                <vers num="2.6.27.31" />
                <vers num="2.6.27.32" />
                <vers num="2.6.27.33" />
                <vers num="2.6.27.34" />
                <vers num="2.6.27.35" />
                <vers num="2.6.27.36" />
                <vers num="2.6.27.37" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers edition="git7" num="2.6.28" />
                <vers edition="rc1" num="2.6.28" />
                <vers edition="rc2" num="2.6.28" />
                <vers edition="rc3" num="2.6.28" />
                <vers edition="rc4" num="2.6.28" />
                <vers edition="rc5" num="2.6.28" />
                <vers edition="rc6" num="2.6.28" />
                <vers edition="rc7" num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.10" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers edition="git1" num="2.6.29" />
                <vers edition="rc1" num="2.6.29" />
                <vers edition="rc2" num="2.6.29" />
                <vers edition="rc2_git7" num="2.6.29" />
                <vers edition="rc8-kk" num="2.6.29" />
                <vers num="2.6.29.1" />
                <vers num="2.6.29.2" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.4" />
                <vers num="2.6.29.5" />
                <vers num="2.6.29.6" />
                <vers num="2.6.29.rc1" />
                <vers num="2.6.29.rc2" />
                <vers num="2.6.3" />
                <vers edition="rc1" num="2.6.30" />
                <vers edition="rc2" num="2.6.30" />
                <vers edition="rc3" num="2.6.30" />
                <vers edition="rc4" num="2.6.30" />
                <vers edition="rc4:x86_32" num="2.6.30" />
                <vers edition="rc5" num="2.6.30" />
                <vers edition="rc6" num="2.6.30" />
                <vers edition="rc7-git6" num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.3" />
                <vers num="2.6.30.4" />
                <vers num="2.6.30.5" />
                <vers num="2.6.30.6" />
                <vers num="2.6.30.7" />
                <vers num="2.6.30.8" />
                <vers num="2.6.30.9" />
                <vers edition="rc1" num="2.6.31" prev="1" />
                <vers edition="rc2" num="2.6.31" prev="1" />
                <vers edition="rc3" num="2.6.31" prev="1" />
                <vers edition="rc4" num="2.6.31" prev="1" />
                <vers edition="rc5" num="2.6.31" prev="1" />
                <vers edition="rc7" num="2.6.31" prev="1" />
                <vers edition="rc8" num="2.6.31" prev="1" />
                <vers num="2.6.31.1" />
                <vers num="2.6.31.2" />
                <vers num="2.6.31.3" />
                <vers num="2.6.31.4" />
                <vers num="2.6.31.5" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3828" seq="2009-3828" severity="High" type="CVE" published="2009-10-30" CVSS_version="2.0" CVSS_score="7.5" modified="2009-11-02">
        <desc>
            <descript source="cve">The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via certain vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53909">everfocus-authentication-sec-bypass(53909)</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507373/100/100/threaded">20091022 Everfocus EDR1600 remote authentication bypass</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/59139">59139</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37108" adv="1">37108</ref>
            <ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2009/Oct/293">20091022 Everfocus EDR1600 remote authentication bypass</ref>
        </refs>
        <vuln_soft>
            <prod vendor="everfocus" name="edr1600_dvr">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3549" seq="2009-3549" severity="Medium" type="CVE" published="2009-10-30" CVSS_version="2.0" CVSS_score="5.0" modified="2009-11-02">
        <desc>
            <descript source="cve">packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html">http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3061" adv="1">ADV-2009-3061</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36846">36846</ref>
            <ref source="CONFIRM" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3689">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3689</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54016">wireshark-dissectpaltalk-dos(54016)</ref>
            <ref source="CONFIRM" url="http://www.wireshark.org/security/wnpa-sec-2009-07.html" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-07.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37175" adv="1">37175</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wireshark" name="wireshark">
                <vers num="1.2" />
                <vers num="1.2.0" />
                <vers num="1.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3550" seq="2009-3550" severity="Medium" type="CVE" published="2009-10-30" CVSS_version="2.0" CVSS_score="4.3" modified="2009-11-02">
        <desc>
            <descript source="cve">The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 and 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a file that records a malformed packet trace.  NOTE: some of these details are obtained from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html" adv="1">http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html</ref>
            <ref source="CONFIRM" patch="1" url="http://www.wireshark.org/docs/relnotes/wireshark-1.0.10.html" adv="1">http://www.wireshark.org/docs/relnotes/wireshark-1.0.10.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54017">wireshark-dcerpcnt-dos(54017)</ref>
            <ref source="CONFIRM" url="http://www.wireshark.org/security/wnpa-sec-2009-08.html" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-08.html</ref>
            <ref source="CONFIRM" url="http://www.wireshark.org/security/wnpa-sec-2009-07.html" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-07.html</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3061" adv="1">ADV-2009-3061</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36846">36846</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37175" adv="1">37175</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wireshark" name="wireshark">
                <vers num="0.10.10" />
                <vers num="0.10.11" />
                <vers num="0.10.12" />
                <vers num="0.10.13" />
                <vers num="0.10.14" />
                <vers num="0.10.2" />
                <vers num="0.10.3" />
                <vers num="0.10.4" />
                <vers num="0.10.5" />
                <vers num="0.10.6" />
                <vers num="0.10.7" />
                <vers num="0.10.8" />
                <vers num="0.10.9" />
                <vers num="1.0" />
                <vers num="1.0.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.0.9" />
                <vers num="1.2" />
                <vers num="1.2.0" />
                <vers num="1.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3551" seq="2009-3551" severity="Medium" type="CVE" published="2009-10-30" CVSS_version="2.0" CVSS_score="5.0" modified="2009-11-02">
        <desc>
            <descript source="cve">Off-by-one error in the dissect_negprot_response function in packet-smb.c in the SMB dissector in Wireshark 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.  NOTE: some of these details are obtained from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html">http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html</ref>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3061" adv="1">ADV-2009-3061</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36846">36846</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54018">wireshark-negprotresponse-dos(54018)</ref>
            <ref source="CONFIRM" url="http://www.wireshark.org/security/wnpa-sec-2009-07.html" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-07.html</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37175" adv="1">37175</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wireshark" name="wireshark">
                <vers num="1.2" />
                <vers num="1.2.0" />
                <vers num="1.2.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" name="CVE-2009-3623" seq="2009-3623" severity="High" type="CVE" published="2009-10-30" CVSS_version="2.0" CVSS_score="7.8" modified="2009-11-02">
        <desc>
            <descript source="cve">The lookup_cb_cred function in fs/nfsd/nfs4callback.c in the nfsd4 subsystem in the Linux kernel before 2.6.31.2 attempts to access a credentials cache even when a client specifies the AUTH_NULL authentication flavor, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an NFSv4 mount request.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=530269">https://bugzilla.redhat.com/show_bug.cgi?id=530269</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc1</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.2">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.2</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125624036516377&amp;w=2">[oss-security] 20091022 Re: CVE request: kernel: nfsd4: fix null dereference creating nfsv4 callback client</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125618753029631&amp;w=2">[oss-security] 20091022 CVE request: kernel: nfsd4: fix null dereference creating nfsv4 callback client</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=886e3b7fe6054230c89ae078a09565ed183ecc73">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=886e3b7fe6054230c89ae078a09565ed183ecc73</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=80fc015bdfe1f5b870c1e1ee02d78e709523fee7">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=80fc015bdfe1f5b870c1e1ee02d78e709523fee7</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.24.7" />
                <vers num="2.6.25.15" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition=":pre-2" num="2.4.18" />
                <vers edition=":pre-3" num="2.4.18" />
                <vers edition=":pre-1" num="2.4.18" />
                <vers edition=":pre-7" num="2.4.18" />
                <vers edition=":pre-6" num="2.4.18" />
                <vers edition=":pre-5" num="2.4.18" />
                <vers edition=":pre-4" num="2.4.18" />
                <vers edition=":pre-8" num="2.4.18" />
                <vers edition="" num="2.4.19" />
                <vers edition=":-pre1" num="2.4.19" />
                <vers edition=":-pre2" num="2.4.19" />
                <vers edition=":-pre5" num="2.4.19" />
                <vers edition=":-pre6" num="2.4.19" />
                <vers edition=":-pre3" num="2.4.19" />
                <vers edition=":-pre4" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="" num="2.4.21" />
                <vers edition=":-pre1" num="2.4.21" />
                <vers edition=":-pre4" num="2.4.21" />
                <vers edition=":-pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="" num="2.4.23" />
                <vers edition=":-ow2" num="2.4.23" />
                <vers edition=":-pre9" num="2.4.23" />
                <vers edition="" num="2.4.24" />
                <vers edition=":-ow1" num="2.4.24" />
                <vers num="2.4.25" />
                <vers num="2.4.26" />
                <vers edition="" num="2.4.27" />
                <vers edition=":-pre1" num="2.4.27" />
                <vers edition=":-pre2" num="2.4.27" />
                <vers edition=":-pre3" num="2.4.27" />
                <vers edition=":-pre4" num="2.4.27" />
                <vers edition=":-pre5" num="2.4.27" />
                <vers num="2.4.28" />
                <vers edition="-rc1" num="2.4.29" />
                <vers edition="-rc2" num="2.4.29" />
                <vers num="2.4.3" />
                <vers edition="rc2" num="2.4.30" />
                <vers edition="rc3" num="2.4.30" />
                <vers num="2.4.31" />
                <vers num="2.4.32" />
                <vers num="2.4.33" />
                <vers num="2.4.33.1" />
                <vers num="2.4.33.2" />
                <vers num="2.4.33.3" />
                <vers num="2.4.33.4" />
                <vers num="2.4.33.5" />
                <vers num="2.4.33.7" />
                <vers num="2.4.34" />
                <vers num="2.4.34.1" />
                <vers num="2.4.34.2" />
                <vers num="2.4.34.3" />
                <vers num="2.4.34.4" />
                <vers num="2.4.34.5" />
                <vers num="2.4.34.6" />
                <vers num="2.4.35.1" />
                <vers num="2.4.35.2" />
                <vers num="2.4.35.3" />
                <vers num="2.4.35.4" />
                <vers num="2.4.35.5" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.4.36.7" />
                <vers num="2.4.36.8" />
                <vers num="2.4.36.9" />
                <vers edition="-rc1" num="2.4.37" />
                <vers num="2.4.37.1" />
                <vers num="2.4.37.2" />
                <vers num="2.4.37.3" />
                <vers num="2.4.37.4" />
                <vers num="2.4.37.5" />
                <vers num="2.4.37.6" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers num="2.6" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers edition="-rc1" num="2.6.16.31" />
                <vers edition="-rc2" num="2.6.16.31" />
                <vers edition="-rc3" num="2.6.16.31" />
                <vers edition="-rc4" num="2.6.16.31" />
                <vers edition="-rc5" num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.2.27.13" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers edition="rc1" num="2.6.23" />
                <vers edition="rc2" num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers edition="rc1" num="2.6.24" />
                <vers edition="rc2" num="2.6.24" />
                <vers edition="rc3" num="2.6.24" />
                <vers edition="rc4" num="2.6.24" />
                <vers edition="rc5" num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers edition="rc4" num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers edition="rc1" num="2.6.27" />
                <vers edition="rc2" num="2.6.27" />
                <vers edition="rc3" num="2.6.27" />
                <vers edition="rc4" num="2.6.27" />
                <vers edition="rc5" num="2.6.27" />
                <vers edition="rc6" num="2.6.27" />
                <vers edition="rc7" num="2.6.27" />
                <vers edition="rc8" num="2.6.27" />
                <vers edition="rc9" num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.13" />
                <vers num="2.6.27.14" />
                <vers num="2.6.27.15" />
                <vers num="2.6.27.16" />
                <vers num="2.6.27.17" />
                <vers num="2.6.27.18" />
                <vers num="2.6.27.19" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.20" />
                <vers num="2.6.27.21" />
                <vers num="2.6.27.22" />
                <vers num="2.6.27.23" />
                <vers num="2.6.27.24" />
                <vers num="2.6.27.25" />
                <vers num="2.6.27.26" />
                <vers num="2.6.27.27" />
                <vers num="2.6.27.28" />
                <vers num="2.6.27.29" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.30" />
                <vers num="2.6.27.31" />
                <vers num="2.6.27.32" />
                <vers num="2.6.27.33" />
                <vers num="2.6.27.34" />
                <vers num="2.6.27.35" />
                <vers num="2.6.27.36" />
                <vers num="2.6.27.37" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers edition="git7" num="2.6.28" />
                <vers edition="rc1" num="2.6.28" />
                <vers edition="rc2" num="2.6.28" />
                <vers edition="rc3" num="2.6.28" />
                <vers edition="rc4" num="2.6.28" />
                <vers edition="rc5" num="2.6.28" />
                <vers edition="rc6" num="2.6.28" />
                <vers edition="rc7" num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.10" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers edition="git1" num="2.6.29" />
                <vers edition="rc1" num="2.6.29" />
                <vers edition="rc2" num="2.6.29" />
                <vers edition="rc2_git7" num="2.6.29" />
                <vers edition="rc8-kk" num="2.6.29" />
                <vers num="2.6.29.1" />
                <vers num="2.6.29.2" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.4" />
                <vers num="2.6.29.5" />
                <vers num="2.6.29.6" />
                <vers num="2.6.29.rc1" />
                <vers num="2.6.29.rc2" />
                <vers num="2.6.3" />
                <vers edition="rc1" num="2.6.30" />
                <vers edition="rc2" num="2.6.30" />
                <vers edition="rc3" num="2.6.30" />
                <vers edition="rc4" num="2.6.30" />
                <vers edition="rc4:x86_32" num="2.6.30" />
                <vers edition="rc5" num="2.6.30" />
                <vers edition="rc6" num="2.6.30" />
                <vers edition="rc7-git6" num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.3" />
                <vers num="2.6.30.4" />
                <vers num="2.6.30.5" />
                <vers num="2.6.30.6" />
                <vers num="2.6.30.7" />
                <vers num="2.6.30.8" />
                <vers num="2.6.30.9" />
                <vers num="2.6.31" />
                <vers num="2.6.31.1" prev="1" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" name="CVE-2009-3722" seq="2009-3722" severity="High" type="CVE" published="2009-10-30" CVSS_version="2.0" CVSS_score="7.8" modified="2009-11-02">
        <desc>
            <descript source="cve">The handle_dr function in arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 2.6.31.1 does not properly verify the Current Privilege Level (CPL) before accessing a debug register, which allows guest OS users to cause a denial of service (trap) on the host OS via a crafted application.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=531660">https://bugzilla.redhat.com/show_bug.cgi?id=531660</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc1</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.1</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.9">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.30.9</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125680666827148&amp;w=2">[oss-security] 20090929 Re: CVE request: kvm: check cpl before emulating debug register access</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125678631403558&amp;w=2">[oss-security] 20090929 CVE request: kvm: check cpl before emulating debug register access</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0a79b009525b160081d75cef5dbf45817956acf2">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0a79b009525b160081d75cef5dbf45817956acf2</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.24.7" />
                <vers num="2.6.25.15" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition=":pre-2" num="2.4.18" />
                <vers edition=":pre-3" num="2.4.18" />
                <vers edition=":pre-1" num="2.4.18" />
                <vers edition=":pre-7" num="2.4.18" />
                <vers edition=":pre-6" num="2.4.18" />
                <vers edition=":pre-5" num="2.4.18" />
                <vers edition=":pre-4" num="2.4.18" />
                <vers edition=":pre-8" num="2.4.18" />
                <vers edition="" num="2.4.19" />
                <vers edition=":-pre1" num="2.4.19" />
                <vers edition=":-pre2" num="2.4.19" />
                <vers edition=":-pre5" num="2.4.19" />
                <vers edition=":-pre6" num="2.4.19" />
                <vers edition=":-pre3" num="2.4.19" />
                <vers edition=":-pre4" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="" num="2.4.21" />
                <vers edition=":-pre1" num="2.4.21" />
                <vers edition=":-pre4" num="2.4.21" />
                <vers edition=":-pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="" num="2.4.23" />
                <vers edition=":-ow2" num="2.4.23" />
                <vers edition=":-pre9" num="2.4.23" />
                <vers edition="" num="2.4.24" />
                <vers edition=":-ow1" num="2.4.24" />
                <vers num="2.4.25" />
                <vers num="2.4.26" />
                <vers edition="" num="2.4.27" />
                <vers edition=":-pre1" num="2.4.27" />
                <vers edition=":-pre2" num="2.4.27" />
                <vers edition=":-pre3" num="2.4.27" />
                <vers edition=":-pre4" num="2.4.27" />
                <vers edition=":-pre5" num="2.4.27" />
                <vers num="2.4.28" />
                <vers edition="-rc1" num="2.4.29" />
                <vers edition="-rc2" num="2.4.29" />
                <vers num="2.4.3" />
                <vers edition="rc2" num="2.4.30" />
                <vers edition="rc3" num="2.4.30" />
                <vers num="2.4.31" />
                <vers num="2.4.32" />
                <vers num="2.4.33" />
                <vers num="2.4.33.1" />
                <vers num="2.4.33.2" />
                <vers num="2.4.33.3" />
                <vers num="2.4.33.4" />
                <vers num="2.4.33.5" />
                <vers num="2.4.33.7" />
                <vers num="2.4.34" />
                <vers num="2.4.34.1" />
                <vers num="2.4.34.2" />
                <vers num="2.4.34.3" />
                <vers num="2.4.34.4" />
                <vers num="2.4.34.5" />
                <vers num="2.4.34.6" />
                <vers num="2.4.35.1" />
                <vers num="2.4.35.2" />
                <vers num="2.4.35.3" />
                <vers num="2.4.35.4" />
                <vers num="2.4.35.5" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.4.36.7" />
                <vers num="2.4.36.8" />
                <vers num="2.4.36.9" />
                <vers edition="-rc1" num="2.4.37" />
                <vers num="2.4.37.1" />
                <vers num="2.4.37.2" />
                <vers num="2.4.37.3" />
                <vers num="2.4.37.4" />
                <vers num="2.4.37.5" />
                <vers num="2.4.37.6" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers num="2.6" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers edition="-rc1" num="2.6.16.31" />
                <vers edition="-rc2" num="2.6.16.31" />
                <vers edition="-rc3" num="2.6.16.31" />
                <vers edition="-rc4" num="2.6.16.31" />
                <vers edition="-rc5" num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.2.27.13" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers edition="rc1" num="2.6.23" />
                <vers edition="rc2" num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers edition="rc1" num="2.6.24" />
                <vers edition="rc2" num="2.6.24" />
                <vers edition="rc3" num="2.6.24" />
                <vers edition="rc4" num="2.6.24" />
                <vers edition="rc5" num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers edition="rc4" num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers edition="rc1" num="2.6.27" />
                <vers edition="rc2" num="2.6.27" />
                <vers edition="rc3" num="2.6.27" />
                <vers edition="rc4" num="2.6.27" />
                <vers edition="rc5" num="2.6.27" />
                <vers edition="rc6" num="2.6.27" />
                <vers edition="rc7" num="2.6.27" />
                <vers edition="rc8" num="2.6.27" />
                <vers edition="rc9" num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.13" />
                <vers num="2.6.27.14" />
                <vers num="2.6.27.15" />
                <vers num="2.6.27.16" />
                <vers num="2.6.27.17" />
                <vers num="2.6.27.18" />
                <vers num="2.6.27.19" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.20" />
                <vers num="2.6.27.21" />
                <vers num="2.6.27.22" />
                <vers num="2.6.27.23" />
                <vers num="2.6.27.24" />
                <vers num="2.6.27.25" />
                <vers num="2.6.27.26" />
                <vers num="2.6.27.27" />
                <vers num="2.6.27.28" />
                <vers num="2.6.27.29" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.30" />
                <vers num="2.6.27.31" />
                <vers num="2.6.27.32" />
                <vers num="2.6.27.33" />
                <vers num="2.6.27.34" />
                <vers num="2.6.27.35" />
                <vers num="2.6.27.36" />
                <vers num="2.6.27.37" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers edition="git7" num="2.6.28" />
                <vers edition="rc1" num="2.6.28" />
                <vers edition="rc2" num="2.6.28" />
                <vers edition="rc3" num="2.6.28" />
                <vers edition="rc4" num="2.6.28" />
                <vers edition="rc5" num="2.6.28" />
                <vers edition="rc6" num="2.6.28" />
                <vers edition="rc7" num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.10" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers edition="git1" num="2.6.29" />
                <vers edition="rc1" num="2.6.29" />
                <vers edition="rc2" num="2.6.29" />
                <vers edition="rc2_git7" num="2.6.29" />
                <vers edition="rc8-kk" num="2.6.29" />
                <vers num="2.6.29.1" />
                <vers num="2.6.29.2" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.4" />
                <vers num="2.6.29.5" />
                <vers num="2.6.29.6" />
                <vers num="2.6.29.rc1" />
                <vers num="2.6.29.rc2" />
                <vers num="2.6.3" />
                <vers edition="rc1" num="2.6.30" />
                <vers edition="rc2" num="2.6.30" />
                <vers edition="rc3" num="2.6.30" />
                <vers edition="rc4" num="2.6.30" />
                <vers edition="rc4:x86_32" num="2.6.30" />
                <vers edition="rc5" num="2.6.30" />
                <vers edition="rc6" num="2.6.30" />
                <vers edition="rc7-git6" num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.3" />
                <vers num="2.6.30.4" />
                <vers num="2.6.30.5" />
                <vers num="2.6.30.6" />
                <vers num="2.6.30.7" />
                <vers num="2.6.30.8" />
                <vers num="2.6.30.9" />
                <vers edition="rc1" num="2.6.31" prev="1" />
                <vers edition="rc2" num="2.6.31" prev="1" />
                <vers edition="rc3" num="2.6.31" prev="1" />
                <vers edition="rc4" num="2.6.31" prev="1" />
                <vers edition="rc5" num="2.6.31" prev="1" />
                <vers edition="rc6" num="2.6.31" prev="1" />
                <vers edition="rc7" num="2.6.31" prev="1" />
                <vers edition="rc8" num="2.6.31" prev="1" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3829" seq="2009-3829" severity="High" type="CVE" published="2009-10-30" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-02">
        <desc>
            <descript source="cve">Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CERT-VN" patch="1" url="http://www.kb.cert.org/vuls/id/676492">VU#676492</ref>
            <ref source="CONFIRM" patch="1" url="http://www.wireshark.org/docs/relnotes/wireshark-1.2.2.html" adv="1">http://www.wireshark.org/docs/relnotes/wireshark-1.2.2.html</ref>
            <ref source="CONFIRM" patch="1" url="http://anonsvn.wireshark.org/viewvc/trunk/wiretap/erf.c?view=markup&amp;pathrev=29364">http://anonsvn.wireshark.org/viewvc/trunk/wiretap/erf.c?view=markup&amp;pathrev=29364</ref>
            <ref source="CONFIRM" url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3849">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3849</ref>
        </refs>
        <vuln_soft>
            <prod vendor="wireshark" name="wireshark">
                <vers num="0.10" />
                <vers num="0.10.1" />
                <vers num="0.10.10" />
                <vers num="0.10.11" />
                <vers num="0.10.12" />
                <vers num="0.10.13" />
                <vers num="0.10.14" />
                <vers num="0.10.2" />
                <vers num="0.10.3" />
                <vers num="0.10.4" />
                <vers num="0.10.5" />
                <vers num="0.10.6" />
                <vers num="0.10.7" />
                <vers num="0.10.8" />
                <vers num="0.10.9" />
                <vers num="0.6" />
                <vers num="0.7.9" />
                <vers num="0.8.16" />
                <vers num="0.8.19" />
                <vers num="0.8.20" />
                <vers num="0.9.10" />
                <vers num="0.9.14" />
                <vers num="0.9.2" />
                <vers num="0.9.5" />
                <vers num="0.9.6" />
                <vers num="0.9.7" />
                <vers num="0.9.8" />
                <vers num="0.99" />
                <vers num="0.99.0" />
                <vers num="0.99.1" />
                <vers num="0.99.2" />
                <vers num="0.99.3" />
                <vers num="0.99.4" />
                <vers num="0.99.5" />
                <vers num="0.99.6" />
                <vers num="0.99.6a" />
                <vers num="0.99.7" />
                <vers num="0.99.8" />
                <vers num="0.99.9" />
                <vers num="1.0" />
                <vers num="1.0.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.0.9" />
                <vers num="1.2" />
                <vers num="1.2.0" />
                <vers num="1.2.1" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:N)" CVSS_base_score="0.0" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="0.0" name="CVE-2009-3830" seq="2009-3830" severity="Low" type="CVE" published="2009-10-30" CVSS_version="2.0" CVSS_score="0.0" modified="2009-11-02">
        <desc>
            <descript source="cve">The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.</descript>
        </desc>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53955">sharepoint-download-info-disclosure(53955)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36817">36817</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507419/100/0/threaded">20091026 SharePoint 2007 ASP.NET Source Code Disclosure</ref>
            <ref source="MSKB" url="http://support.microsoft.com/kb/976829" adv="1">976829</ref>
        </refs>
        <vuln_soft>
            <prod vendor="microsoft" name="office_sharepoint_server">
                <vers num="2007" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3831" seq="2009-3831" severity="High" type="CVE" published="2009-10-30" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-02">
        <desc>
            <descript source="cve">Opera before 10.01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted domain name.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54020">opera-domain-names-code-execution(54020)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3073" adv="1">ADV-2009-3073</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36850">36850</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/59357">59357</ref>
            <ref source="CONFIRM" url="http://www.opera.com/support/kb/view/938/" adv="1">http://www.opera.com/support/kb/view/938/</ref>
            <ref source="CONFIRM" url="http://www.opera.com/docs/changelogs/windows/1001/">http://www.opera.com/docs/changelogs/windows/1001/</ref>
            <ref source="CONFIRM" url="http://www.opera.com/docs/changelogs/unix/1001/">http://www.opera.com/docs/changelogs/unix/1001/</ref>
            <ref source="CONFIRM" url="http://www.opera.com/docs/changelogs/mac/1001/">http://www.opera.com/docs/changelogs/mac/1001/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37182" adv="1">37182</ref>
        </refs>
        <vuln_soft>
            <prod vendor="opera" name="opera">
                <vers num="10" />
                <vers num="5..10" />
                <vers edition="beta_2" num="5.0" />
                <vers edition="beta_3" num="5.0" />
                <vers edition="beta_4" num="5.0" />
                <vers edition="beta_5" num="5.0" />
                <vers edition="beta_6" num="5.0" />
                <vers edition="beta_7" num="5.0" />
                <vers edition="beta_8" num="5.0" />
                <vers num="5.02" />
                <vers num="5.1" />
                <vers num="5.10" />
                <vers num="5.11" />
                <vers num="5.12" />
                <vers num="5.2" />
                <vers num="5.3" />
                <vers num="5.4" />
                <vers num="5.5" />
                <vers num="5.6" />
                <vers num="5.7" />
                <vers num="5.8" />
                <vers num="5.9" />
                <vers edition="beta_1" num="6" />
                <vers edition="beta_1" num="6.0" />
                <vers edition="beta_2" num="6.0" />
                <vers edition="beta_3" num="6.0" />
                <vers num="6.01" />
                <vers num="6.02" />
                <vers num="6.03" />
                <vers num="6.04" />
                <vers num="6.05" />
                <vers num="6.06" />
                <vers num="6.1" />
                <vers num="6.11" />
                <vers num="6.12" />
                <vers edition="beta_1" num="7" />
                <vers edition="beta_1.2" num="7" />
                <vers edition="beta_1" num="7.0" />
                <vers edition="beta_1v2" num="7.0" />
                <vers edition="beta_2" num="7.0" />
                <vers num="7.01" />
                <vers num="7.02" />
                <vers num="7.03" />
                <vers num="7.10" />
                <vers num="7.11" />
                <vers edition="beta7" num="7.20" />
                <vers num="7.21" />
                <vers num="7.22" />
                <vers num="7.23" />
                <vers num="7.30" />
                <vers edition="beta_1" num="7.50" />
                <vers num="7.51" />
                <vers num="7.52" />
                <vers num="7.53" />
                <vers edition="update_1" num="7.54" />
                <vers edition="update_2" num="7.54" />
                <vers num="7.55" />
                <vers edition="beta_1" num="8.0" />
                <vers edition="beta_2" num="8.0" />
                <vers edition="beta_3" num="8.0" />
                <vers num="8.01" />
                <vers num="8.02" />
                <vers num="8.50" />
                <vers num="8.51" />
                <vers num="8.52" />
                <vers num="8.53" />
                <vers num="8.54" />
                <vers edition="beta_1" num="9.0" />
                <vers edition="beta_2" num="9.0" />
                <vers num="9.01" />
                <vers num="9.02" />
                <vers num="9.10" />
                <vers num="9.1tp" />
                <vers edition="beta_1" num="9.20" />
                <vers num="9.21" />
                <vers num="9.22" />
                <vers num="9.23" />
                <vers num="9.24" />
                <vers num="9.25" />
                <vers num="9.26" />
                <vers num="9.27" />
                <vers edition="beta_1" num="9.50" />
                <vers edition="beta_2" num="9.50" />
                <vers num="9.51" />
                <vers num="9.52" />
                <vers num="9.6" />
                <vers edition="beta_1" num="9.60" />
                <vers num="9.61" />
                <vers num="9.62" />
                <vers num="9.63" />
                <vers num="9.64" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3832" seq="2009-3832" severity="High" type="CVE" published="2009-10-30" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-02">
        <desc>
            <descript source="cve">Opera before 10.01 on Windows does not prevent use of Web fonts in rendering the product's own user interface, which allows remote attackers to spoof the address field via a crafted web site.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3073" adv="1">ADV-2009-3073</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36850">36850</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54022">opera-web-fonts-spoofing(54022)</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/59359">59359</ref>
            <ref source="CONFIRM" url="http://www.opera.com/support/kb/view/940/" adv="1">http://www.opera.com/support/kb/view/940/</ref>
            <ref source="CONFIRM" url="http://www.opera.com/docs/changelogs/windows/1001/">http://www.opera.com/docs/changelogs/windows/1001/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37182" adv="1">37182</ref>
        </refs>
        <vuln_soft>
            <prod vendor="opera" name="opera">
                <vers num="10" />
                <vers num="5..10" />
                <vers edition="beta_2" num="5.0" />
                <vers edition="beta_3" num="5.0" />
                <vers edition="beta_4" num="5.0" />
                <vers edition="beta_5" num="5.0" />
                <vers edition="beta_6" num="5.0" />
                <vers edition="beta_7" num="5.0" />
                <vers edition="beta_8" num="5.0" />
                <vers num="5.02" />
                <vers num="5.1" />
                <vers num="5.10" />
                <vers num="5.11" />
                <vers num="5.12" />
                <vers num="5.2" />
                <vers num="5.3" />
                <vers num="5.4" />
                <vers num="5.5" />
                <vers num="5.6" />
                <vers num="5.7" />
                <vers num="5.8" />
                <vers num="5.9" />
                <vers edition="beta_1" num="6" />
                <vers edition="beta_1" num="6.0" />
                <vers edition="beta_2" num="6.0" />
                <vers edition="beta_3" num="6.0" />
                <vers num="6.01" />
                <vers num="6.02" />
                <vers num="6.03" />
                <vers num="6.04" />
                <vers num="6.05" />
                <vers num="6.06" />
                <vers num="6.1" />
                <vers num="6.11" />
                <vers num="6.12" />
                <vers edition="beta_1" num="7" />
                <vers edition="beta_1.2" num="7" />
                <vers edition="beta_1" num="7.0" />
                <vers edition="beta_1v2" num="7.0" />
                <vers edition="beta_2" num="7.0" />
                <vers num="7.01" />
                <vers num="7.02" />
                <vers num="7.03" />
                <vers num="7.10" />
                <vers num="7.11" />
                <vers edition="beta7" num="7.20" />
                <vers num="7.21" />
                <vers num="7.22" />
                <vers num="7.23" />
                <vers num="7.30" />
                <vers edition="beta_1" num="7.50" />
                <vers num="7.51" />
                <vers num="7.52" />
                <vers num="7.53" />
                <vers edition="update_1" num="7.54" />
                <vers edition="update_2" num="7.54" />
                <vers num="7.55" />
                <vers edition="beta_1" num="8.0" />
                <vers edition="beta_2" num="8.0" />
                <vers edition="beta_3" num="8.0" />
                <vers num="8.01" />
                <vers num="8.02" />
                <vers num="8.50" />
                <vers num="8.51" />
                <vers num="8.52" />
                <vers num="8.53" />
                <vers num="8.54" />
                <vers edition="beta_1" num="9.0" />
                <vers edition="beta_2" num="9.0" />
                <vers num="9.01" />
                <vers num="9.02" />
                <vers num="9.10" />
                <vers num="9.1tp" />
                <vers edition="beta_1" num="9.20" />
                <vers num="9.21" />
                <vers num="9.22" />
                <vers num="9.23" />
                <vers num="9.24" />
                <vers num="9.25" />
                <vers num="9.26" />
                <vers num="9.27" />
                <vers edition="beta_1" num="9.50" />
                <vers edition="beta_2" num="9.50" />
                <vers num="9.51" />
                <vers num="9.52" />
                <vers num="9.6" />
                <vers edition="beta_1" num="9.60" />
                <vers num="9.61" />
                <vers num="9.62" />
                <vers num="9.63" />
                <vers num="9.64" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" name="CVE-2009-2267" seq="2009-2267" severity="Medium" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="6.9" modified="2009-11-03">
        <desc>
            <descript source="cve">VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is used, do not properly set the exception code upon a page fault (aka #PF) exception, which allows guest OS users to gain privileges on the guest OS by specifying a crafted value for the cs register.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <local />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.vmware.com/security/advisories/VMSA-2009-0015.html" adv="1">http://www.vmware.com/security/advisories/VMSA-2009-0015.html</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3062" adv="1">ADV-2009-3062</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36841">36841</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507539/100/0/threaded">20091027 Invalid #PF Exception Code in VMware can result in Guest Privilege Escalation</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507523/100/0/threaded">20091027 VMSA-2009-0015 VMware hosted products and ESX patches resolve two security issues</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023083">1023083</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023082">1023082</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37172" adv="1">37172</ref>
            <ref source="MLIST" url="http://lists.vmware.com/pipermail/security-announce/2009/000069.html">[security-announce] 20091027 VMSA-2009-0015 VMware hosted products and ESX patches resolve two security issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="vmware" name="ace">
                <vers num="2.5.0" />
                <vers num="2.5.1" />
                <vers num="2.5.2" />
            </prod>
            <prod vendor="vmware" name="esx">
                <vers num="2.5.5" />
                <vers num="3.0.3" />
                <vers num="3.5" />
                <vers num="4.0" />
            </prod>
            <prod vendor="vmware" name="esxi">
                <vers num="3.5" />
                <vers num="4.0" />
            </prod>
            <prod vendor="vmware" name="fusion">
                <vers num="2.0" />
                <vers num="2.0.1" />
                <vers num="2.0.2" />
                <vers num="2.0.3" />
                <vers num="2.0.4" />
                <vers num="2.0.5" />
            </prod>
            <prod vendor="vmware" name="player">
                <vers num="2.5.1" />
                <vers num="2.5.2" />
            </prod>
            <prod vendor="vmware" name="server">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.0.9" />
                <vers edition="rc2" num="2.0" />
                <vers num="2.0.1" />
            </prod>
            <prod vendor="vmware" name="workstation">
                <vers num="6.5.0" />
                <vers num="6.5.1" />
                <vers num="6.5.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3605" seq="2009-3605" severity="High" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="10.0" modified="2009-11-03">
        <desc>
            <descript source="cve">Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/.  NOTE: this may overlap CVE-2009-0791.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://launchpad.net/ubuntu/+archive/primary/+files/poppler_0.8.7-1ubuntu0.4.diff.gz">https://launchpad.net/ubuntu/+archive/primary/+files/poppler_0.8.7-1ubuntu0.4.diff.gz</ref>
            <ref source="CONFIRM" url="https://launchpad.net/ubuntu/+archive/primary/+files/poppler_0.10.5-1ubuntu2.4.diff.gz">https://launchpad.net/ubuntu/+archive/primary/+files/poppler_0.10.5-1ubuntu2.4.diff.gz</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=491840">https://bugzilla.redhat.com/show_bug.cgi?id=491840</ref>
            <ref source="CONFIRM" url="https://bugs.launchpad.net/bugs/cve/2009-3605">https://bugs.launchpad.net/bugs/cve/2009-3605</ref>
            <ref source="UBUNTU" url="http://www.ubuntu.com/usn/USN-850-1">USN-850-1</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37114" adv="1">37114</ref>
            <ref source="CONFIRM" url="http://cgit.freedesktop.org/poppler/poppler/commit/?id=9cf2325fb22f812b31858e519411f57747d39bd8">http://cgit.freedesktop.org/poppler/poppler/commit/?id=9cf2325fb22f812b31858e519411f57747d39bd8</ref>
            <ref source="CONFIRM" url="http://cgit.freedesktop.org/poppler/poppler/commit/?id=7b2d314a61fd0e12f47c62996cb49ec0d1ba747a">http://cgit.freedesktop.org/poppler/poppler/commit/?id=7b2d314a61fd0e12f47c62996cb49ec0d1ba747a</ref>
            <ref source="CONFIRM" url="http://cgit.freedesktop.org/poppler/poppler/commit/?id=284a92899602daa4a7f429e61849e794569310b5">http://cgit.freedesktop.org/poppler/poppler/commit/?id=284a92899602daa4a7f429e61849e794569310b5</ref>
        </refs>
        <vuln_soft>
            <prod vendor="poppler" name="poppler">
                <vers num="0.1" />
                <vers num="0.1.1" />
                <vers num="0.1.2" />
                <vers num="0.10.0" />
                <vers num="0.10.1" />
                <vers num="0.10.2" />
                <vers num="0.10.3" />
                <vers num="0.10.4" />
                <vers num="0.2.0" />
                <vers num="0.3.0" />
                <vers num="0.3.1" />
                <vers num="0.3.2" />
                <vers num="0.3.3" />
                <vers num="0.4.0" />
                <vers num="0.4.1" />
                <vers num="0.4.2" />
                <vers num="0.4.3" />
                <vers num="0.4.4" />
                <vers num="0.5.0" />
                <vers num="0.5.1" />
                <vers num="0.5.2" />
                <vers num="0.5.3" />
                <vers num="0.5.4" />
                <vers num="0.5.9" />
                <vers num="0.5.90" />
                <vers num="0.5.91" />
                <vers num="0.6.0" />
                <vers num="0.6.1" />
                <vers num="0.6.2" />
                <vers num="0.6.3" />
                <vers num="0.6.4" />
                <vers num="0.7.0" />
                <vers num="0.7.1" />
                <vers num="0.7.2" />
                <vers num="0.7.3" />
                <vers num="0.8.0" />
                <vers num="0.8.1" />
                <vers num="0.8.2" />
                <vers num="0.8.3" />
                <vers num="0.8.4" />
                <vers num="0.8.5" />
                <vers num="0.8.6" />
                <vers num="0.8.7" />
                <vers num="0.9.0" />
                <vers num="0.9.1" />
                <vers num="0.9.2" />
                <vers num="0.9.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" name="CVE-2009-3624" seq="2009-3624" severity="Medium" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="4.6" modified="2009-11-03">
        <desc>
            <descript source="cve">The get_instantiation_keyring function in security/keys/keyctl.c in the KEYS subsystem in the Linux kernel before 2.6.32-rc5 does not properly maintain the reference count of a keyring, which allows local users to gain privileges or cause a denial of service (OOPS) via vectors involving calls to this function without specifying a keyring by ID, as demonstrated by a series of keyctl request2 and keyctl list commands.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc5">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc5</ref>
            <ref source="MISC" url="http://twitter.com/spendergrsec/statuses/4916661870">http://twitter.com/spendergrsec/statuses/4916661870</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37086" adv="1">37086</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125624091417161&amp;w=2">[oss-security] 20091022 Re: CVE request: kernel: get_instantiation_keyring() should inc the keyring refcount in all cases</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125619420905341&amp;w=2">[oss-security] 20091022 CVE request: kernel: get_instantiation_keyring() should inc the keyring refcount in all cases</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=21279cfa107af07ef985539ac0de2152b9cba5f5">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=21279cfa107af07ef985539ac0de2152b9cba5f5</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.24.7" />
                <vers num="2.6.25.15" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition=":pre-2" num="2.4.18" />
                <vers edition=":pre-3" num="2.4.18" />
                <vers edition=":pre-1" num="2.4.18" />
                <vers edition=":pre-7" num="2.4.18" />
                <vers edition=":pre-6" num="2.4.18" />
                <vers edition=":pre-5" num="2.4.18" />
                <vers edition=":pre-4" num="2.4.18" />
                <vers edition=":pre-8" num="2.4.18" />
                <vers edition="" num="2.4.19" />
                <vers edition=":-pre1" num="2.4.19" />
                <vers edition=":-pre2" num="2.4.19" />
                <vers edition=":-pre5" num="2.4.19" />
                <vers edition=":-pre6" num="2.4.19" />
                <vers edition=":-pre3" num="2.4.19" />
                <vers edition=":-pre4" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="" num="2.4.21" />
                <vers edition=":-pre1" num="2.4.21" />
                <vers edition=":-pre4" num="2.4.21" />
                <vers edition=":-pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="" num="2.4.23" />
                <vers edition=":-ow2" num="2.4.23" />
                <vers edition=":-pre9" num="2.4.23" />
                <vers edition="" num="2.4.24" />
                <vers edition=":-ow1" num="2.4.24" />
                <vers num="2.4.25" />
                <vers num="2.4.26" />
                <vers edition="" num="2.4.27" />
                <vers edition=":-pre1" num="2.4.27" />
                <vers edition=":-pre2" num="2.4.27" />
                <vers edition=":-pre3" num="2.4.27" />
                <vers edition=":-pre4" num="2.4.27" />
                <vers edition=":-pre5" num="2.4.27" />
                <vers num="2.4.28" />
                <vers edition="-rc1" num="2.4.29" />
                <vers edition="-rc2" num="2.4.29" />
                <vers num="2.4.3" />
                <vers edition="rc2" num="2.4.30" />
                <vers edition="rc3" num="2.4.30" />
                <vers num="2.4.31" />
                <vers num="2.4.32" />
                <vers num="2.4.33" />
                <vers num="2.4.33.1" />
                <vers num="2.4.33.2" />
                <vers num="2.4.33.3" />
                <vers num="2.4.33.4" />
                <vers num="2.4.33.5" />
                <vers num="2.4.33.7" />
                <vers num="2.4.34" />
                <vers num="2.4.34.1" />
                <vers num="2.4.34.2" />
                <vers num="2.4.34.3" />
                <vers num="2.4.34.4" />
                <vers num="2.4.34.5" />
                <vers num="2.4.34.6" />
                <vers num="2.4.35.1" />
                <vers num="2.4.35.2" />
                <vers num="2.4.35.3" />
                <vers num="2.4.35.4" />
                <vers num="2.4.35.5" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.4.36.7" />
                <vers num="2.4.36.8" />
                <vers num="2.4.36.9" />
                <vers edition="-rc1" num="2.4.37" />
                <vers num="2.4.37.1" />
                <vers num="2.4.37.2" />
                <vers num="2.4.37.3" />
                <vers num="2.4.37.4" />
                <vers num="2.4.37.5" />
                <vers num="2.4.37.6" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers num="2.6" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers edition="-rc1" num="2.6.16.31" />
                <vers edition="-rc2" num="2.6.16.31" />
                <vers edition="-rc3" num="2.6.16.31" />
                <vers edition="-rc4" num="2.6.16.31" />
                <vers edition="-rc5" num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.2.27.13" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers edition="rc1" num="2.6.23" />
                <vers edition="rc2" num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers edition="rc1" num="2.6.24" />
                <vers edition="rc2" num="2.6.24" />
                <vers edition="rc3" num="2.6.24" />
                <vers edition="rc4" num="2.6.24" />
                <vers edition="rc5" num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers edition="rc4" num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers edition="rc1" num="2.6.27" />
                <vers edition="rc2" num="2.6.27" />
                <vers edition="rc3" num="2.6.27" />
                <vers edition="rc4" num="2.6.27" />
                <vers edition="rc5" num="2.6.27" />
                <vers edition="rc6" num="2.6.27" />
                <vers edition="rc7" num="2.6.27" />
                <vers edition="rc8" num="2.6.27" />
                <vers edition="rc9" num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.13" />
                <vers num="2.6.27.14" />
                <vers num="2.6.27.15" />
                <vers num="2.6.27.16" />
                <vers num="2.6.27.17" />
                <vers num="2.6.27.18" />
                <vers num="2.6.27.19" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.20" />
                <vers num="2.6.27.21" />
                <vers num="2.6.27.22" />
                <vers num="2.6.27.23" />
                <vers num="2.6.27.24" />
                <vers num="2.6.27.25" />
                <vers num="2.6.27.26" />
                <vers num="2.6.27.27" />
                <vers num="2.6.27.28" />
                <vers num="2.6.27.29" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.30" />
                <vers num="2.6.27.31" />
                <vers num="2.6.27.32" />
                <vers num="2.6.27.33" />
                <vers num="2.6.27.34" />
                <vers num="2.6.27.35" />
                <vers num="2.6.27.36" />
                <vers num="2.6.27.37" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers edition="git7" num="2.6.28" />
                <vers edition="rc1" num="2.6.28" />
                <vers edition="rc2" num="2.6.28" />
                <vers edition="rc3" num="2.6.28" />
                <vers edition="rc4" num="2.6.28" />
                <vers edition="rc5" num="2.6.28" />
                <vers edition="rc6" num="2.6.28" />
                <vers edition="rc7" num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.10" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers edition="git1" num="2.6.29" />
                <vers edition="rc1" num="2.6.29" />
                <vers edition="rc2" num="2.6.29" />
                <vers edition="rc2_git7" num="2.6.29" />
                <vers edition="rc8-kk" num="2.6.29" />
                <vers num="2.6.29.1" />
                <vers num="2.6.29.2" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.4" />
                <vers num="2.6.29.5" />
                <vers num="2.6.29.6" />
                <vers num="2.6.29.rc1" />
                <vers num="2.6.29.rc2" />
                <vers num="2.6.3" />
                <vers edition="rc1" num="2.6.30" />
                <vers edition="rc2" num="2.6.30" />
                <vers edition="rc3" num="2.6.30" />
                <vers edition="rc4" num="2.6.30" />
                <vers edition="rc4:x86_32" num="2.6.30" />
                <vers edition="rc5" num="2.6.30" />
                <vers edition="rc6" num="2.6.30" />
                <vers edition="rc7-git6" num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.3" />
                <vers num="2.6.30.4" />
                <vers num="2.6.30.5" />
                <vers num="2.6.30.6" />
                <vers num="2.6.30.7" />
                <vers num="2.6.30.8" />
                <vers num="2.6.30.9" />
                <vers edition="rc1" num="2.6.31" />
                <vers edition="rc2" num="2.6.31" />
                <vers edition="rc3" num="2.6.31" />
                <vers edition="rc4" num="2.6.31" />
                <vers edition="rc5" num="2.6.31" />
                <vers edition="rc7" num="2.6.31" />
                <vers edition="rc8" num="2.6.31" />
                <vers num="2.6.31.1" />
                <vers num="2.6.31.2" />
                <vers num="2.6.31.3" />
                <vers num="2.6.31.4" />
                <vers num="2.6.31.5" />
                <vers edition="rc1" num="2.6.32" prev="1" />
                <vers edition="rc3" num="2.6.32" prev="1" />
                <vers edition="rc4" num="2.6.32" prev="1" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" name="CVE-2009-3628" seq="2009-3628" severity="Medium" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="4.0" modified="2009-11-03">
        <desc>
            <descript source="cve">The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to determine an encryption key via crafted input to a tt_content form element.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36801">36801</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53917">typo3-ttcontent-info-disclosure(53917)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3009" adv="1">ADV-2009-3009</ref>
            <ref source="CONFIRM" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37122" adv="1">37122</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125632856206736&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
        </refs>
        <vuln_soft>
            <prod vendor="typo3" name="typo3">
                <vers num="0.1.2" />
                <vers num="1.0.14" />
                <vers num="1.1" />
                <vers num="1.1.09" />
                <vers num="1.1.1" />
                <vers num="1.1.10" />
                <vers num="1.2.0" />
                <vers num="1.3.0" />
                <vers num="1.3.2" />
                <vers num="3.0" />
                <vers num="3.3.x" />
                <vers num="3.5" />
                <vers num="3.5.x" />
                <vers num="3.6.x" />
                <vers num="3.7.0" />
                <vers num="3.7.1" />
                <vers num="3.7.x" />
                <vers num="3.8" />
                <vers num="3.8.x" />
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.10" />
                <vers num="4.0.11" />
                <vers num="4.0.12" prev="1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.4" />
                <vers num="4.0.5" />
                <vers num="4.0.6" />
                <vers num="4.0.7" />
                <vers num="4.0.8" />
                <vers num="4.0.9" />
                <vers edition="beta1" num="4.1.0" />
                <vers edition="rc1" num="4.1.0" />
                <vers num="4.1.1" />
                <vers num="4.1.10" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.1.6" />
                <vers num="4.1.7" />
                <vers num="4.1.8" />
                <vers num="4.1.9" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.2" />
                <vers num="4.2.3" />
                <vers num="4.2.4" />
                <vers num="4.2.5" />
                <vers num="4.2.6" />
                <vers num="4.2.7" />
                <vers num="4.2.8" />
                <vers num="4.2.9" />
                <vers edition="alpha1" num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" name="CVE-2009-3629" seq="2009-3629" severity="Low" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="3.5" modified="2009-11-03">
        <desc>
            <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53918">typo3-backend-xss(53918)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3009" adv="1">ADV-2009-3009</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36801">36801</ref>
            <ref source="CONFIRM" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37122" adv="1">37122</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125633199111438&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125632856206736&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
        </refs>
        <vuln_soft>
            <prod vendor="typo3" name="typo3">
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.10" />
                <vers num="4.0.11" />
                <vers num="4.0.12" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.4" />
                <vers num="4.0.5" />
                <vers num="4.0.6" />
                <vers num="4.0.7" />
                <vers num="4.0.8" />
                <vers num="4.0.9" />
                <vers edition="beta" num="4.1" />
                <vers edition="rc1" num="4.1" />
                <vers edition="beta1" num="4.1.0" />
                <vers edition="rc1" num="4.1.0" />
                <vers num="4.1.1" />
                <vers num="4.1.10" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.1.6" />
                <vers num="4.1.7" />
                <vers num="4.1.8" />
                <vers num="4.1.9" />
                <vers num="4.10" />
                <vers num="4.11" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.2" />
                <vers num="4.2.3" />
                <vers num="4.2.4" />
                <vers num="4.2.5" />
                <vers num="4.2.6" />
                <vers num="4.2.7" />
                <vers num="4.2.8" />
                <vers num="4.2.9" />
                <vers edition="alpha1" num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" name="CVE-2009-3630" seq="2009-3630" severity="Medium" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="4.0" modified="2009-11-03">
        <desc>
            <descript source="cve">The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to place arbitrary web sites in TYPO3 backend framesets via crafted parameters, related to a "frame hijacking" issue.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3009" adv="1">ADV-2009-3009</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36801">36801</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53920">typo3-url-hijacking(53920)</ref>
            <ref source="CONFIRM" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37122" adv="1">37122</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125632856206736&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
        </refs>
        <vuln_soft>
            <prod vendor="typo3" name="typo3">
                <vers num="0.1.2" />
                <vers num="1.0.14" />
                <vers num="1.1" />
                <vers num="1.1.09" />
                <vers num="1.1.1" />
                <vers num="1.1.10" />
                <vers num="1.2.0" />
                <vers num="1.3.0" />
                <vers num="1.3.2" />
                <vers num="3.0" />
                <vers num="3.3.x" />
                <vers num="3.5" />
                <vers num="3.5.x" />
                <vers num="3.6.x" />
                <vers num="3.7.0" />
                <vers num="3.7.1" />
                <vers num="3.7.x" />
                <vers num="3.8" />
                <vers num="3.8.x" />
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.10" />
                <vers num="4.0.11" />
                <vers num="4.0.12" prev="1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.4" />
                <vers num="4.0.5" />
                <vers num="4.0.6" />
                <vers num="4.0.7" />
                <vers num="4.0.8" />
                <vers num="4.0.9" />
                <vers edition="beta1" num="4.1.0" />
                <vers edition="rc1" num="4.1.0" />
                <vers num="4.1.1" />
                <vers num="4.1.10" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.1.6" />
                <vers num="4.1.7" />
                <vers num="4.1.8" />
                <vers num="4.1.9" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.2" />
                <vers num="4.2.3" />
                <vers num="4.2.4" />
                <vers num="4.2.5" />
                <vers num="4.2.6" />
                <vers num="4.2.7" />
                <vers num="4.2.8" />
                <vers num="4.2.9" />
                <vers edition="alpha1" num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_base_score="8.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="10.0" name="CVE-2009-3631" seq="2009-3631" severity="High" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="8.5" modified="2009-11-03">
        <desc>
            <descript source="cve">The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or ftp upload is enabled, allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3009" adv="1">ADV-2009-3009</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36801">36801</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53923">typo3-uploads-command-execution(53923)</ref>
            <ref source="CONFIRM" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37122" adv="1">37122</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125632856206736&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
        </refs>
        <vuln_soft>
            <prod vendor="typo3" name="typo3">
                <vers num="0.1.2" />
                <vers num="1.0.14" />
                <vers num="1.1" />
                <vers num="1.1.09" />
                <vers num="1.1.1" />
                <vers num="1.1.10" />
                <vers num="1.2.0" />
                <vers num="1.3.0" />
                <vers num="1.3.2" />
                <vers num="3.0" />
                <vers num="3.3.x" />
                <vers num="3.5" />
                <vers num="3.5.x" />
                <vers num="3.6.x" />
                <vers num="3.7.0" />
                <vers num="3.7.1" />
                <vers num="3.7.x" />
                <vers num="3.8" />
                <vers num="3.8.x" />
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.10" />
                <vers num="4.0.11" />
                <vers num="4.0.12" prev="1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.4" />
                <vers num="4.0.5" />
                <vers num="4.0.6" />
                <vers num="4.0.7" />
                <vers num="4.0.8" />
                <vers num="4.0.9" />
                <vers edition="beta1" num="4.1.0" />
                <vers edition="rc1" num="4.1.0" />
                <vers num="4.1.1" />
                <vers num="4.1.10" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.1.6" />
                <vers num="4.1.7" />
                <vers num="4.1.8" />
                <vers num="4.1.9" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.2" />
                <vers num="4.2.3" />
                <vers num="4.2.4" />
                <vers num="4.2.5" />
                <vers num="4.2.6" />
                <vers num="4.2.7" />
                <vers num="4.2.8" />
                <vers num="4.2.9" />
                <vers edition="alpha1" num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" name="CVE-2009-3632" seq="2009-3632" severity="Medium" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="6.5" modified="2009-11-03">
        <desc>
            <descript source="cve">SQL injection vulnerability in the traditional frontend editing feature in the Frontend Editing subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to execute arbitrary SQL commands via unspecified parameters.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53924">typo3-editing-sql-injection(53924)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3009" adv="1">ADV-2009-3009</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36801">36801</ref>
            <ref source="CONFIRM" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37122" adv="1">37122</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125632856206736&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
        </refs>
        <vuln_soft>
            <prod vendor="typo3" name="typo3">
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.10" />
                <vers num="4.0.11" />
                <vers num="4.0.12" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.4" />
                <vers num="4.0.5" />
                <vers num="4.0.6" />
                <vers num="4.0.7" />
                <vers num="4.0.8" />
                <vers num="4.0.9" />
                <vers edition="beta" num="4.1" />
                <vers edition="rc1" num="4.1" />
                <vers edition="beta1" num="4.1.0" />
                <vers edition="rc1" num="4.1.0" />
                <vers num="4.1.1" />
                <vers num="4.1.10" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.1.6" />
                <vers num="4.1.7" />
                <vers num="4.1.8" />
                <vers num="4.1.9" />
                <vers num="4.10" />
                <vers num="4.11" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.2" />
                <vers num="4.2.3" />
                <vers num="4.2.4" />
                <vers num="4.2.5" />
                <vers num="4.2.6" />
                <vers num="4.2.7" />
                <vers num="4.2.8" />
                <vers num="4.2.9" />
                <vers edition="alpha1" num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3633" seq="2009-3633" severity="Medium" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="4.3" modified="2009-11-03">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the sanitizing algorithm.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3009" adv="1">ADV-2009-3009</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36801">36801</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53925">typo3-t3libdivquotejsvalue-xss(53925)</ref>
            <ref source="CONFIRM" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37122" adv="1">37122</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125633199111438&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125632856206736&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
        </refs>
        <vuln_soft>
            <prod vendor="typo3" name="typo3">
                <vers num="0.1.2" />
                <vers num="1.0.14" />
                <vers num="1.1" />
                <vers num="1.1.09" />
                <vers num="1.1.1" />
                <vers num="1.1.10" />
                <vers num="1.2.0" />
                <vers num="1.3.0" />
                <vers num="1.3.2" />
                <vers num="3.0" />
                <vers num="3.3.x" />
                <vers num="3.5" />
                <vers num="3.5.x" />
                <vers num="3.6.x" />
                <vers num="3.7.0" />
                <vers num="3.7.1" />
                <vers num="3.7.x" />
                <vers num="3.8" />
                <vers num="3.8.x" />
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.10" />
                <vers num="4.0.11" />
                <vers num="4.0.12" prev="1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.4" />
                <vers num="4.0.5" />
                <vers num="4.0.6" />
                <vers num="4.0.7" />
                <vers num="4.0.8" />
                <vers num="4.0.9" />
                <vers edition="beta1" num="4.1.0" />
                <vers edition="rc1" num="4.1.0" />
                <vers num="4.1.1" />
                <vers num="4.1.10" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.1.6" />
                <vers num="4.1.7" />
                <vers num="4.1.8" />
                <vers num="4.1.9" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.2" />
                <vers num="4.2.3" />
                <vers num="4.2.4" />
                <vers num="4.2.5" />
                <vers num="4.2.6" />
                <vers num="4.2.7" />
                <vers num="4.2.8" />
                <vers num="4.2.9" />
                <vers edition="alpha1" num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3634" seq="2009-3634" severity="Medium" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="4.3" modified="2009-11-02">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the Frontend Login Box (aka felogin) subcomponent in TYPO3 4.2.0 through 4.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53926">typo3-login-xss(53926)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3009" adv="1">ADV-2009-3009</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36801">36801</ref>
            <ref source="CONFIRM" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37122" adv="1">37122</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125633199111438&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125632856206736&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
        </refs>
        <vuln_soft>
            <prod vendor="typo3" name="typo3">
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.2" />
                <vers num="4.2.4" />
                <vers num="4.2.5" />
                <vers num="4.2.6" />
            </prod>
            <prod vendor="typosphere" name="typo">
                <vers num="4.2.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3635" seq="2009-3635" severity="High" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="7.5" modified="2009-11-03">
        <desc>
            <descript source="cve">The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to gain access by using only the password's md5 hash as a credential.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36801">36801</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53928">typo3-installtool-auth-bypass(53928)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3009" adv="1">ADV-2009-3009</ref>
            <ref source="CONFIRM" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37122" adv="1">37122</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125632856206736&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
        </refs>
        <vuln_soft>
            <prod vendor="typo3" name="typo3">
                <vers num="0.1.2" />
                <vers num="1.0.14" />
                <vers num="1.1" />
                <vers num="1.1.09" />
                <vers num="1.1.1" />
                <vers num="1.1.10" />
                <vers num="1.2.0" />
                <vers num="1.3.0" />
                <vers num="1.3.2" />
                <vers num="3.0" />
                <vers num="3.3.x" />
                <vers num="3.5" />
                <vers num="3.5.x" />
                <vers num="3.6.x" />
                <vers num="3.7.0" />
                <vers num="3.7.1" />
                <vers num="3.7.x" />
                <vers num="3.8" />
                <vers num="3.8.x" />
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.10" />
                <vers num="4.0.11" />
                <vers num="4.0.12" prev="1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.4" />
                <vers num="4.0.5" />
                <vers num="4.0.6" />
                <vers num="4.0.7" />
                <vers num="4.0.8" />
                <vers num="4.0.9" />
                <vers edition="beta1" num="4.1.0" />
                <vers edition="rc1" num="4.1.0" />
                <vers num="4.1.1" />
                <vers num="4.1.10" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.1.6" />
                <vers num="4.1.7" />
                <vers num="4.1.8" />
                <vers num="4.1.9" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.2" />
                <vers num="4.2.3" />
                <vers num="4.2.4" />
                <vers num="4.2.5" />
                <vers num="4.2.6" />
                <vers num="4.2.7" />
                <vers num="4.2.8" />
                <vers num="4.2.9" />
                <vers edition="alpha1" num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3636" seq="2009-3636" severity="Medium" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="4.3" modified="2009-11-03">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3009" adv="1">ADV-2009-3009</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36801">36801</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53929">typo3-installtool-xss(53929)</ref>
            <ref source="CONFIRM" url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37122" adv="1">37122</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125633199111438&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125632856206736&amp;w=2">[oss-security] 20091023 Re: CVE id request: typo3</ref>
        </refs>
        <vuln_soft>
            <prod vendor="typo3" name="typo3">
                <vers num="0.1.2" />
                <vers num="1.0.14" />
                <vers num="1.1" />
                <vers num="1.1.09" />
                <vers num="1.1.1" />
                <vers num="1.1.10" />
                <vers num="1.2.0" />
                <vers num="1.3.0" />
                <vers num="1.3.2" />
                <vers num="3.0" />
                <vers num="3.3.x" />
                <vers num="3.5" />
                <vers num="3.5.x" />
                <vers num="3.6.x" />
                <vers num="3.7.0" />
                <vers num="3.7.1" />
                <vers num="3.7.x" />
                <vers num="3.8" />
                <vers num="3.8.x" />
                <vers num="4.0" />
                <vers num="4.0.1" />
                <vers num="4.0.10" />
                <vers num="4.0.11" />
                <vers num="4.0.12" prev="1" />
                <vers num="4.0.2" />
                <vers num="4.0.3" />
                <vers num="4.0.4" />
                <vers num="4.0.5" />
                <vers num="4.0.6" />
                <vers num="4.0.7" />
                <vers num="4.0.8" />
                <vers num="4.0.9" />
                <vers edition="beta1" num="4.1.0" />
                <vers edition="rc1" num="4.1.0" />
                <vers num="4.1.1" />
                <vers num="4.1.10" />
                <vers num="4.1.11" />
                <vers num="4.1.12" />
                <vers num="4.1.2" />
                <vers num="4.1.3" />
                <vers num="4.1.4" />
                <vers num="4.1.5" />
                <vers num="4.1.6" />
                <vers num="4.1.7" />
                <vers num="4.1.8" />
                <vers num="4.1.9" />
                <vers num="4.2.0" />
                <vers num="4.2.1" />
                <vers num="4.2.2" />
                <vers num="4.2.3" />
                <vers num="4.2.4" />
                <vers num="4.2.5" />
                <vers num="4.2.6" />
                <vers num="4.2.7" />
                <vers num="4.2.8" />
                <vers num="4.2.9" />
                <vers edition="alpha1" num="4.3" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3733" seq="2009-3733" severity="Medium" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="4.3" modified="2009-11-03">
        <desc>
            <descript source="cve">Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <conf />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3062" adv="1">ADV-2009-3062</ref>
            <ref source="CONFIRM" url="http://www.vmware.com/security/advisories/VMSA-2009-0015.html" adv="1">http://www.vmware.com/security/advisories/VMSA-2009-0015.html</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36842">36842</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507523/100/0/threaded">20091027 VMSA-2009-0015 VMware hosted products and ESX patches resolve two security issues</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023089">1023089</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023088">1023088</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37186" adv="1">37186</ref>
            <ref source="MLIST" url="http://lists.vmware.com/pipermail/security-announce/2009/000069.html" adv="1">[security-announce] 20091027 VMSA-2009-0015 VMware hosted products and ESX patches resolve two security issues</ref>
        </refs>
        <vuln_soft>
            <prod vendor="vmware" name="esx">
                <vers num="3.0.3" />
                <vers num="3.5" />
            </prod>
            <prod vendor="vmware" name="esxi">
                <vers num="3.5" />
            </prod>
            <prod vendor="vmware" name="server">
                <vers num="1.0" />
                <vers num="1.0.1" />
                <vers num="1.0.1_build_29996" />
                <vers num="1.0.2" />
                <vers num="1.0.3" />
                <vers num="1.0.4" />
                <vers num="1.0.4_build_56528" />
                <vers num="1.0.5" />
                <vers num="1.0.6" />
                <vers num="1.0.7" />
                <vers num="1.0.8" />
                <vers num="1.0.9" />
                <vers edition="rc2" num="2.0" />
                <vers num="2.0.0" />
                <vers num="2.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3833" seq="2009-3833" severity="Medium" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="4.3" modified="2009-11-02">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the album parameter.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37156" adv="1">37156</ref>
            <ref source="MISC" url="http://packetstormsecurity.org/0910-exploits/tftgallery-xss.txt">http://packetstormsecurity.org/0910-exploits/tftgallery-xss.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="tftgallery" name="tftgallery">
                <vers num="0.13" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3834" seq="2009-3834" severity="High" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="7.5" modified="2009-11-02">
        <desc>
            <descript source="cve">SQL injection vulnerability in the Photoblog (com_photoblog) component alpha 3 and alpha 3a for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in a blogs action to index.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53943">photoblog-index-sql-injection(53943)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36809">36809</ref>
            <ref source="MISC" url="http://packetstormsecurity.org/0910-exploits/joomlaphotoblog-sql.txt">http://packetstormsecurity.org/0910-exploits/joomlaphotoblog-sql.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="webguerilla" name="com_photoblog">
                <vers num="3" />
                <vers num="3a" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3835" seq="2009-3835" severity="High" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="7.5" modified="2009-11-02">
        <desc>
            <descript source="cve">SQL injection vulnerability in the JShop (com_jshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53944">jshop-pid-sql-injection(53944)</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36808">36808</ref>
            <ref source="MISC" url="http://www.packetstormsecurity.org/0910-exploits/joomlajshop-sql.txt">http://www.packetstormsecurity.org/0910-exploits/joomlajshop-sql.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="whorl_ltd" name="jshop">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3836" seq="2009-3836" severity="Medium" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="5.0" modified="2009-11-03">
        <desc>
            <descript source="cve">ArubaOS 3.3.1.x, 3.3.2.x, RN 3.1.x, 3.4.x, and 3.3.2.x-FIPS on the Aruba Mobility Controller allows remote attackers to cause a denial of service (Access Point crash) via a malformed 802.11 Association Request management frame.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3051" adv="1">ADV-2009-3051</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36832">36832</ref>
            <ref source="CONFIRM" url="http://www.arubanetworks.com/support/alerts/aid-102609.asc" adv="1">http://www.arubanetworks.com/support/alerts/aid-102609.asc</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37085" adv="1">37085</ref>
        </refs>
        <vuln_soft>
            <prod vendor="arubanetworks" name="arubaos">
                <vers edition="rn" num="3.1.x" />
                <vers num="3.3.1.x" />
                <vers edition="fips" num="3.3.2.x" />
                <vers num="3.3.x" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3837" seq="2009-3837" severity="High" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="10.0" modified="2009-11-02">
        <desc>
            <descript source="cve">Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error message.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53940">eurekaemail-pop3-bo(53940)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3025" adv="1">ADV-2009-3025</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507376/100/0/threaded">20091022 {PRL} Eureka Mail client BoF</ref>
            <ref source="MISC" url="http://www.packetstormsecurity.org/0910-exploits/eurekamc-dos.txt">http://www.packetstormsecurity.org/0910-exploits/eurekamc-dos.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37132" adv="1">37132</ref>
            <ref source="OSVDB" url="http://osvdb.org/59262">59262</ref>
        </refs>
        <vuln_soft>
            <prod vendor="eureka-email" name="eureka_email">
                <vers num="2.2q" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3838" seq="2009-3838" severity="High" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="10.0" modified="2009-11-02">
        <desc>
            <descript source="cve">Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/53933">pegasus-pop3-bo(53933)</ref>
            <ref source="MISC" url="http://www.vupen.com/exploits/Pegasus_Mail_POP3_Message_Handling_Remote_Buffer_Overflow_Exploit_3026233.php" adv="1">http://www.vupen.com/exploits/Pegasus_Mail_POP3_Message_Handling_Remote_Buffer_Overflow_Exploit_3026233.php</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3026" adv="1">ADV-2009-3026</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023075">1023075</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36797">36797</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507377/100/0/threaded">20091022 {PRL} Pegasus Mail client BoF</ref>
            <ref source="MISC" url="http://www.packetstormsecurity.org/0910-exploits/pegasusmc-dos.txt">http://www.packetstormsecurity.org/0910-exploits/pegasusmc-dos.txt</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37134" adv="1">37134</ref>
            <ref source="OSVDB" url="http://osvdb.org/59261">59261</ref>
        </refs>
        <vuln_soft>
            <prod vendor="pmail" name="pegasus_mail">
                <vers num="4.41" />
                <vers num="4.51" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3839" seq="2009-3839" severity="High" type="CVE" published="2009-11-02" CVSS_version="2.0" CVSS_score="7.5" modified="2009-11-03">
        <desc>
            <descript source="cve">Unspecified vulnerability in the Solaris Trusted Extensions Policy configuration in Sun Solaris 10, and OpenSolaris snv_37 through snv_125, might allow remote attackers to execute arbitrary code by leveraging access to the X server.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270969-1" adv="1">270969</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3070" adv="1">ADV-2009-3070</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36840">36840</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37184" adv="1">37184</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="opensolaris">
                <vers edition="" num="snv_01" />
                <vers edition=":x86" num="snv_01" />
                <vers edition="" num="snv_02" />
                <vers edition=":x86" num="snv_02" />
                <vers edition="" num="snv_03" />
                <vers edition=":x86" num="snv_03" />
                <vers edition="" num="snv_04" />
                <vers edition=":x86" num="snv_04" />
                <vers edition="" num="snv_05" />
                <vers edition=":x86" num="snv_05" />
                <vers edition="" num="snv_06" />
                <vers edition=":x86" num="snv_06" />
                <vers edition="" num="snv_07" />
                <vers edition=":x86" num="snv_07" />
                <vers edition="" num="snv_08" />
                <vers edition=":x86" num="snv_08" />
                <vers edition="" num="snv_09" />
                <vers edition=":x86" num="snv_09" />
                <vers edition="" num="snv_10" />
                <vers edition=":x86" num="snv_10" />
                <vers edition="" num="snv_100" />
                <vers edition=":x86" num="snv_100" />
                <vers edition=":sparc" num="snv_100" />
                <vers edition="" num="snv_101" />
                <vers edition=":x86" num="snv_101" />
                <vers edition=":sparc" num="snv_101" />
                <vers edition="" num="snv_102" />
                <vers edition=":sparc" num="snv_102" />
                <vers edition=":x86" num="snv_102" />
                <vers edition="" num="snv_103" />
                <vers edition=":sparc" num="snv_103" />
                <vers edition=":x86" num="snv_103" />
                <vers edition="" num="snv_104" />
                <vers edition=":sparc" num="snv_104" />
                <vers edition=":x86" num="snv_104" />
                <vers edition="" num="snv_105" />
                <vers edition=":x86" num="snv_105" />
                <vers edition=":sparc" num="snv_105" />
                <vers edition="" num="snv_106" />
                <vers edition=":x86" num="snv_106" />
                <vers edition=":sparc" num="snv_106" />
                <vers edition="" num="snv_107" />
                <vers edition=":x86" num="snv_107" />
                <vers edition=":sparc" num="snv_107" />
                <vers edition="" num="snv_108" prev="1" />
                <vers edition=":sparc" num="snv_108" prev="1" />
                <vers edition=":x86" num="snv_108" prev="1" />
                <vers edition="" num="snv_11" />
                <vers edition=":x86" num="snv_11" />
                <vers edition="" num="snv_111" />
                <vers edition=":x86" num="snv_111" />
                <vers edition=":sparc" num="snv_111" />
                <vers edition="" num="snv_112" />
                <vers edition=":x86" num="snv_112" />
                <vers edition=":sparc" num="snv_112" />
                <vers edition="" num="snv_113" />
                <vers edition=":x86" num="snv_113" />
                <vers edition=":sparc" num="snv_113" />
                <vers edition="" num="snv_114" />
                <vers edition=":x86" num="snv_114" />
                <vers edition=":sparc" num="snv_114" />
                <vers edition="" num="snv_115" />
                <vers edition=":x86" num="snv_115" />
                <vers edition=":sparc" num="snv_115" />
                <vers edition="" num="snv_116" />
                <vers edition=":sparc" num="snv_116" />
                <vers edition=":x86" num="snv_116" />
                <vers edition="" num="snv_117" />
                <vers edition=":sparc" num="snv_117" />
                <vers edition=":x86" num="snv_117" />
                <vers edition="" num="snv_118" />
                <vers edition=":sparc" num="snv_118" />
                <vers edition=":x86" num="snv_118" />
                <vers edition="" num="snv_119" />
                <vers edition=":x86" num="snv_119" />
                <vers edition=":sparc" num="snv_119" />
                <vers edition="" num="snv_12" />
                <vers edition=":x86" num="snv_12" />
                <vers edition="" num="snv_120" />
                <vers edition=":sparc" num="snv_120" />
                <vers edition=":x86" num="snv_120" />
                <vers edition="" num="snv_121" />
                <vers edition=":x86" num="snv_121" />
                <vers edition=":sparc" num="snv_121" />
                <vers edition="" num="snv_122" />
                <vers edition=":sparc" num="snv_122" />
                <vers edition=":x86" num="snv_122" />
                <vers edition="" num="snv_123" />
                <vers edition=":sparc" num="snv_123" />
                <vers edition=":x86" num="snv_123" />
                <vers edition="" num="snv_124" />
                <vers edition=":x86" num="snv_124" />
                <vers edition=":sparc" num="snv_124" />
                <vers edition="" num="snv_125" />
                <vers edition=":x86" num="snv_125" />
                <vers edition=":sparc" num="snv_125" />
                <vers edition="" num="snv_13" />
                <vers edition=":x86" num="snv_13" />
                <vers edition="" num="snv_14" />
                <vers edition=":x86" num="snv_14" />
                <vers edition="" num="snv_15" />
                <vers edition=":x86" num="snv_15" />
                <vers edition="" num="snv_16" />
                <vers edition=":x86" num="snv_16" />
                <vers edition="" num="snv_17" />
                <vers edition=":x86" num="snv_17" />
                <vers edition="" num="snv_18" />
                <vers edition=":x86" num="snv_18" />
                <vers edition="" num="snv_19" />
                <vers edition=":x86" num="snv_19" />
                <vers edition="" num="snv_20" />
                <vers edition=":x86" num="snv_20" />
                <vers edition="" num="snv_21" />
                <vers edition=":x86" num="snv_21" />
                <vers edition="" num="snv_22" />
                <vers edition=":x86" num="snv_22" />
                <vers edition="" num="snv_23" />
                <vers edition=":x86" num="snv_23" />
                <vers edition="" num="snv_24" />
                <vers edition=":x86" num="snv_24" />
                <vers edition="" num="snv_25" />
                <vers edition=":x86" num="snv_25" />
                <vers edition="" num="snv_26" />
                <vers edition=":x86" num="snv_26" />
                <vers edition="" num="snv_27" />
                <vers edition=":x86" num="snv_27" />
                <vers edition="" num="snv_28" />
                <vers edition=":x86" num="snv_28" />
                <vers edition="" num="snv_29" />
                <vers edition=":x86" num="snv_29" />
                <vers edition="" num="snv_30" />
                <vers edition=":x86" num="snv_30" />
                <vers edition=":sparc" num="snv_30" />
                <vers edition="" num="snv_31" />
                <vers edition=":x86" num="snv_31" />
                <vers edition="" num="snv_32" />
                <vers edition=":x86" num="snv_32" />
                <vers edition="" num="snv_33" />
                <vers edition=":x86" num="snv_33" />
                <vers edition="" num="snv_34" />
                <vers edition=":x86" num="snv_34" />
                <vers edition="" num="snv_35" />
                <vers edition=":x86" num="snv_35" />
                <vers edition="" num="snv_36" />
                <vers edition=":x86" num="snv_36" />
                <vers edition="" num="snv_37" />
                <vers edition=":x86" num="snv_37" />
                <vers edition=":sparc" num="snv_37" />
                <vers edition="" num="snv_38" />
                <vers edition=":x86" num="snv_38" />
                <vers edition=":sparc" num="snv_38" />
                <vers edition="" num="snv_39" />
                <vers edition=":sparc" num="snv_39" />
                <vers edition=":x86" num="snv_39" />
                <vers edition="" num="snv_40" />
                <vers edition=":x86" num="snv_40" />
                <vers edition=":sparc" num="snv_40" />
                <vers edition="" num="snv_41" />
                <vers edition=":sparc" num="snv_41" />
                <vers edition=":x86" num="snv_41" />
                <vers edition="" num="snv_42" />
                <vers edition=":sparc" num="snv_42" />
                <vers edition=":x86" num="snv_42" />
                <vers edition="" num="snv_43" />
                <vers edition=":sparc" num="snv_43" />
                <vers edition=":x86" num="snv_43" />
                <vers edition="" num="snv_44" />
                <vers edition=":sparc" num="snv_44" />
                <vers edition=":x86" num="snv_44" />
                <vers edition="" num="snv_45" />
                <vers edition=":sparc" num="snv_45" />
                <vers edition=":x86" num="snv_45" />
                <vers edition="" num="snv_46" />
                <vers edition=":x86" num="snv_46" />
                <vers edition=":sparc" num="snv_46" />
                <vers edition="" num="snv_47" />
                <vers edition=":sparc" num="snv_47" />
                <vers edition=":x86" num="snv_47" />
                <vers edition="" num="snv_48" />
                <vers edition=":sparc" num="snv_48" />
                <vers edition=":x86" num="snv_48" />
                <vers edition="" num="snv_49" />
                <vers edition=":sparc" num="snv_49" />
                <vers edition=":x86" num="snv_49" />
                <vers edition="" num="snv_50" />
                <vers edition=":sparc" num="snv_50" />
                <vers edition=":x86" num="snv_50" />
                <vers edition="" num="snv_51" />
                <vers edition=":sparc" num="snv_51" />
                <vers edition=":x86" num="snv_51" />
                <vers edition="" num="snv_52" />
                <vers edition=":sparc" num="snv_52" />
                <vers edition=":x86" num="snv_52" />
                <vers edition="" num="snv_53" />
                <vers edition=":sparc" num="snv_53" />
                <vers edition=":x86" num="snv_53" />
                <vers edition="" num="snv_54" />
                <vers edition=":x86" num="snv_54" />
                <vers edition=":sparc" num="snv_54" />
                <vers edition="" num="snv_55" />
                <vers edition=":sparc" num="snv_55" />
                <vers edition=":x86" num="snv_55" />
                <vers edition="" num="snv_56" />
                <vers edition=":x86" num="snv_56" />
                <vers edition=":sparc" num="snv_56" />
                <vers edition="" num="snv_57" />
                <vers edition=":sparc" num="snv_57" />
                <vers edition=":x86" num="snv_57" />
                <vers edition="" num="snv_58" />
                <vers edition=":x86" num="snv_58" />
                <vers edition=":sparc" num="snv_58" />
                <vers edition="" num="snv_59" />
                <vers edition=":sparc" num="snv_59" />
                <vers edition=":x86" num="snv_59" />
                <vers edition="" num="snv_60" />
                <vers edition=":x86" num="snv_60" />
                <vers edition=":sparc" num="snv_60" />
                <vers edition="" num="snv_61" />
                <vers edition=":sparc" num="snv_61" />
                <vers edition=":x86" num="snv_61" />
                <vers edition="" num="snv_62" />
                <vers edition=":x86" num="snv_62" />
                <vers edition=":sparc" num="snv_62" />
                <vers edition="" num="snv_63" />
                <vers edition=":sparc" num="snv_63" />
                <vers edition=":x86" num="snv_63" />
                <vers edition="" num="snv_64" />
                <vers edition=":x86" num="snv_64" />
                <vers edition=":sparc" num="snv_64" />
                <vers edition="" num="snv_65" />
                <vers edition=":sparc" num="snv_65" />
                <vers edition=":x86" num="snv_65" />
                <vers edition="" num="snv_66" />
                <vers edition=":x86" num="snv_66" />
                <vers edition=":sparc" num="snv_66" />
                <vers edition="" num="snv_67" />
                <vers edition=":sparc" num="snv_67" />
                <vers edition=":x86" num="snv_67" />
                <vers edition="" num="snv_68" />
                <vers edition=":sparc" num="snv_68" />
                <vers edition=":x86" num="snv_68" />
                <vers edition="" num="snv_69" />
                <vers edition=":sparc" num="snv_69" />
                <vers edition=":x86" num="snv_69" />
                <vers edition="" num="snv_70" />
                <vers edition=":sparc" num="snv_70" />
                <vers edition=":x86" num="snv_70" />
                <vers edition="" num="snv_71" />
                <vers edition=":x86" num="snv_71" />
                <vers edition=":sparc" num="snv_71" />
                <vers edition="" num="snv_72" />
                <vers edition=":sparc" num="snv_72" />
                <vers edition=":x86" num="snv_72" />
                <vers edition="" num="snv_73" />
                <vers edition=":x86" num="snv_73" />
                <vers edition=":sparc" num="snv_73" />
                <vers edition="" num="snv_74" />
                <vers edition=":x86" num="snv_74" />
                <vers edition=":sparc" num="snv_74" />
                <vers edition="" num="snv_75" />
                <vers edition=":x86" num="snv_75" />
                <vers edition=":sparc" num="snv_75" />
                <vers edition="" num="snv_76" />
                <vers edition=":sparc" num="snv_76" />
                <vers edition=":x86" num="snv_76" />
                <vers edition="" num="snv_77" />
                <vers edition=":x86" num="snv_77" />
                <vers edition=":sparc" num="snv_77" />
                <vers edition="" num="snv_78" />
                <vers edition=":x86" num="snv_78" />
                <vers edition=":sparc" num="snv_78" />
                <vers edition="" num="snv_79" />
                <vers edition=":x86" num="snv_79" />
                <vers edition=":sparc" num="snv_79" />
                <vers edition="" num="snv_80" />
                <vers edition=":x86" num="snv_80" />
                <vers edition=":sparc" num="snv_80" />
                <vers edition="" num="snv_81" />
                <vers edition=":sparc" num="snv_81" />
                <vers edition=":x86" num="snv_81" />
                <vers edition="" num="snv_82" />
                <vers edition=":x86" num="snv_82" />
                <vers edition=":sparc" num="snv_82" />
                <vers edition="" num="snv_83" />
                <vers edition=":sparc" num="snv_83" />
                <vers edition=":x86" num="snv_83" />
                <vers edition="" num="snv_84" />
                <vers edition=":x86" num="snv_84" />
                <vers edition=":sparc" num="snv_84" />
                <vers edition="" num="snv_85" />
                <vers edition=":sparc" num="snv_85" />
                <vers edition=":x86" num="snv_85" />
                <vers edition="" num="snv_86" />
                <vers edition=":x86" num="snv_86" />
                <vers edition=":sparc" num="snv_86" />
                <vers edition="" num="snv_87" />
                <vers edition=":sparc" num="snv_87" />
                <vers edition=":x86" num="snv_87" />
                <vers edition="" num="snv_88" />
                <vers edition=":x86" num="snv_88" />
                <vers edition=":sparc" num="snv_88" />
                <vers edition="" num="snv_89" />
                <vers edition=":x86" num="snv_89" />
                <vers edition=":sparc" num="snv_89" />
                <vers edition="" num="snv_90" />
                <vers edition=":x86" num="snv_90" />
                <vers edition=":sparc" num="snv_90" />
                <vers edition="" num="snv_91" />
                <vers edition=":x86" num="snv_91" />
                <vers edition=":sparc" num="snv_91" />
                <vers edition="" num="snv_92" />
                <vers edition=":sparc" num="snv_92" />
                <vers edition=":x86" num="snv_92" />
                <vers edition="" num="snv_93" />
                <vers edition=":sparc" num="snv_93" />
                <vers edition=":x86" num="snv_93" />
                <vers edition="" num="snv_94" />
                <vers edition=":sparc" num="snv_94" />
                <vers edition=":x86" num="snv_94" />
                <vers edition="" num="snv_95" />
                <vers edition=":sparc" num="snv_95" />
                <vers edition=":x86" num="snv_95" />
                <vers edition="" num="snv_96" />
                <vers edition=":x86" num="snv_96" />
                <vers edition=":sparc" num="snv_96" />
                <vers edition="" num="snv_97" />
                <vers edition=":x86" num="snv_97" />
                <vers edition=":sparc" num="snv_97" />
                <vers edition="" num="snv_98" />
                <vers edition=":sparc" num="snv_98" />
                <vers edition=":x86" num="snv_98" />
                <vers edition="" num="snv_99" />
                <vers edition=":sparc" num="snv_99" />
                <vers edition=":x86" num="snv_99" />
            </prod>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="10" />
                <vers edition=":x86" num="10" />
                <vers edition=":sparc" num="10" />
                <vers edition="" num="10.0" />
                <vers edition=":sparc" num="10.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3031" seq="2009-3031" severity="High" type="CVE" published="2009-11-03" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-04">
        <desc>
            <descript source="cve">Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12, Deployment Server 6.8 and 6.9 in Symantec Altiris Deployment Solution 6.9 SP3, and Symantec Management Platform (SMP) 7.0 before SP3 allows remote attackers to execute arbitrary code via a long string in the second argument.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20091102_00" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20091102_00</ref>
            <ref source="CONFIRM" url="https://kb.altiris.com/article.asp?article=49568&amp;p=1" adv="1">https://kb.altiris.com/article.asp?article=49568&amp;p=1</ref>
            <ref source="CONFIRM" url="https://kb.altiris.com/article.asp?article=49389&amp;p=1" adv="1">https://kb.altiris.com/article.asp?article=49389&amp;p=1</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3117" adv="1">ADV-2009-3117</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36698">36698</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507625/100/0/threaded">20091102 NSOADV-2009-001: Symantec ConsoleUtilities ActiveX Control Buffer Overflow</ref>
            <ref source="MISC" url="http://sotiriu.de/adv/NSOADV-2009-001.txt">http://sotiriu.de/adv/NSOADV-2009-001.txt</ref>
        </refs>
        <vuln_soft>
            <prod vendor="symantec" name="altiris_deployment_solution">
                <vers num="6.9" />
            </prod>
            <prod vendor="symantec" name="altiris_management_platform">
                <vers num="7.0" />
            </prod>
            <prod vendor="symantec" name="altiris_notification_server">
                <vers num="6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" name="CVE-2009-3298" seq="2009-3298" severity="Medium" type="CVE" published="2009-11-03" CVSS_version="2.0" CVSS_score="6.5" modified="2009-11-04">
        <desc>
            <descript source="cve">Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote authenticated institution administrators to reset a site administrator password via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot other="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3101" adv="1">ADV-2009-3101</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36893">36893</ref>
            <ref source="CONFIRM" patch="1" url="http://eduforge.org/frs/shownotes.php?release_id=546">http://eduforge.org/frs/shownotes.php?release_id=546</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/59584">59584</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1924">DSA-1924</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37218" adv="1">37218</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37217" adv="1">37217</ref>
            <ref source="CONFIRM" url="http://mahara.org/interaction/forum/topic.php?id=1169">http://mahara.org/interaction/forum/topic.php?id=1169</ref>
            <ref source="CONFIRM" url="http://eduforge.org/frs/shownotes.php?release_id=547">http://eduforge.org/frs/shownotes.php?release_id=547</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mahara" name="mahara">
                <vers num="1.0.13" />
                <vers edition="alpha1" num="1.1.0" />
                <vers edition="alpha2" num="1.1.0" />
                <vers edition="alpha3" num="1.1.0" />
                <vers edition="beta1" num="1.1.0" />
                <vers edition="beta2" num="1.1.0" />
                <vers edition="beta3" num="1.1.0" />
                <vers edition="beta4" num="1.1.0" />
                <vers edition="rc1" num="1.1.0" />
                <vers edition="rc2" num="1.1.0" />
                <vers num="1.1.1" />
                <vers num="1.1.2" />
                <vers num="1.1.3" />
                <vers num="1.1.4" />
                <vers num="1.1.5" />
                <vers num="1.1.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3299" seq="2009-3299" severity="Medium" type="CVE" published="2009-11-03" CVSS_version="2.0" CVSS_score="4.3" modified="2009-11-04">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the resume blocktype in Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3101" adv="1">ADV-2009-3101</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36892">36892</ref>
            <ref source="CONFIRM" patch="1" url="http://eduforge.org/frs/shownotes.php?release_id=546">http://eduforge.org/frs/shownotes.php?release_id=546</ref>
            <ref source="OSVDB" url="http://www.osvdb.org/59583">59583</ref>
            <ref source="DEBIAN" url="http://www.debian.org/security/2009/dsa-1924">DSA-1924</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37218" adv="1">37218</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37217" adv="1">37217</ref>
            <ref source="CONFIRM" url="http://mahara.org/interaction/forum/topic.php?id=1170">http://mahara.org/interaction/forum/topic.php?id=1170</ref>
            <ref source="CONFIRM" url="http://eduforge.org/frs/shownotes.php?release_id=547">http://eduforge.org/frs/shownotes.php?release_id=547</ref>
        </refs>
        <vuln_soft>
            <prod vendor="mahara" name="mahara">
                <vers num="1.0.13" />
                <vers edition="alpha1" num="1.1.0" />
                <vers edition="alpha2" num="1.1.0" />
                <vers edition="alpha3" num="1.1.0" />
                <vers edition="beta1" num="1.1.0" />
                <vers edition="beta2" num="1.1.0" />
                <vers edition="beta3" num="1.1.0" />
                <vers edition="beta4" num="1.1.0" />
                <vers edition="rc1" num="1.1.0" />
                <vers edition="rc2" num="1.1.0" />
                <vers num="1.1.1" />
                <vers num="1.1.2" />
                <vers num="1.1.3" />
                <vers num="1.1.4" />
                <vers num="1.1.5" />
                <vers num="1.1.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3720" seq="2009-3720" severity="Medium" type="CVE" published="2009-11-03" CVSS_version="2.0" CVSS_score="5.0" modified="2009-11-04">
        <desc>
            <descript source="cve">The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" url="https://bugs.gentoo.org/show_bug.cgi?id=280615">https://bugs.gentoo.org/show_bug.cgi?id=280615</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/10/28/3">[oss-security] 20091028 Re: CVE Request -- expat [was: Re: Regarding expat bug 1990430]</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/10/26/3">[oss-security] 20091026 Re: CVE Request -- expat [was: Re: Regarding expat bug 1990430]</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/10/23/6">[oss-security] 20091023 Re: CVE Request -- expat [was: Re: Regarding expat bug 1990430]</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/10/23/2">[oss-security] 20091022 Re: Re: Regarding expat bug 1990430</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/10/22/9">[oss-security] 20091022 Re: Regarding expat bug 1990430</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/10/22/5">[oss-security] 20091022 Regarding expat bug 1990430</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/09/06/1">[oss-security] 20090906 Re: Re: expat bug 1990430</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/08/27/6">[oss-security] 20090827 Re: Re: expat bug 1990430</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/08/26/4">[oss-security] 20090826 Re: Re: expat bug 1990430</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/08/26/3">[oss-security] 20090826 Re: expat bug 1990430</ref>
            <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2009/08/21/2">[oss-security] 20090821 expat bug 1990430</ref>
            <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:211">MDVSA-2009:211</ref>
            <ref source="CONFIRM" url="http://svn.python.org/view?view=rev&amp;revision=74429">http://svn.python.org/view?view=rev&amp;revision=74429</ref>
            <ref source="MISC" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1990430&amp;group_id=10127&amp;atid=110127">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1990430&amp;group_id=10127&amp;atid=110127</ref>
            <ref source="MLIST" url="http://mail.python.org/pipermail/expat-bugs/2009-January/002781.html">[expat-bugs] 20090117 [ expat-Bugs-1990430 ] Parser crash with specially formatted UTF-8 sequences</ref>
            <ref source="CONFIRM" url="http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?view=log">http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?view=log</ref>
            <ref source="CONFIRM" url="http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&amp;r2=1.15&amp;view=patch">http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&amp;r2=1.15&amp;view=patch</ref>
        </refs>
        <vuln_soft>
            <prod vendor="james_clark" name="expat">
                <vers num="2.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2009-3851" seq="2009-3851" severity="High" type="CVE" published="2009-11-03" CVSS_version="2.0" CVSS_score="7.2" modified="2009-11-04">
        <desc>
            <descript source="cve">Trusted Extensions in Sun Solaris 10 interferes with the operation of the xscreensaver-demo command for the XScreenSaver application, which makes it easier for physically proximate attackers to access an unattended workstation for which the intended screen locking did not occur, related to the "restart daemon."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-120094-28-1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-120094-28-1</ref>
            <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270809-1" adv="1">270809</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="solaris">
                <vers edition="" num="10.0" />
                <vers edition=":x86" num="10.0" />
                <vers edition=":sparc" num="10.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3852" seq="2009-3852" severity="High" type="CVE" published="2009-11-03" CVSS_version="2.0" CVSS_score="7.5" modified="2009-11-04">
        <desc>
            <descript source="cve">Unspecified vulnerability in the XML component in IBM Runtimes for Java Technology 5.0.0 before SR10 has unknown impact and attack vectors, related to the "updated version of XML4J 4.4.17."</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54069">runtime-xml4j-unspecified(54069)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3106" adv="1">ADV-2009-3106</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36894">36894</ref>
            <ref source="AIXAPAR" url="http://www-01.ibm.com/support/docview.wss?uid=swg1IZ63920">IZ63920</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37210" adv="1">37210</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="ibm_runtimes_for_java_technology">
                <vers num="5.0.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-0306" seq="2009-0306" severity="High" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-04">
        <desc>
            <descript source="cve">Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page.  NOTE: some of these details are obtained from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB19701" adv="1">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB19701</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3133" adv="1">ADV-2009-3133</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36903">36903</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="lotus_notes_intellisync">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3463" seq="2009-3463" severity="High" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-04">
        <desc>
            <descript source="cve">Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site.  NOTE: some of these details are obtained from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.adobe.com/support/security/bulletins/apsb09-16.html" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-16.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54118">shockwave-index-code-execution(54118)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3134" adv="1">ADV-2009-3134</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36905">36905</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023123">1023123</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="shockwave_player">
                <vers num="1.0" />
                <vers num="10.1.0.11" />
                <vers num="11.0.0.456" />
                <vers num="11.5.0.595" />
                <vers num="11.5.0.596" />
                <vers num="11.5.1.601" prev="1" />
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="4.0" />
                <vers num="5.0" />
                <vers num="6.0" />
                <vers num="8.0" />
                <vers num="8.5.1" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3464" seq="2009-3464" severity="High" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="10.0" modified="2009-11-04">
        <desc>
            <descript source="cve">Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3465.  NOTE: some of these details are obtained from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36905">36905</ref>
            <ref source="CONFIRM" patch="1" url="http://www.adobe.com/support/security/bulletins/apsb09-16.html" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-16.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54119">shockwave-pointer-code-execution(54119)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3134" adv="1">ADV-2009-3134</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023123">1023123</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="shockwave_player">
                <vers num="1.0" />
                <vers num="10.1.0.11" />
                <vers num="11.0.0.456" />
                <vers num="11.5.0.595" />
                <vers num="11.5.0.596" />
                <vers num="11.5.1.601" prev="1" />
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="4.0" />
                <vers num="5.0" />
                <vers num="6.0" />
                <vers num="8.0" />
                <vers num="8.5.1" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3465" seq="2009-3465" severity="High" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="10.0" modified="2009-11-04">
        <desc>
            <descript source="cve">Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3464.  NOTE: some of these details are obtained from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54120">shockwave-invalid-pointer-code-execution(54120)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3134" adv="1">ADV-2009-3134</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36905">36905</ref>
            <ref source="CONFIRM" url="http://www.adobe.com/support/security/bulletins/apsb09-16.html">http://www.adobe.com/support/security/bulletins/apsb09-16.html</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023123">1023123</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="shockwave_player">
                <vers num="1.0" />
                <vers num="10.1.0.11" />
                <vers num="11.0.0.456" />
                <vers num="11.5.0.595" />
                <vers num="11.5.0.596" />
                <vers num="11.5.1.601" prev="1" />
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="4.0" />
                <vers num="5.0" />
                <vers num="6.0" />
                <vers num="8.0" />
                <vers num="8.5.1" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3466" seq="2009-3466" severity="High" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-04">
        <desc>
            <descript source="cve">Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption, related to an "invalid string length vulnerability." NOTE: some of these details are obtained from third party information.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.adobe.com/support/security/bulletins/apsb09-16.html" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-16.html</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/54121">shockwave-string-code-execution(54121)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3134" adv="1">ADV-2009-3134</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36905">36905</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023123">1023123</ref>
        </refs>
        <vuln_soft>
            <prod vendor="adobe" name="shockwave_player">
                <vers num="1.0" />
                <vers num="10.1.0.11" />
                <vers num="11.0.0.456" />
                <vers num="11.5.0.595" />
                <vers num="11.5.0.596" />
                <vers num="11.5.1.601" prev="1" />
                <vers num="2.0" />
                <vers num="3.0" />
                <vers num="4.0" />
                <vers num="5.0" />
                <vers num="6.0" />
                <vers num="8.0" />
                <vers num="8.5.1" />
                <vers num="9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" name="CVE-2009-3547" seq="2009-3547" severity="Medium" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="6.9" modified="2009-11-06">
        <desc>
            <descript source="cve">Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1550.html" adv="1">RHSA-2009:1550</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1548.html" adv="1">RHSA-2009:1548</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1541.html" adv="1">RHSA-2009:1541</ref>
            <ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2009-1540.html" adv="1">RHSA-2009:1540</ref>
            <ref source="CONFIRM" url="https://bugzilla.redhat.com/show_bug.cgi?id=530490">https://bugzilla.redhat.com/show_bug.cgi?id=530490</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36901">36901</ref>
            <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc6">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.32-rc6</ref>
            <ref source="MLIST" url="http://marc.info/?l=oss-security&amp;m=125724568017045&amp;w=2">[oss-security] 20091103 CVE-2009-3547 kernel: fs: pipe.c null pointer dereference</ref>
            <ref source="MLIST" url="http://lkml.org/lkml/2009/10/21/42">[linux-kernel] 20091021 Re: [PATCH v4 1/1]: fs: pipe.c null pointer dereference + really sign off + unmangled diffs</ref>
            <ref source="MLIST" url="http://lkml.org/lkml/2009/10/14/184">[linux-kernel] 20091014 fs/pipe.c null pointer dereference</ref>
            <ref source="CONFIRM" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad3960243e55320d74195fb85c975e0a8cc4466c">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad3960243e55320d74195fb85c975e0a8cc4466c</ref>
        </refs>
        <vuln_soft>
            <prod vendor="linux" name="kernel">
                <vers num="2.6.24.7" />
                <vers num="2.6.25.15" />
            </prod>
            <prod vendor="linux" name="kernel">
                <vers num="2.2.27" />
                <vers num="2.4.1" />
                <vers num="2.4.10" />
                <vers num="2.4.11" />
                <vers num="2.4.12" />
                <vers num="2.4.13" />
                <vers num="2.4.14" />
                <vers num="2.4.15" />
                <vers num="2.4.16" />
                <vers num="2.4.17" />
                <vers edition="" num="2.4.18" />
                <vers edition=":x86" num="2.4.18" />
                <vers edition=":pre-2" num="2.4.18" />
                <vers edition=":pre-3" num="2.4.18" />
                <vers edition=":pre-1" num="2.4.18" />
                <vers edition=":pre-7" num="2.4.18" />
                <vers edition=":pre-6" num="2.4.18" />
                <vers edition=":pre-5" num="2.4.18" />
                <vers edition=":pre-4" num="2.4.18" />
                <vers edition=":pre-8" num="2.4.18" />
                <vers edition="" num="2.4.19" />
                <vers edition=":-pre1" num="2.4.19" />
                <vers edition=":-pre2" num="2.4.19" />
                <vers edition=":-pre5" num="2.4.19" />
                <vers edition=":-pre6" num="2.4.19" />
                <vers edition=":-pre3" num="2.4.19" />
                <vers edition=":-pre4" num="2.4.19" />
                <vers num="2.4.2" />
                <vers num="2.4.20" />
                <vers edition="" num="2.4.21" />
                <vers edition=":-pre1" num="2.4.21" />
                <vers edition=":-pre4" num="2.4.21" />
                <vers edition=":-pre7" num="2.4.21" />
                <vers num="2.4.22" />
                <vers edition="" num="2.4.23" />
                <vers edition=":-ow2" num="2.4.23" />
                <vers edition=":-pre9" num="2.4.23" />
                <vers edition="" num="2.4.24" />
                <vers edition=":-ow1" num="2.4.24" />
                <vers num="2.4.25" />
                <vers num="2.4.26" />
                <vers edition="" num="2.4.27" />
                <vers edition=":-pre1" num="2.4.27" />
                <vers edition=":-pre2" num="2.4.27" />
                <vers edition=":-pre3" num="2.4.27" />
                <vers edition=":-pre4" num="2.4.27" />
                <vers edition=":-pre5" num="2.4.27" />
                <vers num="2.4.28" />
                <vers edition="-rc1" num="2.4.29" />
                <vers edition="-rc2" num="2.4.29" />
                <vers num="2.4.3" />
                <vers edition="rc2" num="2.4.30" />
                <vers edition="rc3" num="2.4.30" />
                <vers num="2.4.31" />
                <vers num="2.4.32" />
                <vers num="2.4.33" />
                <vers num="2.4.33.1" />
                <vers num="2.4.33.2" />
                <vers num="2.4.33.3" />
                <vers num="2.4.33.4" />
                <vers num="2.4.33.5" />
                <vers num="2.4.33.7" />
                <vers num="2.4.34" />
                <vers num="2.4.34.1" />
                <vers num="2.4.34.2" />
                <vers num="2.4.34.3" />
                <vers num="2.4.34.4" />
                <vers num="2.4.34.5" />
                <vers num="2.4.34.6" />
                <vers num="2.4.35.1" />
                <vers num="2.4.35.2" />
                <vers num="2.4.35.3" />
                <vers num="2.4.35.4" />
                <vers num="2.4.35.5" />
                <vers num="2.4.36" />
                <vers num="2.4.36.1" />
                <vers num="2.4.36.2" />
                <vers num="2.4.36.3" />
                <vers num="2.4.36.4" />
                <vers num="2.4.36.5" />
                <vers num="2.4.36.6" />
                <vers num="2.4.36.7" />
                <vers num="2.4.36.8" />
                <vers num="2.4.36.9" />
                <vers edition="-rc1" num="2.4.37" />
                <vers num="2.4.37.1" />
                <vers num="2.4.37.2" />
                <vers num="2.4.37.3" />
                <vers num="2.4.37.4" />
                <vers num="2.4.37.5" />
                <vers num="2.4.37.6" />
                <vers num="2.4.4" />
                <vers num="2.4.5" />
                <vers num="2.4.6" />
                <vers num="2.4.7" />
                <vers num="2.4.8" />
                <vers num="2.4.9" />
                <vers num="2.6" />
                <vers num="2.6.0" />
                <vers num="2.6.1" />
                <vers num="2.6.10" />
                <vers num="2.6.11" />
                <vers num="2.6.11.1" />
                <vers num="2.6.11.10" />
                <vers num="2.6.11.11" />
                <vers num="2.6.11.12" />
                <vers num="2.6.11.2" />
                <vers num="2.6.11.3" />
                <vers num="2.6.11.4" />
                <vers num="2.6.11.5" />
                <vers num="2.6.11.6" />
                <vers num="2.6.11.7" />
                <vers num="2.6.11.8" />
                <vers num="2.6.11.9" />
                <vers num="2.6.12" />
                <vers num="2.6.12.1" />
                <vers num="2.6.12.2" />
                <vers num="2.6.12.3" />
                <vers num="2.6.12.4" />
                <vers num="2.6.12.5" />
                <vers num="2.6.12.6" />
                <vers num="2.6.13" />
                <vers num="2.6.13.1" />
                <vers num="2.6.13.2" />
                <vers num="2.6.13.3" />
                <vers num="2.6.13.4" />
                <vers num="2.6.13.5" />
                <vers num="2.6.14" />
                <vers num="2.6.14.1" />
                <vers num="2.6.14.2" />
                <vers num="2.6.14.3" />
                <vers num="2.6.14.4" />
                <vers num="2.6.14.5" />
                <vers num="2.6.14.6" />
                <vers num="2.6.14.7" />
                <vers num="2.6.15" />
                <vers num="2.6.15.1" />
                <vers num="2.6.15.2" />
                <vers num="2.6.15.3" />
                <vers num="2.6.15.4" />
                <vers num="2.6.15.5" />
                <vers num="2.6.15.6" />
                <vers num="2.6.15.7" />
                <vers num="2.6.16" />
                <vers num="2.6.16.1" />
                <vers num="2.6.16.10" />
                <vers num="2.6.16.11" />
                <vers num="2.6.16.12" />
                <vers num="2.6.16.13" />
                <vers num="2.6.16.14" />
                <vers num="2.6.16.15" />
                <vers num="2.6.16.16" />
                <vers num="2.6.16.17" />
                <vers num="2.6.16.18" />
                <vers num="2.6.16.19" />
                <vers num="2.6.16.2" />
                <vers num="2.6.16.20" />
                <vers num="2.6.16.21" />
                <vers num="2.6.16.22" />
                <vers num="2.6.16.23" />
                <vers num="2.6.16.24" />
                <vers num="2.6.16.25" />
                <vers num="2.6.16.26" />
                <vers num="2.6.16.27" />
                <vers num="2.6.16.28" />
                <vers num="2.6.16.29" />
                <vers num="2.6.16.3" />
                <vers num="2.6.16.30" />
                <vers edition="-rc1" num="2.6.16.31" />
                <vers edition="-rc2" num="2.6.16.31" />
                <vers edition="-rc3" num="2.6.16.31" />
                <vers edition="-rc4" num="2.6.16.31" />
                <vers edition="-rc5" num="2.6.16.31" />
                <vers num="2.6.16.32" />
                <vers num="2.6.16.33" />
                <vers num="2.6.16.34" />
                <vers num="2.6.16.35" />
                <vers num="2.6.16.36" />
                <vers num="2.6.16.37" />
                <vers num="2.6.16.38" />
                <vers num="2.6.16.39" />
                <vers num="2.6.16.4" />
                <vers num="2.6.16.40" />
                <vers num="2.6.16.41" />
                <vers num="2.6.16.42" />
                <vers num="2.6.16.43" />
                <vers num="2.6.16.44" />
                <vers num="2.6.16.45" />
                <vers num="2.6.16.46" />
                <vers num="2.6.16.47" />
                <vers num="2.6.16.48" />
                <vers num="2.6.16.49" />
                <vers num="2.6.16.5" />
                <vers num="2.6.16.50" />
                <vers num="2.6.16.51" />
                <vers num="2.6.16.52" />
                <vers num="2.6.16.53" />
                <vers num="2.6.16.54" />
                <vers num="2.6.16.55" />
                <vers num="2.6.16.56" />
                <vers num="2.6.16.57" />
                <vers num="2.6.16.58" />
                <vers num="2.6.16.59" />
                <vers num="2.6.16.6" />
                <vers num="2.6.16.60" />
                <vers num="2.6.16.61" />
                <vers num="2.6.16.62" />
                <vers num="2.6.16.7" />
                <vers num="2.6.16.8" />
                <vers num="2.6.16.9" />
                <vers num="2.6.17" />
                <vers num="2.6.17.1" />
                <vers num="2.6.17.10" />
                <vers num="2.6.17.11" />
                <vers num="2.6.17.12" />
                <vers num="2.6.17.13" />
                <vers num="2.6.17.14" />
                <vers num="2.6.17.2" />
                <vers num="2.6.17.3" />
                <vers num="2.6.17.4" />
                <vers num="2.6.17.5" />
                <vers num="2.6.17.6" />
                <vers num="2.6.17.7" />
                <vers num="2.6.17.8" />
                <vers num="2.6.17.9" />
                <vers edition="rc1" num="2.6.18" />
                <vers edition="rc2" num="2.6.18" />
                <vers edition="rc3" num="2.6.18" />
                <vers edition="rc4" num="2.6.18" />
                <vers edition="rc5" num="2.6.18" />
                <vers edition="rc6" num="2.6.18" />
                <vers edition="rc7" num="2.6.18" />
                <vers num="2.6.18.1" />
                <vers num="2.6.18.2" />
                <vers num="2.6.18.3" />
                <vers num="2.6.18.4" />
                <vers num="2.6.18.5" />
                <vers num="2.6.18.6" />
                <vers num="2.6.18.7" />
                <vers num="2.6.18.8" />
                <vers num="2.6.19" />
                <vers num="2.6.19.1" />
                <vers num="2.6.19.2" />
                <vers num="2.6.19.3" />
                <vers num="2.6.19.4" />
                <vers num="2.6.19.5" />
                <vers num="2.6.19.6" />
                <vers num="2.6.19.7" />
                <vers num="2.6.2" />
                <vers num="2.6.2.27.13" />
                <vers num="2.6.20" />
                <vers num="2.6.20.1" />
                <vers num="2.6.20.10" />
                <vers num="2.6.20.11" />
                <vers num="2.6.20.12" />
                <vers num="2.6.20.13" />
                <vers num="2.6.20.14" />
                <vers num="2.6.20.15" />
                <vers num="2.6.20.16" />
                <vers num="2.6.20.17" />
                <vers num="2.6.20.18" />
                <vers num="2.6.20.19" />
                <vers num="2.6.20.2" />
                <vers num="2.6.20.20" />
                <vers num="2.6.20.21" />
                <vers num="2.6.20.3" />
                <vers num="2.6.20.4" />
                <vers num="2.6.20.5" />
                <vers num="2.6.20.6" />
                <vers num="2.6.20.7" />
                <vers num="2.6.20.8" />
                <vers num="2.6.20.9" />
                <vers num="2.6.21" />
                <vers num="2.6.21.1" />
                <vers num="2.6.21.2" />
                <vers num="2.6.21.3" />
                <vers num="2.6.21.4" />
                <vers num="2.6.21.5" />
                <vers num="2.6.21.6" />
                <vers num="2.6.21.7" />
                <vers num="2.6.22" />
                <vers num="2.6.22.1" />
                <vers num="2.6.22.10" />
                <vers num="2.6.22.11" />
                <vers num="2.6.22.12" />
                <vers num="2.6.22.13" />
                <vers num="2.6.22.14" />
                <vers num="2.6.22.15" />
                <vers num="2.6.22.16" />
                <vers num="2.6.22.17" />
                <vers num="2.6.22.18" />
                <vers num="2.6.22.19" />
                <vers num="2.6.22.2" />
                <vers num="2.6.22.20" />
                <vers num="2.6.22.21" />
                <vers num="2.6.22.22" />
                <vers num="2.6.22.3" />
                <vers num="2.6.22.4" />
                <vers num="2.6.22.5" />
                <vers num="2.6.22.6" />
                <vers num="2.6.22.7" />
                <vers num="2.6.22.8" />
                <vers num="2.6.22.9" />
                <vers edition="rc1" num="2.6.23" />
                <vers edition="rc2" num="2.6.23" />
                <vers num="2.6.23.1" />
                <vers num="2.6.23.10" />
                <vers num="2.6.23.11" />
                <vers num="2.6.23.12" />
                <vers num="2.6.23.13" />
                <vers num="2.6.23.14" />
                <vers num="2.6.23.15" />
                <vers num="2.6.23.16" />
                <vers num="2.6.23.17" />
                <vers num="2.6.23.2" />
                <vers num="2.6.23.3" />
                <vers num="2.6.23.4" />
                <vers num="2.6.23.5" />
                <vers num="2.6.23.6" />
                <vers num="2.6.23.7" />
                <vers num="2.6.23.8" />
                <vers num="2.6.23.9" />
                <vers edition="rc1" num="2.6.24" />
                <vers edition="rc2" num="2.6.24" />
                <vers edition="rc3" num="2.6.24" />
                <vers edition="rc4" num="2.6.24" />
                <vers edition="rc5" num="2.6.24" />
                <vers num="2.6.24.1" />
                <vers num="2.6.24.2" />
                <vers num="2.6.24.3" />
                <vers num="2.6.24.4" />
                <vers num="2.6.24.5" />
                <vers num="2.6.24.6" />
                <vers num="2.6.24.7" />
                <vers edition="" num="2.6.25" />
                <vers edition=":x86_64" num="2.6.25" />
                <vers edition="" num="2.6.25.1" />
                <vers edition=":x86_64" num="2.6.25.1" />
                <vers edition="" num="2.6.25.10" />
                <vers edition=":x86_64" num="2.6.25.10" />
                <vers edition="" num="2.6.25.11" />
                <vers edition=":x86_64" num="2.6.25.11" />
                <vers edition="" num="2.6.25.12" />
                <vers edition=":x86_64" num="2.6.25.12" />
                <vers num="2.6.25.13" />
                <vers num="2.6.25.14" />
                <vers num="2.6.25.15" />
                <vers num="2.6.25.16" />
                <vers num="2.6.25.17" />
                <vers num="2.6.25.18" />
                <vers num="2.6.25.19" />
                <vers edition="" num="2.6.25.2" />
                <vers edition=":x86_64" num="2.6.25.2" />
                <vers num="2.6.25.20" />
                <vers edition="" num="2.6.25.3" />
                <vers edition=":x86_64" num="2.6.25.3" />
                <vers edition="" num="2.6.25.4" />
                <vers edition=":x86_64" num="2.6.25.4" />
                <vers edition="" num="2.6.25.5" />
                <vers edition=":x86_64" num="2.6.25.5" />
                <vers edition="" num="2.6.25.6" />
                <vers edition=":x86_64" num="2.6.25.6" />
                <vers edition="" num="2.6.25.7" />
                <vers edition=":x86_64" num="2.6.25.7" />
                <vers edition="" num="2.6.25.8" />
                <vers edition=":x86_64" num="2.6.25.8" />
                <vers edition="" num="2.6.25.9" />
                <vers edition=":x86_64" num="2.6.25.9" />
                <vers edition="rc4" num="2.6.26" />
                <vers num="2.6.26.1" />
                <vers num="2.6.26.2" />
                <vers num="2.6.26.3" />
                <vers num="2.6.26.4" />
                <vers num="2.6.26.5" />
                <vers num="2.6.26.6" />
                <vers num="2.6.26.7" />
                <vers num="2.6.26.8" />
                <vers edition="rc1" num="2.6.27" />
                <vers edition="rc2" num="2.6.27" />
                <vers edition="rc3" num="2.6.27" />
                <vers edition="rc4" num="2.6.27" />
                <vers edition="rc5" num="2.6.27" />
                <vers edition="rc6" num="2.6.27" />
                <vers edition="rc7" num="2.6.27" />
                <vers edition="rc8" num="2.6.27" />
                <vers edition="rc9" num="2.6.27" />
                <vers num="2.6.27.1" />
                <vers num="2.6.27.10" />
                <vers num="2.6.27.11" />
                <vers num="2.6.27.12" />
                <vers num="2.6.27.13" />
                <vers num="2.6.27.14" />
                <vers num="2.6.27.15" />
                <vers num="2.6.27.16" />
                <vers num="2.6.27.17" />
                <vers num="2.6.27.18" />
                <vers num="2.6.27.19" />
                <vers num="2.6.27.2" />
                <vers num="2.6.27.20" />
                <vers num="2.6.27.21" />
                <vers num="2.6.27.22" />
                <vers num="2.6.27.23" />
                <vers num="2.6.27.24" />
                <vers num="2.6.27.25" />
                <vers num="2.6.27.26" />
                <vers num="2.6.27.27" />
                <vers num="2.6.27.28" />
                <vers num="2.6.27.29" />
                <vers num="2.6.27.3" />
                <vers num="2.6.27.30" />
                <vers num="2.6.27.31" />
                <vers num="2.6.27.32" />
                <vers num="2.6.27.33" />
                <vers num="2.6.27.34" />
                <vers num="2.6.27.35" />
                <vers num="2.6.27.36" />
                <vers num="2.6.27.37" />
                <vers num="2.6.27.4" />
                <vers num="2.6.27.5" />
                <vers num="2.6.27.6" />
                <vers num="2.6.27.7" />
                <vers num="2.6.27.8" />
                <vers num="2.6.27.9" />
                <vers edition="git7" num="2.6.28" />
                <vers edition="rc1" num="2.6.28" />
                <vers edition="rc2" num="2.6.28" />
                <vers edition="rc3" num="2.6.28" />
                <vers edition="rc4" num="2.6.28" />
                <vers edition="rc5" num="2.6.28" />
                <vers edition="rc6" num="2.6.28" />
                <vers edition="rc7" num="2.6.28" />
                <vers num="2.6.28.1" />
                <vers num="2.6.28.10" />
                <vers num="2.6.28.2" />
                <vers num="2.6.28.3" />
                <vers num="2.6.28.4" />
                <vers num="2.6.28.5" />
                <vers num="2.6.28.6" />
                <vers num="2.6.28.7" />
                <vers num="2.6.28.8" />
                <vers num="2.6.28.9" />
                <vers edition="git1" num="2.6.29" />
                <vers edition="rc1" num="2.6.29" />
                <vers edition="rc2" num="2.6.29" />
                <vers edition="rc2_git7" num="2.6.29" />
                <vers edition="rc8-kk" num="2.6.29" />
                <vers num="2.6.29.1" />
                <vers num="2.6.29.2" />
                <vers num="2.6.29.3" />
                <vers num="2.6.29.4" />
                <vers num="2.6.29.5" />
                <vers num="2.6.29.6" />
                <vers num="2.6.29.rc1" />
                <vers num="2.6.29.rc2" />
                <vers num="2.6.3" />
                <vers edition="rc1" num="2.6.30" />
                <vers edition="rc2" num="2.6.30" />
                <vers edition="rc3" num="2.6.30" />
                <vers edition="rc4" num="2.6.30" />
                <vers edition="rc4:x86_32" num="2.6.30" />
                <vers edition="rc5" num="2.6.30" />
                <vers edition="rc6" num="2.6.30" />
                <vers edition="rc7-git6" num="2.6.30" />
                <vers num="2.6.30.1" />
                <vers num="2.6.30.2" />
                <vers num="2.6.30.3" />
                <vers num="2.6.30.4" />
                <vers num="2.6.30.5" />
                <vers num="2.6.30.6" />
                <vers num="2.6.30.7" />
                <vers num="2.6.30.8" />
                <vers num="2.6.30.9" />
                <vers edition="rc1" num="2.6.31" />
                <vers edition="rc2" num="2.6.31" />
                <vers edition="rc3" num="2.6.31" />
                <vers edition="rc4" num="2.6.31" />
                <vers edition="rc5" num="2.6.31" />
                <vers edition="rc7" num="2.6.31" />
                <vers edition="rc8" num="2.6.31" />
                <vers num="2.6.31.1" />
                <vers num="2.6.31.2" />
                <vers num="2.6.31.3" />
                <vers num="2.6.31.4" />
                <vers num="2.6.31.5" />
                <vers edition="rc1" num="2.6.32" prev="1" />
                <vers edition="rc3" num="2.6.32" prev="1" />
                <vers edition="rc4" num="2.6.32" prev="1" />
                <vers num="2.6.4" />
                <vers num="2.6.5" />
                <vers num="2.6.6" />
                <vers num="2.6.7" />
                <vers num="2.6.8" />
                <vers num="2.6.8.1" />
                <vers num="2.6.9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3853" seq="2009-3853" severity="High" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-04">
        <desc>
            <descript source="cve">Buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Express 5.3.3.0 through 5.3.6.6, allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www-01.ibm.com/support/docview.wss?uid=swg21405562" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21405562</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3132" adv="1">ADV-2009-3132</ref>
            <ref source="AIXAPAR" url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC61036">IC61036</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="tivoli_storage_manager_client">
                <vers num="5.3.2" />
                <vers num="5.3.3" />
                <vers edition="" num="5.3.3.0" />
                <vers edition=":express" num="5.3.3.0" />
                <vers num="5.3.4" />
                <vers num="5.3.5" />
                <vers num="5.3.5.2" />
                <vers num="5.3.5.3" />
                <vers num="5.3.6" />
                <vers num="5.3.6.1" />
                <vers num="5.3.6.3" />
                <vers num="5.3.6.4" />
                <vers num="5.3.6.5" />
                <vers edition="" num="5.3.6.6" />
                <vers edition=":express" num="5.3.6.6" />
                <vers num="5.4.0.0" />
                <vers num="5.4.1" />
                <vers num="5.4.1.1" />
                <vers num="5.4.1.2" />
                <vers num="5.4.1.6" />
                <vers num="5.4.1.96" />
                <vers num="5.4.2.2" />
                <vers num="5.4.2.7" />
                <vers num="5.5.0.0" />
                <vers num="5.5.0.91" />
                <vers num="5.5.2.1" />
                <vers num="6.1.0.0" />
                <vers num="6.1.0.1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3854" seq="2009-3854" severity="High" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="10.0" modified="2009-11-04">
        <desc>
            <descript source="cve">Buffer overflow in the traditional client scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7 and 5.4 before 5.4.2 allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www-01.ibm.com/support/docview.wss?uid=swg21405562" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21405562</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3132" adv="1">ADV-2009-3132</ref>
            <ref source="AIXAPAR" url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC61058">IC61058</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="tivoli_storage_manager_client">
                <vers num="5.3.0" />
                <vers num="5.3.2" />
                <vers num="5.3.3" />
                <vers num="5.3.4" />
                <vers num="5.3.5" />
                <vers num="5.3.5.2" />
                <vers num="5.3.5.3" />
                <vers num="5.3.6" />
                <vers num="5.3.6.1" />
                <vers num="5.3.6.3" />
                <vers num="5.3.6.4" />
                <vers num="5.3.6.5" />
                <vers num="5.3.6.6" />
                <vers num="5.4.0.0" />
                <vers num="5.4.1.1" />
                <vers num="5.4.1.2" />
                <vers num="5.4.1.6" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3855" seq="2009-3855" severity="High" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-04">
        <desc>
            <descript source="cve">Multiple unspecified vulnerabilities in the (1) UNIX and (2) Linux backup-archive clients, and the (3) OS/400 API client, in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.6, 5.4 before 5.4.2, and 5.5 before 5.5.1, when the MAILPROG option is enabled, allow attackers to read, modify, or delete arbitrary files via unknown vectors.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www-01.ibm.com/support/docview.wss?uid=swg21405562" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21405562</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3132" adv="1">ADV-2009-3132</ref>
            <ref source="AIXAPAR" url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC54489">IC54489</ref>
        </refs>
        <vuln_soft>
            <prod vendor="ibm" name="tivoli_storage_manager_client">
                <vers num="5.3.2" />
                <vers num="5.3.3" />
                <vers num="5.3.4" />
                <vers num="5.3.5" />
                <vers num="5.3.5.2" />
                <vers num="5.3.5.3" />
                <vers num="5.3.6.1" />
                <vers num="5.3.6.3" />
                <vers num="5.3.6.4" />
                <vers num="5.3.6.5" />
                <vers num="5.4.0.0" />
                <vers num="5.4.1" />
                <vers num="5.4.1.1" />
                <vers num="5.4.1.2" />
                <vers num="5.4.1.6" />
                <vers num="5.5.0.0" />
                <vers num="5.5.0.7" />
                <vers num="5.5.0.91" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3856" seq="2009-3856" severity="Medium" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="4.3" modified="2009-11-04">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script or HTML via the calendar parameter.  NOTE: some of these details are obtained from third party information.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37204" adv="1">37204</ref>
            <ref source="MISC" url="http://onsec.ru/vuln?id=10">http://onsec.ru/vuln?id=10</ref>
        </refs>
        <vuln_soft>
            <prod vendor="twiglightcms" name="twilight_cms">
                <vers num="4.0" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3857" seq="2009-3857" severity="Medium" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="4.3" modified="2009-11-04">
        <desc>
            <descript source="cve">Buffer overflow in Softonic International SciTE 1.72 allows user-assisted remote attackers to cause a denial of service (application crash) via a Ruby (.rb) file containing a long string, which triggers the crash when a scroll bar is used.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/51674">scite-editor-file-dos(51674)</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9133">9133</ref>
        </refs>
        <vuln_soft>
            <prod vendor="softonic" name="scite">
                <vers num="1.72" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" name="CVE-2009-3858" seq="2009-3858" severity="Medium" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="4.3" modified="2009-11-04">
        <desc>
            <descript source="cve">Cross-site scripting (XSS) vulnerability in GejoSoft allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI in photos/tags.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/51879">gejosoft-photostags-xss(51879)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1968" adv="1">ADV-2009-1968</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35921" adv="1">35921</ref>
            <ref source="MISC" url="http://packetstormsecurity.org/0907-exploits/gejosoft-xss.txt">http://packetstormsecurity.org/0907-exploits/gejosoft-xss.txt</ref>
            <ref source="OSVDB" url="http://osvdb.org/56061">56061</ref>
        </refs>
        <vuln_soft>
            <prod vendor="gejosoft" name="gejosoft">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3859" seq="2009-3859" severity="High" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-05">
        <desc>
            <descript source="cve">Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .rws file with a long RWS010 entry.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="EEYE" patch="1" url="http://research.eeye.com/html/advisories/published/AD20090710.html" adv="1">AD20090710</ref>
            <ref source="XF" url="http://xforce.iss.net/xforce/xfdb/51625">retinawifiscanner-rws-bo(51625)</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/1862" adv="1">ADV-2009-1862</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1022534">1022534</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/35624" adv="1">35624</ref>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9114">9114</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/35786" adv="1">35786</ref>
            <ref source="OSVDB" url="http://osvdb.org/55744">55744</ref>
        </refs>
        <vuln_soft>
            <prod vendor="eeye" name="retina_network_security_scanner">
                <vers num="5.10.14" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" name="CVE-2009-3860" seq="2009-3860" severity="Medium" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="5.8" modified="2009-11-05">
        <desc>
            <descript source="cve">Multiple insecure method vulnerabilities in Idefense Labs COMRaider allow remote attackers to create or overwrite arbitrary files via the (1) CreateFolder and (2) Copy methods.  NOTE: this might only be a vulnerability in certain insecure configurations of Internet Explorer.</descript>
        </desc>
        <loss_types>
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="BID" url="http://www.securityfocus.com/bid/35725">35725</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/505042/100/0/threaded">20090717 COMRaider Idefense Labs CreateFolder() and Copy() Insecure Method (Hard Disk Filler Exploit)</ref>
            <ref source="MISC" url="http://www.juniper.net/security/auto/vulnerabilities/vuln35725.html">http://www.juniper.net/security/auto/vulnerabilities/vuln35725.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="idefense" name="comraider">
                <vers num="" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" name="CVE-2009-3861" seq="2009-3861" severity="High" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="7.2" modified="2009-11-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in SafeNet SoftRemote 10.8.5 (Build 2) and 10.3.5 (Build 6), and possibly other versions before 10.8.9, allows local users to execute arbitrary code via a long string in a (1) TREENAME or (2) GROUPNAME Policy file (spd).</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <local />
        </range>
        <refs>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3108" adv="1">ADV-2009-3108</ref>
            <ref source="MISC" url="http://www.senseofsecurity.com.au/advisories/SOS-09-008" adv="1">http://www.senseofsecurity.com.au/advisories/SOS-09-008</ref>
            <ref source="SECTRACK" url="http://www.securitytracker.com/id?1023117">1023117</ref>
            <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/507593/100/0/threaded">20091030 SafeNet SoftRemote Local Buffer Overflow - Security Advisory - SOS-09-008</ref>
        </refs>
        <vuln_soft>
            <prod vendor="safenet-inc" name="softremote">
                <vers num="1.7.1" />
                <vers num="1.7.2" />
                <vers num="1.7.7" />
                <vers num="1.8.1" />
                <vers num="1.9.0" />
                <vers num="10.3.5" />
                <vers num="10.7.7" />
                <vers num="10.8.0" />
                <vers num="10.8.1" />
                <vers num="10.8.2" />
                <vers num="10.8.3" />
                <vers num="10.8.4" />
                <vers num="10.8.5" />
                <vers num="10.8.6" />
                <vers num="10.8.7" />
                <vers num="10.8.8" prev="1" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3862" seq="2009-3862" severity="Medium" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="5.0" modified="2009-11-05">
        <desc>
            <descript source="cve">The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="CONFIRM" patch="1" url="http://www.novell.com/support/viewContent.do?externalId=7004721" adv="1">http://www.novell.com/support/viewContent.do?externalId=7004721</ref>
            <ref source="MISC" url="http://www.zerodayinitiative.com/advisories/ZDI-09-075/">http://www.zerodayinitiative.com/advisories/ZDI-09-075/</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3120">ADV-2009-3120</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36902">36902</ref>
        </refs>
        <vuln_soft>
            <prod vendor="novell" name="edirectory">
                <vers edition="sp2" num="8.7.3" />
                <vers edition="sp2:windows" num="8.7.3" />
                <vers edition="sp3" num="8.7.3" />
                <vers edition="sp3:windows" num="8.7.3" />
                <vers edition="sp4" num="8.7.3" />
                <vers edition="sp4:windows" num="8.7.3" />
                <vers edition="sp5" num="8.7.3" />
                <vers edition="sp5:windows" num="8.7.3" />
                <vers edition="sp6" num="8.7.3" />
                <vers edition="sp6:windows" num="8.7.3" />
                <vers edition="sp7" num="8.7.3" />
                <vers edition="sp7:windows" num="8.7.3" />
                <vers edition="sp8" num="8.7.3" />
                <vers edition="sp8:windows" num="8.7.3" />
                <vers edition="sp9" num="8.7.3" />
                <vers edition="sp9:windows" num="8.7.3" />
                <vers num="8.7.3.8" />
                <vers num="8.7.3.9" />
                <vers edition="sp1" num="8.8" />
                <vers edition="sp2" num="8.8" />
                <vers edition="sp3" num="8.8" />
                <vers edition="sp4" num="8.8" />
                <vers num="8.8.1" />
                <vers num="8.8.2" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3863" seq="2009-3863" severity="Medium" type="CVE" published="2009-11-04" CVSS_version="2.0" CVSS_score="5.0" modified="2009-11-05">
        <desc>
            <descript source="cve">Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (application crash) via a long argument to the SetFontFace method.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="MILW0RM" url="http://www.milw0rm.com/exploits/9683">9683</ref>
        </refs>
        <vuln_soft>
            <prod vendor="novell" name="groupwise">
                <vers num="7.0.3.1294" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" name="CVE-2009-3864" seq="2009-3864" severity="High" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="7.5" modified="2009-11-05">
        <desc>
            <descript source="cve">The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1" adv="1">269868</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_10" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3865" seq="2009-3865" severity="High" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-05">
        <desc>
            <descript source="cve">The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
            <sec_prot admin="1" />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="VUPEN" patch="1" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="BID" patch="1" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1" adv="1">269869</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3866" seq="2009-3866" severity="High" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-05">
        <desc>
            <descript source="cve">The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://zerodayinitiative.com/advisories/ZDI-09-077/">http://zerodayinitiative.com/advisories/ZDI-09-077/</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269870-1" adv="1">269870</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3867" seq="2009-3867" severity="High" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://zerodayinitiative.com/advisories/ZDI-09-076/">http://zerodayinitiative.com/advisories/ZDI-09-076/</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1" adv="1">270474</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023132" adv="1">1023132</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_10" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_1" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="sdk">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3868" seq="2009-3868" severity="High" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-05">
        <desc>
            <descript source="cve">Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1" adv="1">270474</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023132">1023132</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_10" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_1" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="sdk">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3869" seq="2009-3869" severity="High" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-05">
        <desc>
            <descript source="cve">Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://zerodayinitiative.com/advisories/ZDI-09-078/">http://zerodayinitiative.com/advisories/ZDI-09-078/</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1" adv="1">270474</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023132">1023132</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_10" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_1" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="sdk">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3871" seq="2009-3871" severity="High" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-05">
        <desc>
            <descript source="cve">Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://zerodayinitiative.com/advisories/ZDI-09-079/">http://zerodayinitiative.com/advisories/ZDI-09-079/</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1" adv="1">270474</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023132">1023132</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_10" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_1" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="sdk">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" name="CVE-2009-3872" seq="2009-3872" severity="High" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="10.0" modified="2009-11-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1" adv="1">270474</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023132">1023132</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_10" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_1" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="sdk">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" name="CVE-2009-3873" seq="2009-3873" severity="Low" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="0.0" modified="2009-11-05">
        <desc>
            <descript source="cve">The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.</descript>
        </desc>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1" adv="1">270474</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023132">1023132</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_10" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_1" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="sdk">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" name="CVE-2009-3874" seq="2009-3874" severity="High" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="9.3" modified="2009-11-05">
        <desc>
            <descript source="cve">Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643.</descript>
        </desc>
        <loss_types>
            <avail />
            <conf />
            <int />
        </loss_types>
        <range>
            <network />
            <user_init />
        </range>
        <refs>
            <ref source="MISC" patch="1" url="http://zerodayinitiative.com/advisories/ZDI-09-080/">http://zerodayinitiative.com/advisories/ZDI-09-080/</ref>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1" adv="1">270474</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SECTRACK" url="http://securitytracker.com/id?1023132">1023132</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_10" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_1" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="sdk">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3875" seq="2009-3875" severity="Medium" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="5.0" modified="2009-11-05">
        <desc>
            <descript source="cve">The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to "timing attack vulnerabilities," aka Bug Id 6863503.</descript>
        </desc>
        <loss_types>
            <int />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270475-1" adv="1">270475</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_10" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_1" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="sdk">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3876" seq="2009-3876" severity="Medium" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="5.0" modified="2009-11-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser, aka Bug Id 6864911.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270476-1" adv="1">270476</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_10" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_1" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="sdk">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4.2_8" />
                <vers num="1.4.2_9" />
            </prod>
        </vuln_soft>
    </entry>
    <entry CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" name="CVE-2009-3877" seq="2009-3877" severity="Medium" type="CVE" published="2009-11-05" CVSS_version="2.0" CVSS_score="5.0" modified="2009-11-05">
        <desc>
            <descript source="cve">Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911.</descript>
        </desc>
        <loss_types>
            <avail />
        </loss_types>
        <range>
            <network />
        </range>
        <refs>
            <ref source="SUNALERT" patch="1" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270476-1" adv="1">270476</ref>
            <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2009/3131" adv="1">ADV-2009-3131</ref>
            <ref source="BID" url="http://www.securityfocus.com/bid/36881">36881</ref>
            <ref source="SECUNIA" url="http://secunia.com/advisories/37231" adv="1">37231</ref>
            <ref source="CONFIRM" url="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</ref>
        </refs>
        <vuln_soft>
            <prod vendor="sun" name="jdk">
                <vers edition="update_1" num="1.5.0" />
                <vers edition="update_10" num="1.5.0" />
                <vers edition="update_11" num="1.5.0" />
                <vers edition="update_12" num="1.5.0" />
                <vers edition="update_13" num="1.5.0" />
                <vers edition="update_14" num="1.5.0" />
                <vers edition="update_15" num="1.5.0" />
                <vers edition="update_16" num="1.5.0" />
                <vers edition="update_17" num="1.5.0" />
                <vers edition="update_18" num="1.5.0" />
                <vers edition="update_19" num="1.5.0" />
                <vers edition="update_2" num="1.5.0" />
                <vers edition="update_20" num="1.5.0" />
                <vers edition="update_21" num="1.5.0" />
                <vers edition="update_3" num="1.5.0" />
                <vers edition="update_4" num="1.5.0" />
                <vers edition="update_5" num="1.5.0" />
                <vers edition="update_6" num="1.5.0" />
                <vers edition="update_7" num="1.5.0" />
                <vers edition="update_8" num="1.5.0" />
                <vers edition="update_9" num="1.5.0" />
                <vers edition="update_1" num="1.6.0" />
                <vers edition="update_10" num="1.6.0" />
                <vers edition="update_11" num="1.6.0" />
                <vers edition="update_12" num="1.6.0" />
                <vers edition="update_13" num="1.6.0" />
                <vers edition="update_14" num="1.6.0" />
                <vers edition="update_15" num="1.6.0" />
                <vers edition="update_16" num="1.6.0" />
                <vers edition="update_2" num="1.6.0" />
                <vers edition="update_3" num="1.6.0" />
                <vers edition="update_4" num="1.6.0" />
                <vers edition="update_5" num="1.6.0" />
                <vers edition="update_6" num="1.6.0" />
                <vers edition="update_7" num="1.6.0" />
                <vers edition="update_8" num="1.6.0" />
                <vers edition="update_9" num="1.6.0" />
            </prod>
            <prod vendor="sun" name="jre">
                <vers num="1.3.1_01" />
                <vers num="1.3.1_01a" />
                <vers num="1.3.1_02" />
                <vers num="1.3.1_03" />
                <vers num="1.3.1_04" />
                <vers num="1.3.1_05" />
                <vers num="1.3.1_06" />
                <vers num="1.3.1_07" />
                <vers num="1.3.1_08" />
                <vers num="1.3.1_09" />
                <vers num="1.3.1_1" />
                <vers num="1.3.1_10" />
                <vers num="1.3.1_11" />
                <vers num="1.3.1_12" />
                <vers num="1.3.1_13" />
                <vers num="1.3.1_14" />
                <vers num="1.3.1_15" />
                <vers num="1.3.1_16" />
                <vers num="1.3.1_17" />
                <vers num="1.3.1_18" />
                <vers num="1.3.1_19" />
                <vers num="1.3.1_2" />
                <vers num="1.3.1_20" />
                <vers num="1.3.1_21" />
                <vers num="1.3.1_22" />
                <vers num="1.3.1_23" />
                <vers num="1.3.1_24" />
                <vers num="1.3.1_25" />
                <vers num="1.3.1_3" />
                <vers num="1.3.1_4" />
                <vers num="1.3.1_5" />
                <vers num="1.3.1_6" />
                <vers num="1.3.1_7" />
                <vers num="1.3.1_8" />
                <vers num="1.3.1_9" />
                <vers num="1.4.2_01" />
                <vers num="1.4.2_02" />
                <vers num="1.4.2_03" />
                <vers num="1.4.2_04" />
                <vers num="1.4.2_05" />
                <vers num="1.4.2_06" />
                <vers num="1.4.2_07" />
                <vers num="1.4.2_08" />
                <vers num="1.4.2_09" />
                <vers num="1.4.2_1" />
                <vers num="1.4.2_10" />
                <vers num="1.4.2_11" />
                <vers num="1.4.2_12" />
                <vers num="1.4.2_13" />
                <vers num="1.4.2_14" />
                <vers num="1.4.2_15" />
                <vers num="1.4.2_16" />
                <vers num="1.4.2_17" />
                <vers num="1.4.2_18" />
                <vers num="1.4.2_19" />
                <vers num="1.4.2_2" />
                <vers num="1.4.2_20" />
                <vers num="1.4.2_21" />
                <vers num="1.4.2_22" />
                <vers num="1.4.2_3" />
                <vers num="1.4.2_4" />
                <vers num="1.4.2_5" />
                <vers num="1.4.2_6" />
                <vers num="1.4.2_7" />
                <vers num="1.4