<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:patch="http://scap.nist.gov/schema/patch/0.1" xmlns:cvss="http://scap.nist.gov/schema/cvss-v2/0.2" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/0.1" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://scap.nist.gov/schema/feed/vulnerability/2.0" xmlns:vuln="http://scap.nist.gov/schema/vulnerability/0.4" nvd_xml_version="2.0" pub_date="2013-05-21T07:27:18" xsi:schemaLocation="http://scap.nist.gov/schema/patch/0.1 http://nvd.nist.gov/schema/patch_0.1.xsd http://scap.nist.gov/schema/scap-core/0.1 http://nvd.nist.gov/schema/scap-core_0.1.xsd http://scap.nist.gov/schema/feed/vulnerability/2.0 http://nvd.nist.gov/schema/nvd-cve-feed_2.0.xsd">
  <entry id="CVE-1999-0001">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.7"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:2.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.7</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.7.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6.1</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:3.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.1.5.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0001</vuln:cve-id>
    <vuln:published-datetime>1999-12-30T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-12-16T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-20"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/5707" xml:lang="en">5707</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.openbsd.org/errata23.html#tcpfix" xml:lang="en">http://www.openbsd.org/errata23.html#tcpfix</vuln:reference>
    </vuln:references>
    <vuln:summary>ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0002">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:caldera:openlinux:1.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:3.0.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:2.1</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:1.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:2.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0002</vuln:cve-id>
    <vuln:published-datetime>1998-10-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-01-26T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/121" xml:lang="en">121</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/j-006.shtml" xml:lang="en">J-006</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19981006-01-I" xml:lang="en">19981006-01-I</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0003">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tritreal:ted_cde:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.02"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.03"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/a:tritreal:ted_cde:4.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.02</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.03</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0003</vuln:cve-id>
    <vuln:published-datetime>1998-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:30.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/122" xml:lang="en">122</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-PX" xml:lang="en">19981101-01-PX</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-A" xml:lang="en">19981101-01-A</vuln:reference>
    </vuln:references>
    <vuln:summary>Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).</vuln:summary>
  </entry>
  <entry id="CVE-1999-0004">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:dtmail"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pine:4.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_washington:pine:4.02</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.0</vuln:product>
      <vuln:product>cpe:/a:hp:dtmail</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0004</vuln:cve-id>
    <vuln:published-datetime>1997-12-16T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:31.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms98-008.asp" xml:lang="en">MS98-008</vuln:reference>
    </vuln:references>
    <vuln:summary>MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0005">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netscape:messaging_server:3.55"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:imap:10.234"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_washington:imap:10.234</vuln:product>
      <vuln:product>cpe:/a:netscape:messaging_server:3.55</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0005</vuln:cve-id>
    <vuln:published-datetime>1998-07-20T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:31.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/130" xml:lang="en">130</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/177" xml:lang="en">00177</vuln:reference>
    </vuln:references>
    <vuln:summary>Arbitrary command execution via IMAP buffer overflow in authenticate command.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0006">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:qpopper:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qualcomm:qpopper:2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0006</vuln:cve-id>
    <vuln:published-datetime>1998-07-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:31.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/133" xml:lang="en">133</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I" xml:lang="en">19980801-01-I</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0007">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:c2net:stonghold_web_server:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/a:c2net:stonghold_web_server:2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:c2net:stonghold_web_server:2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:site_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:certificate_server:1.0:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:collabra_server:3.5.2"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:directory_server:1.3:patch5"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:directory_server:3.1:patch1"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:directory_server:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:enterprise_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:enterprise_server:3.0.1b"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:enterprise_server:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:fasttrack_server:3.01b"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:messaging_server:3.54"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:proxy_server:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/a:open_market:secure_webserver:2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ssleay:ssleay:0.6.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ssleay:ssleay:0.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ssleay:ssleay:0.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:open_market:secure_webserver:2.1</vuln:product>
      <vuln:product>cpe:/a:ssleay:ssleay:0.9</vuln:product>
      <vuln:product>cpe:/a:netscape:directory_server:1.3:patch5</vuln:product>
      <vuln:product>cpe:/a:netscape:certificate_server:1.0:patch1</vuln:product>
      <vuln:product>cpe:/a:netscape:directory_server:3.1:patch1</vuln:product>
      <vuln:product>cpe:/a:c2net:stonghold_web_server:2.2</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5</vuln:product>
      <vuln:product>cpe:/a:netscape:proxy_server:3.5.1</vuln:product>
      <vuln:product>cpe:/a:netscape:enterprise_server:3.0.1b</vuln:product>
      <vuln:product>cpe:/a:c2net:stonghold_web_server:2.3</vuln:product>
      <vuln:product>cpe:/a:netscape:enterprise_server:2.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:3.0</vuln:product>
      <vuln:product>cpe:/a:c2net:stonghold_web_server:2.0.1</vuln:product>
      <vuln:product>cpe:/a:netscape:collabra_server:3.5.2</vuln:product>
      <vuln:product>cpe:/a:ssleay:ssleay:0.6.6</vuln:product>
      <vuln:product>cpe:/a:netscape:messaging_server:3.54</vuln:product>
      <vuln:product>cpe:/a:netscape:fasttrack_server:3.01b</vuln:product>
      <vuln:product>cpe:/a:ssleay:ssleay:0.8.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:site_server:3.0</vuln:product>
      <vuln:product>cpe:/a:netscape:enterprise_server:3.5.1</vuln:product>
      <vuln:product>cpe:/a:netscape:directory_server:3.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0007</vuln:cve-id>
    <vuln:published-datetime>1998-06-26T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms98-002.mspx" xml:lang="en">MS98-002</vuln:reference>
    </vuln:references>
    <vuln:summary>Information from SSL-encrypted sessions via PKCS #1.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0008">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0008</vuln:cve-id>
    <vuln:published-datetime>1998-06-08T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:31.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/170" xml:lang="en">00170</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in NIS+, in Sun's rpc.nisd program.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0009">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:5.4_3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:5.4_3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:5.4_4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:5.4_4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.6"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.1t"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.4b"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.4t"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5_iop"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5_ipr"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5a"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5d"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5e"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5g"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5h"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:asl_ux_4800:64"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:4.0.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.1</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:5.4_3.1</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5a</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5_iop</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5f</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3.3.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5d</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.4t</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.4</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:5.4_4.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5g</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.1t</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3.3.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:5.4_3.0</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:5.4_4.11</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:2.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5e</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.2</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.4b</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:5.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3.3.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5h</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.2.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.0</vuln:product>
      <vuln:product>cpe:/o:caldera:openlinux:1.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5</vuln:product>
      <vuln:product>cpe:/o:nec:asl_ux_4800:64</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5_ipr</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0009</vuln:cve-id>
    <vuln:published-datetime>1998-04-08T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:31.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083" xml:lang="en">HPSBUX9808-083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/134" xml:lang="en">134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180" xml:lang="en">00180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX" xml:lang="en">19980603-01-PX</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6051" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6051" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0010">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:y2k_patchr4.11mu05"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:y2k_patchr4.12mu03"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:y2k_patchr4.20mu01"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:y2k_patchr4.20mu02"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:y2k_patchr4.20mu03"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:asl_ux_4800:11"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:asl_ux_4800:13"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unix:3.2v4"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:y2k_patchr4.11mu05</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:5.5</vuln:product>
      <vuln:product>cpe:/o:sco:unix:3.2v4</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:y2k_patchr4.12mu03</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:2.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.1</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.0</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:5.6</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:y2k_patchr4.20mu02</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:5.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:5.4</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:y2k_patchr4.20mu01</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:y2k_patchr4.20mu03</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.0</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3</vuln:product>
      <vuln:product>cpe:/o:nec:asl_ux_4800:11</vuln:product>
      <vuln:product>cpe:/o:nec:asl_ux_4800:13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0010</vuln:cve-id>
    <vuln:published-datetime>1998-04-08T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083" xml:lang="en">HPSBUX9808-083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX" xml:lang="en">19980603-01-PX</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5833" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5833" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0011">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:y2k_patchr4.11mu05"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:y2k_patchr4.12mu03"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:y2k_patchr4.20mu01"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:y2k_patchr4.20mu02"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:y2k_patchr4.20mu03"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:asl_ux_4800:11"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:asl_ux_4800:13"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unix:3.2v4"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:5.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:y2k_patchr4.11mu05</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:5.5</vuln:product>
      <vuln:product>cpe:/o:sco:unix:3.2v4</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:y2k_patchr4.12mu03</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:2.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.1</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.0</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:5.6</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:y2k_patchr4.20mu02</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:5.3</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:5.4</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:y2k_patchr4.20mu01</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:y2k_patchr4.20mu03</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.0</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3</vuln:product>
      <vuln:product>cpe:/o:nec:asl_ux_4800:11</vuln:product>
      <vuln:product>cpe:/o:nec:asl_ux_4800:13</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0011</vuln:cve-id>
    <vuln:published-datetime>1998-04-08T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:31.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083" xml:lang="en">HPSBUX9808-083</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180" xml:lang="en">00180</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX" xml:lang="en">19980603-01-PX</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5966" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5966" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0012">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:frontpage"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:personal_web_server:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:enterprise_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:fasttrack_server:2.01"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:fasttrack_server:3.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:personal_web_server:4.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:frontpage</vuln:product>
      <vuln:product>cpe:/a:netscape:fasttrack_server:3.01</vuln:product>
      <vuln:product>cpe:/a:netscape:enterprise_server:3.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
      <vuln:product>cpe:/a:netscape:fasttrack_server:2.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0012</vuln:cve-id>
    <vuln:published-datetime>1998-02-06T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:31.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0013">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.10"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.12"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.13"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.14"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.2"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.5"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.7"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.8"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ssh:ssh:1.2.6</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.3</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.0</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.2</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.4</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.10</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.5</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.11</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.7</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.12</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.8</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.9</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.13</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.14</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0013</vuln:cve-id>
    <vuln:published-datetime>1998-01-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:32.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0014">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cde:cde:1.01"/>
        <cpe-lang:fact-ref name="cpe:/a:cde:cde:1.01_x86"/>
        <cpe-lang:fact-ref name="cpe:/a:cde:cde:1.02"/>
        <cpe-lang:fact-ref name="cpe:/a:cde:cde:1.02_x86"/>
        <cpe-lang:fact-ref name="cpe:/a:cde:cde:1.2"/>
        <cpe-lang:fact-ref name="cpe:/a:cde:cde:1.2_x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:vvos:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cde:cde:1.2</vuln:product>
      <vuln:product>cpe:/a:cde:cde:1.02_x86</vuln:product>
      <vuln:product>cpe:/a:cde:cde:1.2_x86</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/a:cde:cde:1.01_x86</vuln:product>
      <vuln:product>cpe:/a:cde:cde:1.01</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/a:cde:cde:1.02</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:vvos:10.24</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0014</vuln:cve-id>
    <vuln:published-datetime>1998-01-21T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:32.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-075" xml:lang="en">HPSBUX9801-075</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/185" xml:lang="en">00185</vuln:reference>
    </vuln:references>
    <vuln:summary>Unauthorized privileged access or denial of service via dtappgather program in CDE.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0015">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.03"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.05"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.07"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_95:0.0a"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_95:0.0a</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp2</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.01</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.03</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.2.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.07</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.05</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0015</vuln:cve-id>
    <vuln:published-datetime>1997-12-16T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-04T00:00:06.593-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5579" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5579" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5579" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5579" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Teardrop IP denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0016">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:7000"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/a:gnu:inet:5.01"/>
          <cpe-lang:fact-ref name="cpe:/a:microsoft:winsock:2.0"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.03"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.05"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.07"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_95"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_95</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:winsock:2.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.07</vuln:product>
      <vuln:product>cpe:/a:gnu:inet:5.01</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.05</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:7000</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.01</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.03</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0016</vuln:cve-id>
    <vuln:published-datetime>1997-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:32.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076" xml:lang="en">HPSBUX9801-076</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5727" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5727" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5835" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5835" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Land IP denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0017">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:inet:5.01"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:inet:6.01"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:inet:6.02"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.7"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:siemens:reliant_unix"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.1</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:2.1</vuln:product>
      <vuln:product>cpe:/o:siemens:reliant_unix</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.4::x86</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.4</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5::x86</vuln:product>
      <vuln:product>cpe:/o:caldera:openlinux:1.2</vuln:product>
      <vuln:product>cpe:/a:gnu:inet:6.02</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.2.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.7</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.0</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
      <vuln:product>cpe:/a:gnu:inet:5.01</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/a:gnu:inet:6.01</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0017</vuln:cve-id>
    <vuln:published-datetime>1997-12-10T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:32.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:summary>FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0018">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0018</vuln:cve-id>
    <vuln:published-datetime>1997-12-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:32.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/127" xml:lang="en">127</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in statd allows root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0019">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:4.11"/>
        <cpe-lang:fact-ref name="cpe:/a:ncr:mp-ras:2.03"/>
        <cpe-lang:fact-ref name="cpe:/a:ncr:mp-ras:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:nighthawk:cx_ux"/>
        <cpe-lang:fact-ref name="cpe:/o:nighthawk:powerux"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:2"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:5.5::x86</vuln:product>
      <vuln:product>cpe:/a:ncr:mp-ras:2.03</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.3</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:3</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:3.0</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:2</vuln:product>
      <vuln:product>cpe:/o:nighthawk:cx_ux</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:4.11</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.4::x86</vuln:product>
      <vuln:product>cpe:/a:ncr:mp-ras:3.0</vuln:product>
      <vuln:product>cpe:/o:nighthawk:powerux</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0019</vuln:cve-id>
    <vuln:published-datetime>1996-04-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:32.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/135" xml:lang="en">00135</vuln:reference>
    </vuln:references>
    <vuln:summary>Delete or create a file via rpc.statd, due to invalid information.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0020">
    <vuln:cve-id>CVE-1999-0020</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:34.853-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0032.  Reason: This candidate is a duplicate of CVE-1999-0032.  Notes: All CVE users should reference CVE-1999-0032 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0021">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:muhammad_a._muquit:wwwcount:2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:muhammad_a._muquit:wwwcount:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0021</vuln:cve-id>
    <vuln:published-datetime>1997-11-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:34.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/128" xml:lang="en">128</vuln:reference>
    </vuln:references>
    <vuln:summary>Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0022">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:4.1.3:u1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:1.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1::xfs</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:4.1.3:u1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:4.1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3::xfs</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:4.1.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:4.1.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0022</vuln:cve-id>
    <vuln:published-datetime>1996-07-03T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:34.993-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/179" xml:lang="en">00179</vuln:reference>
    </vuln:references>
    <vuln:summary>Local user gains root privileges via buffer overflow in rdist, via expstr() function.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0023">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:inet:inet:5.01"/>
        <cpe-lang:fact-ref name="cpe:/a:inet:inet:6.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:tcp_ip:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:tcp_ip:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1.1a</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sco:internet_faststart:1.0</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:2.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1.2</vuln:product>
      <vuln:product>cpe:/a:inet:inet:5.01</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sco:tcp_ip:1.2.1</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:2.0</vuln:product>
      <vuln:product>cpe:/a:inet:inet:6.01</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:2.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.3</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:sco:tcp_ip:1.2.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:2.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0023</vuln:cve-id>
    <vuln:published-datetime>1996-07-24T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:35.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Local user gains root privileges via buffer overflow in rdist, via lookup() function.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0024">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:4.9.5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:asl_ux_4800:64"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:ews-ux_v:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:ews-ux_v:4.2mp"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:up-ux_v:4.2mp"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unix:3.2v4"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:nec:ews-ux_v:4.2</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sco:unix:3.2v4</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:2.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:nec:asl_ux_4800:64</vuln:product>
      <vuln:product>cpe:/a:isc:bind:4.9.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/a:isc:bind:8.1</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:3.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:nec:ews-ux_v:4.2mp</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:nec:up-ux_v:4.2mp</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0024</vuln:cve-id>
    <vuln:published-datetime>1997-08-13T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:35.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>DNS cache poisoning via BIND, by predictable query IDs.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0025">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0025</vuln:cve-id>
    <vuln:published-datetime>1997-07-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:35.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT-VN</vuln:source>
      <vuln:reference href="http://www.kb.cert.org/vuls/id/20851" xml:lang="en">VU#20851</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-1997-21.html" xml:lang="en">CA-1997-21</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/440" xml:lang="en">df-bo(440)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/346" xml:lang="en">346</vuln:reference>
    </vuln:references>
    <vuln:summary>root privileges via buffer overflow in df command on SGI IRIX systems.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0026">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0026</vuln:cve-id>
    <vuln:published-datetime>1997-07-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:35.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>root privileges via buffer overflow in pset command on SGI IRIX systems.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0027">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0027</vuln:cve-id>
    <vuln:published-datetime>1997-07-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-02-25T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:cwe id="CWE-119"/>
    <vuln:summary>root privileges via buffer overflow in eject command on SGI IRIX systems.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0028">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0028</vuln:cve-id>
    <vuln:published-datetime>1997-07-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:35.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>root privileges via buffer overflow in login/scheme command on SGI IRIX systems.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0029">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0029</vuln:cve-id>
    <vuln:published-datetime>1997-07-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:35.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>root privileges via buffer overflow in ordist command on SGI IRIX systems.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0030">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0030</vuln:cve-id>
    <vuln:published-datetime>1997-07-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:35.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>root privileges via buffer overflow in xlock command on SGI IRIX systems.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0031">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:communicator:3.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:3.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:4.0</vuln:product>
      <vuln:product>cpe:/a:netscape:communicator:4.0</vuln:product>
      <vuln:product>cpe:/a:netscape:communicator:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0031</vuln:cve-id>
    <vuln:published-datetime>1997-07-08T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:35.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html" xml:lang="en">HPSBUX9707-065</vuln:reference>
    </vuln:references>
    <vuln:summary>JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0032">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:next:nextstep:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:next:nextstep:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:next:nextstep:4.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
      <vuln:product>cpe:/o:next:nextstep:4.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0032</vuln:cve-id>
    <vuln:published-datetime>1996-10-25T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:35.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/707" xml:lang="en">707</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/i-042.shtml" xml:lang="en">I-042</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX" xml:lang="en">19980402-01-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0033">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ncr:mp-ras:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:3.2v4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:5.5::x86</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.3</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:2.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:3.0</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:3.2v4</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1::x86</vuln:product>
      <vuln:product>cpe:/a:ncr:mp-ras:3.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.4::x86</vuln:product>
      <vuln:product>cpe:/o:ibm:aix</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0033</vuln:cve-id>
    <vuln:published-datetime>1997-06-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:35.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Command execution in Sun systems via buffer overflow in the at program.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0034">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:larry_wall:perl:5.3"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:freeware:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:freeware:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:larry_wall:perl:5.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.1</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:3.0</vuln:product>
      <vuln:product>cpe:/a:sgi:freeware:1.0</vuln:product>
      <vuln:product>cpe:/a:sgi:freeware:2.0</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0034</vuln:cve-id>
    <vuln:published-datetime>1997-05-29T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0035">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:inet:5.01"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
      <vuln:product>cpe:/a:gnu:inet:5.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0035</vuln:cve-id>
    <vuln:published-datetime>1997-05-29T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0036">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0036</vuln:cve-id>
    <vuln:published-datetime>1997-05-26T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/557" xml:lang="en">sgi-lockout(557)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/990" xml:lang="en">990</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/h-106.shtml" xml:lang="en">H-106</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX" xml:lang="en">19970508-02-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0037">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2:stable</vuln:product>
      <vuln:product>cpe:/o:redhat:linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0037</vuln:cve-id>
    <vuln:published-datetime>1997-05-21T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0038">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.93"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.08"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:data_general:dg_ux:2.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:0.93</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:1.1</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:3.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1::xfs</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.08</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:4.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:1.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:5.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3::xfs</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:1.3</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:1.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:7.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:6.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0038</vuln:cve-id>
    <vuln:published-datetime>1997-04-26T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in xlock program allows local users to execute commands as root.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0039">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0039</vuln:cve-id>
    <vuln:published-datetime>1997-05-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.367-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-1997-12.html" xml:lang="en">CA-1997-12</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/333" xml:lang="en">http-sgi-webdist(333)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/374" xml:lang="en">374</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/235" xml:lang="en">235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX" xml:lang="en">19970501-02-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0040">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.08"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.09"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.10"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:asl_ux_4800:64"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:ews-ux_v:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:ews-ux_v:4.2mp"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:up-ux_v:4.2mp"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:nec:ews-ux_v:4.2</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.10</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.01</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.08</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:nec:up-ux_v:4.2mp</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.0.1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.09</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
      <vuln:product>cpe:/o:nec:asl_ux_4800:64</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.00</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:nec:ews-ux_v:4.2mp</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.1.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0040</vuln:cve-id>
    <vuln:published-datetime>1997-05-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0041">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:libc:5.0.9"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:libc:5.2.18"/>
        <cpe-lang:fact-ref name="cpe:/a:gnu:libc:5.3.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:1.5::mk"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos_max:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
      <vuln:product>cpe:/a:gnu:libc:5.2.18</vuln:product>
      <vuln:product>cpe:/a:gnu:libc:5.0.9</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:1.5::mk</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:9.0</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.1</vuln:product>
      <vuln:product>cpe:/a:gnu:libc:5.3.12</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:9.2</vuln:product>
      <vuln:product>cpe:/o:cray:unicos_max:1.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0041</vuln:cve-id>
    <vuln:published-datetime>1997-02-13T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in NLS (Natural Language Service).</vuln:summary>
  </entry>
  <entry id="CVE-1999-0042">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:imap:4"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:pop:3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_washington:imap:4</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:3.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:2.0</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2.1</vuln:product>
      <vuln:product>cpe:/o:caldera:openlinux:1.0</vuln:product>
      <vuln:product>cpe:/a:university_of_washington:pop:3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0042</vuln:cve-id>
    <vuln:published-datetime>1997-04-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in University of Washington's implementation of IMAP and POP servers.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0043">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4sec"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4sec2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4unoff3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4unoff4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:news_server:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:nec:goah_intrasv:1.1"/>
        <cpe-lang:fact-ref name="cpe:/h:nec:goah_networksv:1.2"/>
        <cpe-lang:fact-ref name="cpe:/h:nec:goah_networksv:2.2"/>
        <cpe-lang:fact-ref name="cpe:/h:nec:goah_networksv:3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:inn:1.5</vuln:product>
      <vuln:product>cpe:/a:netscape:news_server:1.1</vuln:product>
      <vuln:product>cpe:/h:nec:goah_networksv:1.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.1</vuln:product>
      <vuln:product>cpe:/a:isc:inn:1.4sec2</vuln:product>
      <vuln:product>cpe:/a:isc:inn:1.4unoff3</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:caldera:openlinux:1.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.0</vuln:product>
      <vuln:product>cpe:/a:isc:inn:1.4unoff4</vuln:product>
      <vuln:product>cpe:/h:nec:goah_intrasv:1.1</vuln:product>
      <vuln:product>cpe:/h:nec:goah_networksv:3.1</vuln:product>
      <vuln:product>cpe:/h:nec:goah_networksv:2.2</vuln:product>
      <vuln:product>cpe:/a:isc:inn:1.4sec</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0043</vuln:cve-id>
    <vuln:published-datetime>1996-12-04T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0044">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0044</vuln:cve-id>
    <vuln:published-datetime>1996-12-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P" xml:lang="en">19970301-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0045">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:0.8.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:0.8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:commerce_server:1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:communications_server:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:communications_server:1.12"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:enterprise_server:2.0a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:communications_server:1.12</vuln:product>
      <vuln:product>cpe:/a:netscape:commerce_server:1.12</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0</vuln:product>
      <vuln:product>cpe:/a:netscape:communications_server:1.1</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0.5</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:0.8.11</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.1</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:0.8.14</vuln:product>
      <vuln:product>cpe:/a:netscape:enterprise_server:2.0a</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0045</vuln:cve-id>
    <vuln:published-datetime>1996-12-10T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>List of arbitrary files on Web host via nph-test-cgi script.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0046">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:0.93"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:4.3a"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:ultrix:4.5"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:unix:3.2g"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:unix:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:unix:4.0a"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:unix:4.0b"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.08"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.09"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.34"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:next:nextstep:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:next:nextstep:1.0a"/>
        <cpe-lang:fact-ref name="cpe:/o:next:nextstep:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:next:nextstep:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:next:nextstep:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:next:nextstep:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:next:nextstep:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:next:nextstep:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:next:nextstep:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:data_general:dg_ux:2.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:0.93</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:digital:ultrix:3.0</vuln:product>
      <vuln:product>cpe:/o:next:nextstep:3.1</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:next:nextstep:4.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
      <vuln:product>cpe:/o:digital:unix:4.0a</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:next:nextstep:3.0</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:3.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
      <vuln:product>cpe:/o:digital:unix:4.0</vuln:product>
      <vuln:product>cpe:/o:digital:unix:3.2g</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.08</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.09</vuln:product>
      <vuln:product>cpe:/o:next:nextstep:3.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.34</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:1.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.1.5.1</vuln:product>
      <vuln:product>cpe:/o:next:nextstep:1.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:digital:ultrix:4.2</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.2</vuln:product>
      <vuln:product>cpe:/o:next:nextstep:3.3</vuln:product>
      <vuln:product>cpe:/o:next:nextstep:2.0</vuln:product>
      <vuln:product>cpe:/o:next:nextstep:1.0a</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:digital:ultrix:4.3a</vuln:product>
      <vuln:product>cpe:/o:digital:ultrix:2.2</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:digital:unix:4.0b</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:1.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
      <vuln:product>cpe:/a:data_general:dg_ux:4.0</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.0.1</vuln:product>
      <vuln:product>cpe:/o:next:nextstep:2.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.0</vuln:product>
      <vuln:product>cpe:/o:digital:ultrix:4.0</vuln:product>
      <vuln:product>cpe:/o:digital:ultrix:4.4</vuln:product>
      <vuln:product>cpe:/o:digital:ultrix:4.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:digital:ultrix:4.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:digital:ultrix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0046</vuln:cve-id>
    <vuln:published-datetime>1997-02-06T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow of rlogin program using TERM environmental variable.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0047">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.3"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.8.4</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.8.3</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:caldera:openlinux:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0047</vuln:cve-id>
    <vuln:published-datetime>1997-01-28T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:36.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/685" xml:lang="en">685</vuln:reference>
    </vuln:references>
    <vuln:summary>MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0048">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:debian:netkit:0.07"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:asl_ux_4800"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:ews-ux_v"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:up-ux_v"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/a:debian:netkit:0.07</vuln:product>
      <vuln:product>cpe:/o:nec:ews-ux_v</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:nec:up-ux_v</vuln:product>
      <vuln:product>cpe:/o:nec:asl_ux_4800</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0048</vuln:cve-id>
    <vuln:published-datetime>1997-01-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:37.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/147" xml:lang="en">00147</vuln:reference>
    </vuln:references>
    <vuln:summary>Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0049">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0049</vuln:cve-id>
    <vuln:published-datetime>1997-01-08T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:37.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Csetup under IRIX allows arbitrary file creation or overwriting.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0050">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.03"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.05"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.06"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.07"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.08"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.09"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:9.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.08</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.07</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.05</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.04</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.01</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.03</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.09</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.06</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0050</vuln:cve-id>
    <vuln:published-datetime>1996-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:37.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in HP-UX newgrp program.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0051">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:globetrotter:flexlm:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:globetrotter:flexlm:4.1"/>
        <cpe-lang:fact-ref name="cpe:/a:globetrotter:flexlm:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:license_oeo:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:license_oeo:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:sgi:license_oeo:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.1t"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.4b"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.4t"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5_iop"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5_ipr"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5a"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5d"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5e"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5f"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5g"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4.0.5h"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4jl"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:4.0.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/a:sgi:license_oeo:3.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5a</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1::xfs</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5_iop</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5f</vuln:product>
      <vuln:product>cpe:/a:sgi:license_oeo:3.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5d</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3.3.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.4t</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5g</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.1t</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/a:globetrotter:flexlm:4.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4jl</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5e</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.4b</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/a:globetrotter:flexlm:5.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3.3.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5h</vuln:product>
      <vuln:product>cpe:/a:sgi:license_oeo:3.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
      <vuln:product>cpe:/a:globetrotter:flexlm:4.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4.0.5_ipr</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0051</vuln:cve-id>
    <vuln:published-datetime>1997-01-06T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:38.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0052">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:2.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.7.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.2</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:4.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.1.5.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0052</vuln:cve-id>
    <vuln:published-datetime>1998-11-04T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:38.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/1389" xml:lang="en">freebsd-ip-frag-dos(1389)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/908" xml:lang="en">908</vuln:reference>
    </vuln:references>
    <vuln:summary>IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0053">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2:stable"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2:stable</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0053</vuln:cve-id>
    <vuln:published-datetime>1998-10-13T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:16:20.580-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6094" xml:lang="en">6094</vuln:reference>
    </vuln:references>
    <vuln:summary>TCP RST denial of service in FreeBSD.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0054">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0054</vuln:cve-id>
    <vuln:published-datetime>1998-06-10T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:38.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/171" xml:lang="en">00171</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun's ftpd daemon can be subjected to a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0055">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.3.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0055</vuln:cve-id>
    <vuln:published-datetime>1998-05-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:38.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>AIXAPAR</vuln:source>
      <vuln:reference href="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX80543&amp;apar=only" xml:lang="en">IX80543</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/172" xml:lang="en">00172</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflows in Sun libnsl allow root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0056">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0056</vuln:cve-id>
    <vuln:published-datetime>1998-09-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/174" xml:lang="en">00174</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Sun's ping program can give root access to local users.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0057">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:vacation"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.09"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:vvos"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.09</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2:stable</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:ibm:aix</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:vvos</vuln:product>
      <vuln:product>cpe:/o:sun:solaris</vuln:product>
      <vuln:product>cpe:/a:eric_allman:vacation</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0057</vuln:cve-id>
    <vuln:published-datetime>1998-11-16T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9811-087" xml:lang="en">HPSBUX9811-087</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5931" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5931" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Vacation program allows command execution by remote users through a sendmail command.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0058">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:2.0b10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:2.0b10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0058</vuln:cve-id>
    <vuln:published-datetime>1997-04-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/712" xml:lang="en">712</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in PHP cgi program, php.cgi allows shell access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0059">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0059</vuln:cve-id>
    <vuln:published-datetime>1997-07-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.1</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/325" xml:lang="en">irix-fam(325)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/353" xml:lang="en">353</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/164" xml:lang="en">164</vuln:reference>
    </vuln:references>
    <vuln:summary>IRIX fam service allows an attacker to obtain a list of all files on the server.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0060">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_max_router:1.0"/>
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_max_router:2.0"/>
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_max_router:3.0"/>
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_max_router:4.0"/>
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_max_router:5.0"/>
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_pipeline_router:1.0"/>
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_pipeline_router:2.0"/>
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_pipeline_router:3.0"/>
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_pipeline_router:4.0"/>
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_pipeline_router:5.0"/>
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_pipeline_router:6.0"/>
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_tnt_router:1.0"/>
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_tnt_router:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:lucent:ascend_max_router:2.0</vuln:product>
      <vuln:product>cpe:/h:lucent:ascend_max_router:3.0</vuln:product>
      <vuln:product>cpe:/h:lucent:ascend_max_router:5.0</vuln:product>
      <vuln:product>cpe:/h:lucent:ascend_pipeline_router:4.0</vuln:product>
      <vuln:product>cpe:/h:lucent:ascend_pipeline_router:5.0</vuln:product>
      <vuln:product>cpe:/h:lucent:ascend_pipeline_router:1.0</vuln:product>
      <vuln:product>cpe:/h:lucent:ascend_max_router:4.0</vuln:product>
      <vuln:product>cpe:/h:lucent:ascend_pipeline_router:3.0</vuln:product>
      <vuln:product>cpe:/h:lucent:ascend_tnt_router:1.0</vuln:product>
      <vuln:product>cpe:/h:lucent:ascend_pipeline_router:2.0</vuln:product>
      <vuln:product>cpe:/h:lucent:ascend_pipeline_router:6.0</vuln:product>
      <vuln:product>cpe:/h:lucent:ascend_max_router:1.0</vuln:product>
      <vuln:product>cpe:/h:lucent:ascend_tnt_router:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0060</vuln:cve-id>
    <vuln:published-datetime>1998-03-16T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0061">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:2.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2:stable</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0061</vuln:cve-id>
    <vuln:published-datetime>1997-10-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).</vuln:summary>
  </entry>
  <entry id="CVE-1999-0062">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0062</vuln:cve-id>
    <vuln:published-datetime>1998-08-03T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/7559" xml:lang="en">7559</vuln:reference>
    </vuln:references>
    <vuln:summary>The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0063">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3db"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29w"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xa3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0db"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0t"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29w</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3db</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29xa3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0db</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29xb</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0063</vuln:cve-id>
    <vuln:published-datetime>1999-01-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5874" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5874" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0064">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0064</vuln:cve-id>
    <vuln:published-datetime>1997-05-26T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in AIX lquerylv program gives root access to local users.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0065">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0065</vuln:cve-id>
    <vuln:published-datetime>1998-08-31T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/181" xml:lang="en">00181</vuln:reference>
    </vuln:references>
    <vuln:summary>Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0066">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:john_s._roberts:anyform:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:john_s._roberts:anyform:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:john_s._roberts:anyform:2.0</vuln:product>
      <vuln:product>cpe:/a:john_s._roberts:anyform:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0066</vuln:cve-id>
    <vuln:published-datetime>1995-07-31T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/719" xml:lang="en">719</vuln:reference>
    </vuln:references>
    <vuln:summary>AnyForm CGI remote execution.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0067">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ncsa:ncsa_httpd:1.5a::export"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ncsa:ncsa_httpd:1.5a::export</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0067</vuln:cve-id>
    <vuln:published-datetime>1996-03-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-1996-06.html" xml:lang="en">CA-1996-06</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/629" xml:lang="en">629</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/136" xml:lang="en">136</vuln:reference>
    </vuln:references>
    <vuln:summary>phf CGI program allows remote command execution through shell metacharacters.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0068">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:2.0b10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:2.0b10</vuln:product>
      <vuln:product>cpe:/a:php:php:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0068</vuln:cve-id>
    <vuln:published-datetime>1997-10-19T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/713" xml:lang="en">713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3396" xml:lang="en">3396</vuln:reference>
    </vuln:references>
    <vuln:summary>CGI PHP mylog script allows an attacker to read any file on the target server.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0069">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0069</vuln:cve-id>
    <vuln:published-datetime>1998-04-29T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:39.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/8158" xml:lang="en">8158</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/169" xml:lang="en">00169</vuln:reference>
    </vuln:references>
    <vuln:summary>Solaris ufsrestore buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0070">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server"/>
        <cpe-lang:fact-ref name="cpe:/a:ncsa:ncsa_web_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server</vuln:product>
      <vuln:product>cpe:/a:ncsa:ncsa_web_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0070</vuln:cve-id>
    <vuln:published-datetime>1996-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>test-cgi program allows an attacker to list files on the server.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0071">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:1.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0071</vuln:cve-id>
    <vuln:published-datetime>1997-09-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0072">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0072</vuln:cve-id>
    <vuln:published-datetime>1997-10-22T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in AIX xdat gives root access to local users.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0073">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:unix:3.2g"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:unix:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:digital:osf_1:3.0</vuln:product>
      <vuln:product>cpe:/o:digital:osf_1:1.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:digital:osf_1:1.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3::xfs</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:digital:unix:4.0</vuln:product>
      <vuln:product>cpe:/o:digital:unix:3.2g</vuln:product>
      <vuln:product>cpe:/o:digital:osf_1:3.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1::xfs</vuln:product>
      <vuln:product>cpe:/o:digital:osf_1:2.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0073</vuln:cve-id>
    <vuln:published-datetime>1995-10-13T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0074">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2:stable</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:2.0.4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0074</vuln:cve-id>
    <vuln:published-datetime>1997-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Listening TCP ports are sequentially allocated, allowing spoofing attacks.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0075">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:washington_university:wu-ftpd</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0075</vuln:cve-id>
    <vuln:published-datetime>1996-10-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/5742" xml:lang="en">5742</vuln:reference>
    </vuln:references>
    <vuln:summary>PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0076">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:washington_university:wu-ftpd</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0076</vuln:cve-id>
    <vuln:published-datetime>1997-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Buffer overflow in wu-ftp from PASV command causes a core dump.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0077">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0077</vuln:cve-id>
    <vuln:published-datetime>1995-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/static/139.php" xml:lang="en">tcp-seq-predict(139)</vuln:reference>
    </vuln:references>
    <vuln:summary>Predictable TCP sequence numbers allow spoofing.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0078">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ncr:mp-ras:2.03"/>
        <cpe-lang:fact-ref name="cpe:/a:ncr:mp-ras:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:ncr:mp-ras:3.01"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:up-ux_v"/>
        <cpe-lang:fact-ref name="cpe:/o:next:nextstep"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ncr:mp-ras:2.03</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2:stable</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:2.1</vuln:product>
      <vuln:product>cpe:/o:nec:up-ux_v</vuln:product>
      <vuln:product>cpe:/o:next:nextstep</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5</vuln:product>
      <vuln:product>cpe:/a:ncr:mp-ras:3.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/a:ncr:mp-ras:3.01</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0078</vuln:cve-id>
    <vuln:published-datetime>1996-04-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>1.9</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0079">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bisonware:bisonware_ftp_server:3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bisonware:bisonware_ftp_server:3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0079</vuln:cve-id>
    <vuln:published-datetime>1997-09-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0080">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0080</vuln:cve-id>
    <vuln:published-datetime>1995-11-30T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0081">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:washington_university:wu-ftpd</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0081</vuln:cve-id>
    <vuln:published-datetime>1997-01-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>wu-ftp allows files to be overwritten via the rnfr command.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0082">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ftp:ftp"/>
        <cpe-lang:fact-ref name="cpe:/a:ftpcd:ftpcd"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ftpcd:ftpcd</vuln:product>
      <vuln:product>cpe:/a:ftp:ftp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0082</vuln:cve-id>
    <vuln:published-datetime>1988-11-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FarmerVenema</vuln:source>
      <vuln:reference href="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html" xml:lang="en">Improving the Security of Your Site by Breaking Into it</vuln:reference>
    </vuln:references>
    <vuln:summary>CWD ~root command in ftpd allows root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0083">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0083</vuln:cve-id>
    <vuln:published-datetime>1997-06-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:40.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>getcwd() file descriptor leak in FTP.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0084">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:nfs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:nfs</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0084</vuln:cve-id>
    <vuln:published-datetime>1990-05-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:16:25.283-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/78" xml:lang="en">nfs-mknod(78)</vuln:reference>
    </vuln:references>
    <vuln:summary>Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0085">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2:stable"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2:stable</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:2.0.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0085</vuln:cve-id>
    <vuln:published-datetime>1996-08-21T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:41.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/119" xml:lang="en">rwhod(119)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/118" xml:lang="en">rwhod-vuln(118)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0086">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0086</vuln:cve-id>
    <vuln:published-datetime>1998-01-08T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:41.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>AIX routed allows remote users to modify sensitive files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0087">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0087</vuln:cve-id>
    <vuln:published-datetime>1998-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:41.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/7992" xml:lang="en">7992</vuln:reference>
    </vuln:references>
    <vuln:summary>Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0088">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0088</vuln:cve-id>
    <vuln:published-datetime>1998-10-26T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:16:25.877-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0089">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0089</vuln:cve-id>
    <vuln:published-datetime>1997-10-28T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:16:26.003-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in AIX libDtSvc library can allow local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0090">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0090</vuln:cve-id>
    <vuln:published-datetime>1997-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:41.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in AIX rcp command allows local users to obtain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0091">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0091</vuln:cve-id>
    <vuln:published-datetime>1997-10-28T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:41.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in AIX writesrv command allows local users to obtain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0092">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0092</vuln:cve-id>
    <vuln:published-datetime>1997-10-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:41.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Various vulnerabilities in the AIX portmir command allows local users to obtain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0093">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0093</vuln:cve-id>
    <vuln:published-datetime>1997-10-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:41.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0094">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0094</vuln:cve-id>
    <vuln:published-datetime>1997-10-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:41.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>AIX piodmgrsu command allows local users to gain additional group privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0095">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:5.58"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eric_allman:sendmail:5.58</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0095</vuln:cve-id>
    <vuln:published-datetime>1988-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:41.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/1" xml:lang="en">1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/195" xml:lang="en">195</vuln:reference>
    </vuln:references>
    <vuln:summary>The debug command in Sendmail is enabled, allowing attackers to execute commands as root.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0096">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6.1</vuln:product>
      <vuln:product>cpe:/o:sco:internet_faststart:1.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6</vuln:product>
      <vuln:product>cpe:/o:sco:internet_faststart:1.1</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0096</vuln:cve-id>
    <vuln:published-datetime>1996-12-10T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:41.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba" xml:lang="en">00122</vuln:reference>
    </vuln:references>
    <vuln:summary>Sendmail decode alias can be used to overwrite sensitive files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0097">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.03"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.04"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.05"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.06"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.07"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.08"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.09"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.10"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3c"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3c</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.01</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.03</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.09</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.08</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.07</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2.1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.05</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.04</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9.06</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0097</vuln:cve-id>
    <vuln:published-datetime>1997-10-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:41.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).</vuln:summary>
  </entry>
  <entry id="CVE-1999-0098">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apple:appleshare::::jp"/>
        <cpe-lang:fact-ref name="cpe:/a:pmail:mercury_mail_server"/>
        <cpe-lang:fact-ref name="cpe:/a:slmail:slmail:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apple:appleshare::::jp</vuln:product>
      <vuln:product>cpe:/a:slmail:slmail:2.6</vuln:product>
      <vuln:product>cpe:/a:pmail:mercury_mail_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0098</vuln:cve-id>
    <vuln:published-datetime>1998-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:42.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0099">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:convex:convexos:10.1"/>
        <cpe-lang:fact-ref name="cpe:/o:convex:convexos:10.2"/>
        <cpe-lang:fact-ref name="cpe:/o:convex:convexos:11.0"/>
        <cpe-lang:fact-ref name="cpe:/o:convex:convexos:11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:convex:spp-ux:3"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:8.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:8.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cray:unicos:9.0"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:convex:spp-ux:3</vuln:product>
      <vuln:product>cpe:/o:convex:convexos:11.0</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:9.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.0</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:8.3</vuln:product>
      <vuln:product>cpe:/o:convex:convexos:10.2</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:convex:convexos:10.1</vuln:product>
      <vuln:product>cpe:/o:cray:unicos:8.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.0.1</vuln:product>
      <vuln:product>cpe:/o:convex:convexos:11.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0099</vuln:cve-id>
    <vuln:published-datetime>1995-10-19T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:42.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0100">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:inn:1.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0100</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:42.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Remote access in AIX innd 1.5.1, using control messages.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0101">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0101</vuln:cve-id>
    <vuln:published-datetime>1996-12-10T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:45.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml" xml:lang="en">H-13</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0102">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:seattle_lab_software:slmail:3.0.2421"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:seattle_lab_software:slmail:3.0.2421</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0102</vuln:cve-id>
    <vuln:published-datetime>1998-07-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:45.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0103">
    <vuln:cve-id>CVE-1999-0103</vuln:cve-id>
    <vuln:published-datetime>1996-02-08T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:45.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0104">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_95:0a"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:caldera:openlinux:2.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_95:0a</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0104</vuln:cve-id>
    <vuln:published-datetime>1997-12-16T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-03-04T00:00:14.640-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:5743" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5743" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5743" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5743" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0105">
    <vuln:cve-id>CVE-1999-0105</vuln:cve-id>
    <vuln:published-datetime>1997-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:45.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>finger allows recursive searches by using a long string of @ symbols.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0106">
    <vuln:cve-id>CVE-1999-0106</vuln:cve-id>
    <vuln:published-datetime>1997-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:45.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Finger redirection allows finger bombs.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0107">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:0.8.11"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:0.8.14"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.3"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.0.5"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.1.1"/>
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server:1.2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server:1.2.5</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0.5</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:0.8.11</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.1</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.1.1</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0.2</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:0.8.14</vuln:product>
      <vuln:product>cpe:/a:apache:http_server:1.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0107</vuln:cve-id>
    <vuln:published-datetime>1997-12-30T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:45.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0108">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0108</vuln:cve-id>
    <vuln:published-datetime>1998-05-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:45.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>The printers program in IRIX has a buffer overflow that gives root access to local users.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0109">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0109</vuln:cve-id>
    <vuln:published-datetime>1997-02-10T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:46.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/140" xml:lang="en">00140</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in ffbconfig in Solaris 2.5.1.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0110">
    <vuln:cve-id>CVE-1999-0110</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:46.557-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0315.  Reason: This candidate's original description had a typo that delayed it from being detected as a duplicate of CVE-1999-0315.  Notes: All CVE users should reference CVE-1999-0315 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0111">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0111</vuln:cve-id>
    <vuln:published-datetime>1997-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:46.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>RIP v1 is susceptible to spoofing.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0112">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cde:cde"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/a:cde:cde</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0112</vuln:cve-id>
    <vuln:published-datetime>1997-05-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:46.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/878" xml:lang="en">dtterm-bo(878)</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in AIX dtterm program for the CDE.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0113">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0113</vuln:cve-id>
    <vuln:published-datetime>1994-05-23T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:46.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/458" xml:lang="en">458</vuln:reference>
    </vuln:references>
    <vuln:summary>Some implementations of rlogin allow root access if given a -froot parameter.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0114">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:elm_development_group:elm:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:elm_development_group:elm:2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0114</vuln:cve-id>
    <vuln:published-datetime>1998-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:46.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Local users can execute commands as other users, and read other users' files, through the filter command in the Elm elm-2.4 mail package using a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0115">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0115</vuln:cve-id>
    <vuln:published-datetime>1997-09-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:46.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/1800" xml:lang="en">1800</vuln:reference>
    </vuln:references>
    <vuln:summary>AIX bugfiler program allows local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0116">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:ibm:sng:2.1"/>
        <cpe-lang:fact-ref name="cpe:/h:ibm:sng:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
      <vuln:product>cpe:/h:ibm:sng:2.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/h:ibm:sng:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0116</vuln:cve-id>
    <vuln:published-datetime>1996-09-19T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:46.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/136" xml:lang="en">00136</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX" xml:lang="en">19961202-01-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0117">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0117</vuln:cve-id>
    <vuln:published-datetime>1992-03-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:47.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>AIX passwd allows local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0118">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0118</vuln:cve-id>
    <vuln:published-datetime>1998-11-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:48.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91158980826979&amp;w=2" xml:lang="en">19981119 RSI.0011.11-09-98.AIX.INFOD</vuln:reference>
    </vuln:references>
    <vuln:summary>AIX infod allows local users to gain root access through an X display.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0119">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0::beta"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0::beta</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0119</vuln:cve-id>
    <vuln:published-datetime>1999-01-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:16:30.393-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Windows NT 4.0 beta allows users to read and delete shares.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0120">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:1.1.1a</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0120</vuln:cve-id>
    <vuln:published-datetime>1994-03-21T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:48.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/126" xml:lang="en">00126</vuln:reference>
    </vuln:references>
    <vuln:summary>Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0121">
    <vuln:cve-id>CVE-1999-0121</vuln:cve-id>
    <vuln:published-datetime>1999-01-21T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in dtaction command gives root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0122">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:4.1.4</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0122</vuln:cve-id>
    <vuln:published-datetime>1997-07-21T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:48.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in AIX lchangelv gives root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0123">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0123</vuln:cve-id>
    <vuln:published-datetime>1995-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:16:30.923-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>3.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Race condition in Linux mailx command allows local users to read user files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0124">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:university_of_minnesota:gopherd"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_minnesota:gopherd</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0124</vuln:cve-id>
    <vuln:published-datetime>1993-08-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:48.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0125">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6:hw3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6:hw3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0125</vuln:cve-id>
    <vuln:published-datetime>1998-01-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:48.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19980605-01-PX" xml:lang="en">19980605-01-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in SGI IRIX mailx program.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0126">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:xfree86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:xfree86_project:xfree86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0126</vuln:cve-id>
    <vuln:published-datetime>1998-05-03T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:48.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/j-010.shtml" xml:lang="en">J-010</vuln:reference>
    </vuln:references>
    <vuln:summary>SGI IRIX buffer overflow in xterm and Xaw allows root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0127">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0127</vuln:cve-id>
    <vuln:published-datetime>1996-12-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:48.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0128">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:1.3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:tcp_ip:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:ibm:sng"/>
        <cpe-lang:fact-ref name="cpe:/h:ibm:sng:2.1"/>
        <cpe-lang:fact-ref name="cpe:/h:ibm:sng:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:5.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0</vuln:product>
      <vuln:product>cpe:/o:sco:internet_faststart:1.0</vuln:product>
      <vuln:product>cpe:/o:sco:internet_faststart:1.1</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:3.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:1.3.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.4::x86</vuln:product>
      <vuln:product>cpe:/h:ibm:sng:2.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:sco:tcp_ip:1.2.1</vuln:product>
      <vuln:product>cpe:/h:ibm:sng:2.2</vuln:product>
      <vuln:product>cpe:/h:ibm:sng</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
      <vuln:product>cpe:/o:digital:osf_1:1.3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0128</vuln:cve-id>
    <vuln:published-datetime>1996-12-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:48.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0129">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.2"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.16"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6</vuln:product>
      <vuln:product>cpe:/o:sco:internet_faststart:1.0</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.16</vuln:product>
      <vuln:product>cpe:/o:sco:internet_faststart:1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.8</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6.1</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.8.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.8.1</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.8.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0129</vuln:cve-id>
    <vuln:published-datetime>1996-12-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:48.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0130">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:caldera:network_desktop:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.7"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.1"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.7</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.0</vuln:product>
      <vuln:product>cpe:/a:caldera:network_desktop:1.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.8.2</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.8.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0130</vuln:cve-id>
    <vuln:published-datetime>1996-11-16T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/716" xml:lang="en">716</vuln:reference>
    </vuln:references>
    <vuln:summary>Local users can start Sendmail in daemon mode and gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0131">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.6"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.7.1"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.7.2"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.7.3"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.7.4"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.7.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.6</vuln:product>
      <vuln:product>cpe:/o:sco:internet_faststart:1.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:3.0.3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.7.2</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.7.4</vuln:product>
      <vuln:product>cpe:/o:digital:osf_1:1.3.2</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.7.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.7.1</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.7.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0131</vuln:cve-id>
    <vuln:published-datetime>1996-09-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/717" xml:lang="en">717</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0132">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3c"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3c</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0132</vuln:cve-id>
    <vuln:published-datetime>1996-08-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-1996-19.html" xml:lang="en">CA-1996-19</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/401" xml:lang="en">expreserve(401)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/11723" xml:lang="en">11723</vuln:reference>
    </vuln:references>
    <vuln:summary>Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0133">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:adobe:framemaker"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:adobe:framemaker</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0133</vuln:cve-id>
    <vuln:published-datetime>1996-08-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0134">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:5.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0134</vuln:cve-id>
    <vuln:published-datetime>1996-08-06T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/8159" xml:lang="en">8159</vuln:reference>
    </vuln:references>
    <vuln:summary>vold in Solaris 2.x allows local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0135">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0135</vuln:cve-id>
    <vuln:published-datetime>1996-07-25T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>admintool in Solaris allows a local user to write to arbitrary files and gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0136">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:5.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0136</vuln:cve-id>
    <vuln:published-datetime>1996-07-31T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0137">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fred_n._van_kempen:dip:3.3.7o"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:fred_n._van_kempen:dip:3.3.7o</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0137</vuln:cve-id>
    <vuln:published-datetime>1996-07-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>The dip program on many Linux systems allows local users to gain root access via a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0138">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:apple:a_ux:3.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:1.2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:asl_ux_4800"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:ews-ux_v:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:ews-ux_v:4.2mp"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:up-ux_v:4.2mp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:nec:ews-ux_v:4.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:8</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0</vuln:product>
      <vuln:product>cpe:/o:apple:a_ux:3.1.1</vuln:product>
      <vuln:product>cpe:/o:digital:osf_1:1.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:1.2.0</vuln:product>
      <vuln:product>cpe:/o:nec:ews-ux_v:4.2mp</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
      <vuln:product>cpe:/o:nec:asl_ux_4800</vuln:product>
      <vuln:product>cpe:/o:nec:up-ux_v:4.2mp</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0138</vuln:cve-id>
    <vuln:published-datetime>1996-06-26T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0139">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0139</vuln:cve-id>
    <vuln:published-datetime>1998-12-12T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/8205" xml:lang="en">8205</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0140">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0140</vuln:cve-id>
    <vuln:published-datetime>1999-06-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:16:33.893-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in RAS/PPTP on NT systems.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:2.02"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:navigator:2.02</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0141</vuln:cve-id>
    <vuln:published-datetime>1996-03-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>3.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/134" xml:lang="en">00134</vuln:reference>
    </vuln:references>
    <vuln:summary>Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0142">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:java</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0142</vuln:cve-id>
    <vuln:published-datetime>1996-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0143">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:mit:kerberos:5"/>
        <cpe-lang:fact-ref name="cpe:/a:process_software:multinet:3.4"/>
        <cpe-lang:fact-ref name="cpe:/a:process_software:multinet:3.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mit:kerberos:4.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/a:mit:kerberos:5</vuln:product>
      <vuln:product>cpe:/a:process_software:multinet:3.4</vuln:product>
      <vuln:product>cpe:/a:process_software:multinet:3.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0143</vuln:cve-id>
    <vuln:published-datetime>1996-02-21T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:49.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0144">
    <vuln:cve-id>CVE-1999-0144</vuln:cve-id>
    <vuln:published-datetime>1997-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/static/208.php" xml:lang="en">qmail-rcpt</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/2237" xml:lang="en">2237</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html" xml:lang="en">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://cr.yp.to/qmail/venema.html" xml:lang="en">http://cr.yp.to/qmail/venema.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319029&amp;w=2" xml:lang="en">19970612 Re: Denial of service (qmail-smtpd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2" xml:lang="en">19970612 qmail-dos-2.c, another denial of service attack</vuln:reference>
    </vuln:references>
    <vuln:summary>Denial of service in Qmail by specifying a large number of recipients with the RCPT command.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0145">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eric_allman:sendmail</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0145</vuln:cve-id>
    <vuln:published-datetime>1993-09-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:50.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-1993-14.html" xml:lang="en">CA-1993-14</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-1990-11.html" xml:lang="en">CA-1990-11</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www2.dataguard.no/bugtraq/1995_1/0332.html" xml:lang="en">19950206 sendmail wizard thing...</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>FarmerVenema</vuln:source>
      <vuln:reference href="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html" xml:lang="en">Improving the Security of Your Site by Breaking Into it</vuln:reference>
    </vuln:references>
    <vuln:summary>Sendmail WIZ command enabled, allowing root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0146">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ncsa:campas"/>
        <cpe-lang:fact-ref name="cpe:/a:ncsa:servers"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ncsa:campas</vuln:product>
      <vuln:product>cpe:/a:ncsa:servers</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0146</vuln:cve-id>
    <vuln:published-datetime>1997-07-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:50.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/298" xml:lang="en">http-cgi-campas(298)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/1975" xml:lang="en">1975</vuln:reference>
    </vuln:references>
    <vuln:summary>The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0147">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:university_of_arizona:glimpse_http:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:university_of_arizona:webglimpse:1.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_arizona:webglimpse:1.5</vuln:product>
      <vuln:product>cpe:/a:university_of_arizona:glimpse_http:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0147</vuln:cve-id>
    <vuln:published-datetime>1997-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:50.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0148">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0148</vuln:cve-id>
    <vuln:published-datetime>1997-09-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:50.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/380" xml:lang="en">380</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX" xml:lang="en">19970501-02-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>The handler CGI program in IRIX allows arbitrary command execution.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0149">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0149</vuln:cve-id>
    <vuln:published-datetime>1997-04-19T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:50.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/290" xml:lang="en">http-sgi-wrap(290)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/373" xml:lang="en">373</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/247" xml:lang="en">247</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX" xml:lang="en">19970501-02-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0150">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:fingerd"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:fingerd</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0150</vuln:cve-id>
    <vuln:published-datetime>1997-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:51.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The Perl fingerd program allows arbitrary command execution from remote users.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0151">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:satan:satan:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:satan:satan:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:satan:satan:1.0</vuln:product>
      <vuln:product>cpe:/a:satan:satan:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0151</vuln:cve-id>
    <vuln:published-datetime>1995-04-03T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:52.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0152">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:data_general:dg_ux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:data_general:dg_ux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0152</vuln:cve-id>
    <vuln:published-datetime>1997-08-11T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:52.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The DG/UX finger daemon allows remote command execution through shell metacharacters.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0153">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_95"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_95</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0153</vuln:cve-id>
    <vuln:published-datetime>1997-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:52.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/1666" xml:lang="en">1666</vuln:reference>
    </vuln:references>
    <vuln:summary>Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0154">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:3.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0154</vuln:cve-id>
    <vuln:published-datetime>1999-12-31T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:52.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0155">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:aladdin_enterprises:ghostscript:2.6"/>
        <cpe-lang:fact-ref name="cpe:/a:aladdin_enterprises:ghostscript:3.22"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:aladdin_enterprises:ghostscript:3.22</vuln:product>
      <vuln:product>cpe:/a:aladdin_enterprises:ghostscript:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0155</vuln:cve-id>
    <vuln:published-datetime>1995-08-31T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:52.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The ghostscript command with the -dSAFER option allows remote attackers to execute commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0156">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:washington_university:wu-ftpd</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0156</vuln:cve-id>
    <vuln:published-datetime>1997-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:52.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:summary>wu-ftpd FTP daemon allows any user and password combination.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0157">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2p"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3t"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0"/>
          <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0t"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:4.2%281%29"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:11.3t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2p</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0t</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:4.2%281%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0157</vuln:cve-id>
    <vuln:published-datetime>1998-08-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/1097" xml:lang="en">1097</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5575" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5575" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0158">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:4.1%286%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:pix_firewall:4.2%281%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:pix_firewall:4.1%286%29</vuln:product>
      <vuln:product>cpe:/o:cisco:pix_firewall:4.2%281%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0158</vuln:cve-id>
    <vuln:published-datetime>1998-08-31T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/770/pixmgrfile-pub.shtml" xml:lang="en">20010913 Cisco PIX Firewall Manager File Exposure</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/685" xml:lang="en">685</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0159">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.0%2820.3%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2815%29ca"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2816%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2816%29aa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2816%29ia"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2817%29cc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1%2817%29ct"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2810%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%2810%29bc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%288%29sa3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%289%29p"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2%289%29xa"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%281%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%281%29ed"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.3%281%29t"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:11.1%2816%29aa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2817%29ct</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:9.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2817%29cc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%288%29sa3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2816%29ia</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%289%29xa</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.0%2820.3%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%289%29p</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%281%29t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2810%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%281%29ed</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2%2810%29bc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2816%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.3%281%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1%2815%29ca</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0159</vuln:cve-id>
    <vuln:published-datetime>1998-08-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5567" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5567" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login).  This applies to some IOS 9.x, 10.x, and 11.x releases.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0160">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:10.3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2p"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:9.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:9.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.0</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:4.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2p</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:10.3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:11.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0160</vuln:cve-id>
    <vuln:published-datetime>1997-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/1099" xml:lang="en">1099</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5827" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5827" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0161">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:10.3%283.4%29"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:10.3%284.2%29"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:10.3%283.4%29</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:10.3%284.2%29</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0161</vuln:cve-id>
    <vuln:published-datetime>1995-07-31T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/797" xml:lang="en">797</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5297" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5297" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0162">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:11.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:11.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0162</vuln:cve-id>
    <vuln:published-datetime>1998-09-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5661" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5661" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>The "established" keyword in some Cisco IOS software allowed an attacker to bypass filtering.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0163">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eric_allman:sendmail</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0163</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>In older versions of Sendmail, an attacker could use a pipe character to execute root commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0164">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:5.4::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:5.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.4</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0164</vuln:cve-id>
    <vuln:published-datetime>1995-08-29T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/8346" xml:lang="en">8346</vuln:reference>
    </vuln:references>
    <vuln:summary>A race condition in the Solaris ps command allows an attacker to overwrite critical files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0165">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:nfs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:1.1.1a</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.0.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.0.3</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
      <vuln:product>cpe:/a:sun:nfs</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:3.5</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.0.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0165</vuln:cve-id>
    <vuln:published-datetime>1997-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>NFS cache poisoning.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0166">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:nfs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:nfs</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0166</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>NFS allows users to use a "cd .." command to access other directories besides the exported file system.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0167">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0167</vuln:cve-id>
    <vuln:published-datetime>1991-12-06T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0168">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3c"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:4.1.3c</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0168</vuln:cve-id>
    <vuln:published-datetime>1992-06-04T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place.  For example, NFS file systems could be mounted through the portmapper despite export restrictions.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0169">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:nfs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:nfs</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0169</vuln:cve-id>
    <vuln:published-datetime>1997-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>NFS allows attackers to read and write any file on the system by specifying a false UID.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0170">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:digital:ultrix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:digital:ultrix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0170</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0171">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0171</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:53.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in syslog by sending it a large number of superfluous messages.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0172">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:matt_wright:formmail"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:matt_wright:formmail</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0172</vuln:cve-id>
    <vuln:published-datetime>1995-08-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:54.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>FormMail CGI program allows remote execution of commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0173">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:matt_wright:formmail"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:matt_wright:formmail</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0173</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:54.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>FormMail CGI program can be used by web servers other than the host server that the program resides on.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0174">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:4.05"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:4.06"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:4.07"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:4.51"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:4.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:communicator:4.07</vuln:product>
      <vuln:product>cpe:/a:netscape:communicator:4.06</vuln:product>
      <vuln:product>cpe:/a:netscape:communicator:4.6</vuln:product>
      <vuln:product>cpe:/a:netscape:communicator:4.05</vuln:product>
      <vuln:product>cpe:/a:netscape:communicator:4.51</vuln:product>
      <vuln:product>cpe:/a:netscape:communicator:4.0</vuln:product>
      <vuln:product>cpe:/a:netscape:communicator:4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0174</vuln:cve-id>
    <vuln:published-datetime>1997-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:54.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0175">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:novell:web_server:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:novell:web_server:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0175</vuln:cve-id>
    <vuln:published-datetime>1996-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:54.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0176">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:webgais_development_team:webgais:1.0b2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webgais_development_team:webgais:1.0b2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0176</vuln:cve-id>
    <vuln:published-datetime>1997-07-10T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:54.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The Webgais program allows a remote user to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0177">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oreilly:website:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oreilly:website:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0177</vuln:cve-id>
    <vuln:published-datetime>1997-09-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:54.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0178">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:oreilly:oreilly_website:1.1e"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:oreilly:oreilly_website:1.1e</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0178</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:54.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/295" xml:lang="en">http-website-winsample(295)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/2078" xml:lang="en">2078</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/8" xml:lang="en">8</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html" xml:lang="en">19970106 Re: signal handling</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0179">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_95"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_95</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0179</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:54.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q140818" xml:lang="en">Q140818</vuln:reference>
    </vuln:references>
    <vuln:summary>Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0180">
    <vuln:cve-id>CVE-1999-0180</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:54.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>in.rshd allows users to login with a NULL username and execute commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0181">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rpc.walld:rpc.walld"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rpc.walld:rpc.walld</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0181</vuln:cve-id>
    <vuln:published-datetime>1994-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:54.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>6.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0182">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:samba:samba:1.9.17:p2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:samba:samba:1.9.17:p2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0182</vuln:cve-id>
    <vuln:published-datetime>1997-09-30T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:54.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/h-110.shtml" xml:lang="en">H-110</vuln:reference>
    </vuln:references>
    <vuln:summary>Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0183">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tftp:tftp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tftp:tftp</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0183</vuln:cve-id>
    <vuln:published-datetime>1997-09-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:54.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Linux implementations of TFTP would allow access to files outside the restricted directory.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0184">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isc:bind:9.4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:bind:9.4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0184</vuln:cve-id>
    <vuln:published-datetime>1997-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:55.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0185">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0185</vuln:cve-id>
    <vuln:published-datetime>1997-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:55.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/156" xml:lang="en">00156</vuln:reference>
    </vuln:references>
    <vuln:summary>In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0186">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0186</vuln:cve-id>
    <vuln:published-datetime>1998-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:55.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm" xml:lang="en">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm</vuln:reference>
    </vuln:references>
    <vuln:summary>In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0187">
    <vuln:cve-id>CVE-1999-0187</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:59.307-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0022.  Reason: This candidate is a duplicate of CVE-1999-0022.  Notes: All CVE users should reference CVE-1999-0022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0188">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0188</vuln:cve-id>
    <vuln:published-datetime>1998-12-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:59.367-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/182" xml:lang="en">00182</vuln:reference>
    </vuln:references>
    <vuln:summary>The passwd command in Solaris can be subjected to a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0189">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0189</vuln:cve-id>
    <vuln:published-datetime>1997-06-04T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:59.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142" xml:lang="en">00142</vuln:reference>
    </vuln:references>
    <vuln:summary>Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0190">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0190</vuln:cve-id>
    <vuln:published-datetime>1998-04-08T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:59.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/167" xml:lang="en">00167</vuln:reference>
    </vuln:references>
    <vuln:summary>Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0191">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0191</vuln:cve-id>
    <vuln:published-datetime>1997-09-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:59.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/275" xml:lang="en">275</vuln:reference>
    </vuln:references>
    <vuln:summary>IIS newdsn.exe CGI script allows remote users to overwrite files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0192">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.2::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:6.0::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.6"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.9"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.2</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.5</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:6.0::i386</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.1</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.6</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.2::i386</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.0</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.4</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:4.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.0</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0192</vuln:cve-id>
    <vuln:published-datetime>1997-10-18T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:59.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0193">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ascend:cascadeview_ux:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ascend:cascadeview_ux:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0193</vuln:cve-id>
    <vuln:published-datetime>1997-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:59.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0194">
    <vuln:cve-id>CVE-1999-0194</vuln:cve-id>
    <vuln:published-datetime>1999-05-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:59.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in in.comsat allows attackers to generate messages.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0195">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0195</vuln:cve-id>
    <vuln:published-datetime>1997-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:59.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0196">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:webgais_development_team:webgais:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webgais_development_team:webgais:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0196</vuln:cve-id>
    <vuln:published-datetime>1997-07-08T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:33:59.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/2077" xml:lang="en">2077</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/237" xml:lang="en">237</vuln:reference>
    </vuln:references>
    <vuln:summary>websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).</vuln:summary>
  </entry>
  <entry id="CVE-1999-0197">
    <vuln:cve-id>CVE-1999-0197</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>finger 0@host on some systems may print information on some user accounts.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0198">
    <vuln:cve-id>CVE-1999-0198</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>finger .@host on some systems may print information on some user accounts.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0200">
    <vuln:cve-id>CVE-1999-0200</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0201">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ftp:ftp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ftp:ftp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0201</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:00.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0202">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:university_of_washington:wu-ftpd:2.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_washington:wu-ftpd:2.4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0202</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-03-26T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0203">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.6.10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.6.10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0203</vuln:cve-id>
    <vuln:published-datetime>1995-08-17T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:00.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0204">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.6.9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.6.9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0204</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:00.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0205">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.6.11"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.6.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.6.12</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.6.11</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0205</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:00.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in Sendmail 8.6.11 and 8.6.12.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0206">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.8.1</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0206</vuln:cve-id>
    <vuln:published-datetime>1996-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:00.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0207">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:great_circle_associates:majordomo:1.90"/>
        <cpe-lang:fact-ref name="cpe:/a:great_circle_associates:majordomo:1.91"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:great_circle_associates:majordomo:1.90</vuln:product>
      <vuln:product>cpe:/a:great_circle_associates:majordomo:1.91</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0207</vuln:cve-id>
    <vuln:published-datetime>1994-06-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:00.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0208">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:asl_ux_4800"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:ews-ux_v"/>
        <cpe-lang:fact-ref name="cpe:/o:nec:up-ux_v"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:nec:ews-ux_v</vuln:product>
      <vuln:product>cpe:/o:nec:up-ux_v</vuln:product>
      <vuln:product>cpe:/o:nec:asl_ux_4800</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0208</vuln:cve-id>
    <vuln:published-datetime>1995-12-12T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:01.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0209">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:4.0.3</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:3.5</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.0.2</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0209</vuln:cve-id>
    <vuln:published-datetime>1990-08-14T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:01.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/8" xml:lang="en">8</vuln:reference>
    </vuln:references>
    <vuln:summary>The SunView (SunTools) selection_svc facility allows remote users to read files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0210">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0210</vuln:cve-id>
    <vuln:published-datetime>1997-11-26T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:01.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CERT</vuln:source>
      <vuln:reference href="http://www.cert.org/advisories/CA-99-05-statd-automountd.html" xml:lang="en">CA-99-05</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9910-104" xml:lang="en">HPSBUX9910-104</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/235" xml:lang="en">235</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2" xml:lang="en">19990103 SUN almost has a clue! (automountd)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88053459921223&amp;w=2" xml:lang="en">19971126 Solaris 2.5.1 automountd exploit (fwd)</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:6076" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:6076" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0211">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3c"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:4.1.3c</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0211</vuln:cve-id>
    <vuln:published-datetime>1994-02-14T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:01.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/24" xml:lang="en">24</vuln:reference>
    </vuln:references>
    <vuln:summary>Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0212">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0212</vuln:cve-id>
    <vuln:published-datetime>1998-04-29T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:01.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="PATCH">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/i-048.shtml" xml:lang="en">I-048</vuln:reference>
    </vuln:references>
    <vuln:summary>Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0213">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0213</vuln:cve-id>
    <vuln:published-datetime>1998-07-15T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:01.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0214">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0214</vuln:cve-id>
    <vuln:published-datetime>1992-07-21T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:01.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service by sending forged ICMP unreachable packets.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0215">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0215</vuln:cve-id>
    <vuln:published-datetime>1998-10-26T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:01.633-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/j-012.shtml" xml:lang="en">J-012</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19981004-01-PX" xml:lang="en">19981004-01-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>Routed allows attackers to append data to files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0216">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:inet:5.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:inet:5.01</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0216</vuln:cve-id>
    <vuln:published-datetime>1997-11-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:01.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service of inetd on Linux through SYN and RST packets.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0217">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.0.3c"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3a1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1psr_a"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:4.0.3</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1psr_a</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3a1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.2</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.0.3c</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0217</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:01.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0218">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:livingston_portmaster:portmaster"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:livingston_portmaster:portmaster</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0218</vuln:cve-id>
    <vuln:published-datetime>1995-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:01.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Livingston portmaster machines could be rebooted via a series of commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0219">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cat_soft:serv-u:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cat_soft:serv-u:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0219</vuln:cve-id>
    <vuln:published-datetime>1997-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:01.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/205" xml:lang="en">ftp-servu(205)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/269" xml:lang="en">269</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92582581330282&amp;w=2" xml:lang="en">19990504 Re: Buffer overflows in FTP Serv-U 2.5</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92574916930144&amp;w=2" xml:lang="en">19990503 Buffer overflows in FTP Serv-U 2.5</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0220">
    <vuln:cve-id>CVE-1999-0220</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Attackers can do a denial of service of IRC by crashing the server.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0221">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:lucent:ascend_routers"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:lucent:ascend_routers</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0221</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:02.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service of Ascend routers through port 150 (remote administration).</vuln:summary>
  </entry>
  <entry id="CVE-1999-0222">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:router"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:router</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0222</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:02.133-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0223">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0223</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:02.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/1878" xml:lang="en">1878</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches" xml:lang="en">http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches</vuln:reference>
    </vuln:references>
    <vuln:summary>Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0224">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0224</vuln:cve-id>
    <vuln:published-datetime>1999-07-23T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:02.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in Windows NT messenger service through a long username.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0225">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0225</vuln:cve-id>
    <vuln:published-datetime>1998-02-14T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:02.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>NAI</vuln:source>
      <vuln:reference href="http://www.nai.com/nai_labs/asp_set/advisory/25_windows_nt_dos_adv.asp" xml:lang="en">19980214 Windows NT Logon Denial of Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/support/kb.asp?ID=180963" xml:lang="en">Q180963</vuln:reference>
    </vuln:references>
    <vuln:summary>Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0226">
    <vuln:cve-id>CVE-1999-0226</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0227">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0227</vuln:cve-id>
    <vuln:published-datetime>1997-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:02.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q154087" xml:lang="en">Q154087</vuln:reference>
    </vuln:references>
    <vuln:summary>Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0228">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0228</vuln:cve-id>
    <vuln:published-datetime>1997-02-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:02.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q162567" xml:lang="en">Q162567</vuln:reference>
    </vuln:references>
    <vuln:summary>Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0229">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0229</vuln:cve-id>
    <vuln:published-datetime>1999-05-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:02.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in Windows NT IIS server using ..\..</vuln:summary>
  </entry>
  <entry id="CVE-1999-0230">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:4.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:4.1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:4.1.1</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:4.1.2</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:4.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0230</vuln:cve-id>
    <vuln:published-datetime>1997-12-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:02.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/1102" xml:lang="en">1102</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Cisco 7xx routers through the telnet service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0231">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:seattle_lab_software:slmail:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:seattle_lab_software:slmail:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0231</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:16:46.843-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0232">
    <vuln:cve-id>CVE-1999-0232</vuln:cve-id>
    <vuln:published-datetime>1995-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:03.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0233">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0233</vuln:cve-id>
    <vuln:published-datetime>1996-02-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2010-12-30T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q155056" xml:lang="en">Q155056</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q148188" xml:lang="en">Q148188</vuln:reference>
    </vuln:references>
    <vuln:summary>IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0234">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="AND">
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:yggdrasil:linux"/>
        </cpe-lang:logical-test>
        <cpe-lang:logical-test negate="false" operator="OR">
          <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
        </cpe-lang:logical-test>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:3.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:caldera:openlinux</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:3.0.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:4.2</vuln:product>
      <vuln:product>cpe:/o:yggdrasil:linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0234</vuln:cve-id>
    <vuln:published-datetime>1996-10-08T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:03.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Bash treats any character with a value of 255 as a command separator.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0235">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ncsa:ncsa_web_server:1.3"/>
        <cpe-lang:fact-ref name="cpe:/a:ncsa:ncsa_web_server:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:ncsa:ncsa_web_server:1.4.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ncsa:ncsa_web_server:1.4.1</vuln:product>
      <vuln:product>cpe:/a:ncsa:ncsa_web_server:1.4</vuln:product>
      <vuln:product>cpe:/a:ncsa:ncsa_web_server:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0235</vuln:cve-id>
    <vuln:published-datetime>1995-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:03.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0236">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server"/>
        <cpe-lang:fact-ref name="cpe:/a:ncsa:servers"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server</vuln:product>
      <vuln:product>cpe:/a:ncsa:servers</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0236</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:03.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0237">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:webcom:cgi_guestbook"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webcom:cgi_guestbook</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0237</vuln:cve-id>
    <vuln:published-datetime>1997-09-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:03.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Remote execution of arbitrary commands through Guestbook CGI program.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0238">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:php:php:2.0b10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php:1.0</vuln:product>
      <vuln:product>cpe:/a:php:php:2.0b10</vuln:product>
      <vuln:product>cpe:/a:php:php:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0238</vuln:cve-id>
    <vuln:published-datetime>1997-08-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:03.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>php.cgi allows attackers to read any file on the system.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0239">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netscape:fasttrack_server:3.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:fasttrack_server:3.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0239</vuln:cve-id>
    <vuln:published-datetime>1998-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:03.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/122" xml:lang="en">122</vuln:reference>
    </vuln:references>
    <vuln:summary>Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0240">
    <vuln:cve-id>CVE-1999-0240</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0241">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0241</vuln:cve-id>
    <vuln:published-datetime>1995-11-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:03.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0242">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:slackware:slackware_linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0242</vuln:cve-id>
    <vuln:published-datetime>1995-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:03.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0243">
    <vuln:cve-id>CVE-1999-0243</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Linux cfingerd could be exploited to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0244">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:livingston:radius:1.x"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:livingston:radius:1.x</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0244</vuln:cve-id>
    <vuln:published-datetime>1997-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:03.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0245">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0245</vuln:cve-id>
    <vuln:published-datetime>1995-09-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:03.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Some configurations of NIS+ in Linux allowed attackers to log in as the user "+".</vuln:summary>
  </entry>
  <entry id="CVE-1999-0246">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0246</vuln:cve-id>
    <vuln:published-datetime>1996-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:03.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>HP Remote Watch allows a remote user to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0247">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4sec"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4sec2"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4unoff3"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.4unoff4"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:isc:inn:1.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:isc:inn:1.5.1</vuln:product>
      <vuln:product>cpe:/a:isc:inn:1.5</vuln:product>
      <vuln:product>cpe:/a:isc:inn:1.4unoff4</vuln:product>
      <vuln:product>cpe:/a:isc:inn:1.4unoff3</vuln:product>
      <vuln:product>cpe:/a:isc:inn:1.4sec2</vuln:product>
      <vuln:product>cpe:/a:isc:inn:1.4sec</vuln:product>
      <vuln:product>cpe:/a:isc:inn:1.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0247</vuln:cve-id>
    <vuln:published-datetime>1997-07-21T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:04.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/1443" xml:lang="en">1443</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NAI</vuln:source>
      <vuln:reference href="http://www.nai.com/nai_labs/asp_set/advisory/17_inn_avd.asp" xml:lang="en">19970721 INN news server vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0248">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.27"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ssh:ssh:1.2.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0248</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:16:49.157-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1" xml:lang="en">http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html" xml:lang="en">http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html</vuln:reference>
    </vuln:references>
    <vuln:summary>A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0249">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0249</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:04.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Windows NT RSHSVC program allows remote users to execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0250">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:dan_bernstein:qmail:1.01"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:dan_bernstein:qmail:1.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0250</vuln:cve-id>
    <vuln:published-datetime>1997-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:04.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html" xml:lang="en">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://cr.yp.to/qmail/venema.html" xml:lang="en">http://cr.yp.to/qmail/venema.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2" xml:lang="en">19970612 qmail-dos-2.c, another denial of service attack</vuln:reference>
    </vuln:references>
    <vuln:summary>Denial of service in Qmail through long SMTP commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0251">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:talkd:talkd"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:talkd:talkd</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0251</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:04.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in talk program allows remote attackers to disrupt a user's display.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0252">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:lsoft:listserv"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:lsoft:listserv</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0252</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:08.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in listserv allows arbitrary command execution.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0253">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:1.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:3.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0253</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:08.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0254">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0254</vuln:cve-id>
    <vuln:published-datetime>1998-11-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:08.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0255">
    <vuln:cve-id>CVE-1999-0255</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Buffer overflow in ircd allows arbitrary command execution.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0256">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:jgaa:warftpd:1.66"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_95"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_95</vuln:product>
      <vuln:product>cpe:/a:jgaa:warftpd:1.66</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0256</vuln:cve-id>
    <vuln:published-datetime>1998-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:08.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/875" xml:lang="en">875</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in War FTP allows remote execution of commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0257">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0257</vuln:cve-id>
    <vuln:published-datetime>1998-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:08.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Nestea variation of teardrop IP fragmentation denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0258">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_95"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_95</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0258</vuln:cve-id>
    <vuln:published-datetime>1998-02-13T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:08.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Bonk variation of teardrop IP fragmentation denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0259">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:infodrom:cfingerd:1.2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:infodrom:cfingerd:1.2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0259</vuln:cve-id>
    <vuln:published-datetime>1997-05-23T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:08.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>cfingerd lists all users on a system via search.**@target.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0260">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:renaud_deraison:jj"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:renaud_deraison:jj</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0260</vuln:cve-id>
    <vuln:published-datetime>1996-12-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:08.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The jj CGI program allows command execution via shell metacharacters.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0261">
    <vuln:cve-id>CVE-1999-0261</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:08.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.insecure.org/sploits/netmanage.chameleon.overflows.html" xml:lang="en">http://www.insecure.org/sploits/netmanage.chameleon.overflows.html</vuln:reference>
    </vuln:references>
    <vuln:summary>Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0262">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:renaud_deraison:faxsurvey"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:renaud_deraison:faxsurvey</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0262</vuln:cve-id>
    <vuln:published-datetime>1998-08-04T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/1532" xml:lang="en">http-cgi-faxsurvey(1532)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/2056" xml:lang="en">2056</vuln:reference>
    </vuln:references>
    <vuln:summary>Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0263">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6:hw3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6:hw3:x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6:hw5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6:hw5:x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6:hw5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6:hw3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6:hw3:x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6:hw5:x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0263</vuln:cve-id>
    <vuln:published-datetime>1998-07-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/173" xml:lang="en">00173</vuln:reference>
    </vuln:references>
    <vuln:summary>Solaris SUNWadmap can be exploited to obtain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0264">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:miva:htmlscript"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:miva:htmlscript</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0264</vuln:cve-id>
    <vuln:published-datetime>1998-01-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>htmlscript CGI program allows remote read access to files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0265">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microware:os-9"/>
        <cpe-lang:fact-ref name="cpe:/o:novell:netware:3.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microware:os-9</vuln:product>
      <vuln:product>cpe:/o:novell:netware:3.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0265</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q154174" xml:lang="en">Q154174</vuln:reference>
    </vuln:references>
    <vuln:summary>ICMP redirect messages may crash or lock up a host.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0266">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:roar_smith:info2www"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:roar_smith:info2www</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0266</vuln:cve-id>
    <vuln:published-datetime>1998-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/1995" xml:lang="en">1995</vuln:reference>
    </vuln:references>
    <vuln:summary>The info2www CGI script allows remote file access or remote command execution.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0267">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ncsa:ncsa_httpd:1.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ncsa:ncsa_httpd:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0267</vuln:cve-id>
    <vuln:published-datetime>1997-09-23T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0268">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:metainfo:metaweb"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:metainfo:metaweb</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0268</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3969" xml:lang="en">3969</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/110" xml:lang="en">110</vuln:reference>
    </vuln:references>
    <vuln:summary>MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0269">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netscape:enterprise_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:enterprise_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0269</vuln:cve-id>
    <vuln:published-datetime>1998-08-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Netscape Enterprise servers may list files through the PageServices query.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0270">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0270</vuln:cve-id>
    <vuln:published-datetime>1998-04-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2011-03-07T21:00:25.437-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/810" xml:lang="en">sgi-pfdispaly(810)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/64" xml:lang="en">64</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/134" xml:lang="en">134</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/i-041.shtml" xml:lang="en">I-041</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19980401-01-P" xml:lang="en">19980401-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0271">
    <vuln:cve-id>CVE-1999-0271</vuln:cve-id>
    <vuln:published-datetime>1998-01-15T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Progressive Networks Real Video server (pnserver) can be crashed remotely.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0272">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:slmail:slmail:3.0.2421"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:slmail:slmail:3.0.2421</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0272</vuln:cve-id>
    <vuln:published-datetime>1997-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in Slmail v2.5 through the POP3 port.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0273">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0273</vuln:cve-id>
    <vuln:published-datetime>1998-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service through Solaris 2.5.1 telnet by sending ^D characters.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0274">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0274</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0275">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0275</vuln:cve-id>
    <vuln:published-datetime>1997-06-10T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0276">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hughes:msql:2.0."/>
        <cpe-lang:fact-ref name="cpe:/a:hughes:msql:2.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:hughes:msql:2.0.1</vuln:product>
      <vuln:product>cpe:/a:hughes:msql:2.0.</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0276</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:09.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>mSQL v2.0.1 and below allows remote execution through a buffer overflow.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0277">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0277</vuln:cve-id>
    <vuln:published-datetime>1996-10-28T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:10.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>The WorkMan program can be used to overwrite any file to get root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0278">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:3.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0278</vuln:cve-id>
    <vuln:published-datetime>1998-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:10.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:assessment_check name="oval:org.mitre.oval:def:913" href="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:913" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms98-003.mspx" xml:lang="en">MS98-003</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:913" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:913" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0279">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:excite:ews:1.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:excite:ews:1.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0279</vuln:cve-id>
    <vuln:published-datetime>1998-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:10.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0280">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:3.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:3.0.1</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0280</vuln:cve-id>
    <vuln:published-datetime>1997-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:10.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Remote command execution in Microsoft Internet Explorer using .lnk and .url files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0281">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:3.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0281</vuln:cve-id>
    <vuln:published-datetime>1997-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:10.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in IIS using long URLs.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0282">
    <vuln:cve-id>CVE-1999-0282</vuln:cve-id>
    <vuln:published-datetime>1997-09-23T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:13.757-04:00</vuln:last-modified-datetime>
    <vuln:summary>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1584, CVE-1999-1586.  Reason: This candidate combined references from one issue with the description from another issue.  Notes: Users should consult CVE-1999-1584 and CVE-1999-1586 to obtain the appropriate name.  All references and descriptions in this candidate have been removed to prevent accidental usage.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0283">
    <vuln:cve-id>CVE-1999-0283</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88256790401004&amp;w=2" xml:lang="en">19970716 Viewable .jhtml source with JavaWebServer</vuln:reference>
    </vuln:references>
    <vuln:summary>The Java Web Server would allow remote users to obtain the source code for CGI programs.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0284">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_domino_mail_server"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_domino_mail_server</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:exchange_server:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0284</vuln:cve-id>
    <vuln:published-datetime>1998-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:13.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:summary>Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0285">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0285</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:16:54.203-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0286">
    <vuln:cve-id>CVE-1999-0286</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0287">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:webcom:cgi_guestbook"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webcom:cgi_guestbook</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0287</vuln:cve-id>
    <vuln:published-datetime>1999-04-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:14.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:summary>Vulnerability in the Wguest CGI program.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0288">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0288</vuln:cve-id>
    <vuln:published-datetime>1998-08-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:14.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/1233" xml:lang="en">nt-winsupd-fix(1233)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://safenetworks.com/Windows/wins.html" xml:lang="en">http://safenetworks.com/Windows/wins.html</vuln:reference>
    </vuln:references>
    <vuln:summary>The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0289">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:apache:http_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:apache:http_server</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0289</vuln:cve-id>
    <vuln:published-datetime>1999-12-12T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:16:54.733-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0290">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:qbik:wingate"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qbik:wingate</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0290</vuln:cve-id>
    <vuln:published-datetime>1998-02-21T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:14.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0291">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:qbik:wingate"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qbik:wingate</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0291</vuln:cve-id>
    <vuln:published-datetime>1999-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:14.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0292">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0292</vuln:cve-id>
    <vuln:published-datetime>1997-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:14.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Denial of service through Winpopup using large user names.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0293">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0293</vuln:cve-id>
    <vuln:published-datetime>1998-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:14.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>AAA authentication on Cisco systems allows attackers to execute commands without authorization.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0294">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:wins"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:wins</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0294</vuln:cve-id>
    <vuln:published-datetime>1997-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:14.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>All records in a WINS database can be deleted through SNMP for a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0295">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0295</vuln:cve-id>
    <vuln:published-datetime>1997-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:14.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/157" xml:lang="en">00157</vuln:reference>
    </vuln:references>
    <vuln:summary>Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0296">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0296</vuln:cve-id>
    <vuln:published-datetime>1998-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:14.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/162" xml:lang="en">00162</vuln:reference>
    </vuln:references>
    <vuln:summary>Solaris volrmmount program allows attackers to read any file.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0297">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:paul_vixie:vixie_cron:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:2.0.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
      <vuln:product>cpe:/a:paul_vixie:vixie_cron:3.0</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0297</vuln:cve-id>
    <vuln:published-datetime>1996-12-12T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:14.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0298">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:slackware:slackware_linux:2.2</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:2.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0298</vuln:cve-id>
    <vuln:published-datetime>1997-02-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:14.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NAI</vuln:source>
      <vuln:reference href="http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp" xml:lang="en">19970205 Vulnerabilities in Ypbind when run with -ypset/-ypsetme</vuln:reference>
    </vuln:references>
    <vuln:summary>ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0299">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:6.2:stable"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:6.2:stable</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0299</vuln:cve-id>
    <vuln:published-datetime>1997-03-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:16:56.250-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6093" xml:lang="en">6093</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in FreeBSD lpd through long DNS hostnames.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0300">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0300</vuln:cve-id>
    <vuln:published-datetime>1997-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:15.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/155" xml:lang="en">00155</vuln:reference>
    </vuln:references>
    <vuln:summary>nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0301">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0301</vuln:cve-id>
    <vuln:published-datetime>1997-08-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:15.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/149" xml:lang="en">00149</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in SunOS/Solaris ps command.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0302">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0302</vuln:cve-id>
    <vuln:published-datetime>1998-09-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:15.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/176" xml:lang="en">00176</vuln:reference>
    </vuln:references>
    <vuln:summary>SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0303">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:digital:osf_1:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.3:u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.4::jl"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:1.1.1a</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1.3:u1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.2</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:digital:osf_1:1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1.4</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:::x86</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1.4::jl</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0303</vuln:cve-id>
    <vuln:published-datetime>1998-05-21T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:15.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0304">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:netbsd:netbsd:2.0.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.2</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:3.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0304</vuln:cve-id>
    <vuln:published-datetime>1998-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:15.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>mmap function in BSD allows local attackers in the kmem group to modify memory through devices.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0305">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:2.0</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.5</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0305</vuln:cve-id>
    <vuln:published-datetime>1998-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:15.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/736" xml:lang="en">bsd-sourceroute(736)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/11502" xml:lang="en">11502</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.openbsd.org/advisories/sourceroute.txt" xml:lang="en">http://www.openbsd.org/advisories/sourceroute.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0306">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:vvos:10.24"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:vvos:10.24</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0306</vuln:cve-id>
    <vuln:published-datetime>1997-11-04T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>buffer overflow in HP xlock program.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0307">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:9.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0307</vuln:cve-id>
    <vuln:published-datetime>2000-12-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in HP-UX cstm program allows local users to gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0308">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:8</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0308</vuln:cve-id>
    <vuln:published-datetime>1996-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9410-018" xml:lang="en">HPSBUX9410-018</vuln:reference>
    </vuln:references>
    <vuln:summary>HP-UX gwind program allows users to modify arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0309">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0309</vuln:cve-id>
    <vuln:published-datetime>1997-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-056" xml:lang="en">HPSBUX9702-056</vuln:reference>
    </vuln:references>
    <vuln:summary>HP-UX vgdisplay program gives root access to local users.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0310">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.25"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ssh:ssh:1.2.25</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0310</vuln:cve-id>
    <vuln:published-datetime>1998-09-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>SSH 1.2.25 on HP-UX allows access to new user accounts.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0311">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0311</vuln:cve-id>
    <vuln:published-datetime>1996-11-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9612-042" xml:lang="en">HPSBUX9612-042</vuln:reference>
    </vuln:references>
    <vuln:summary>fpkg2swpk in HP-UX allows local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0312">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0312</vuln:cve-id>
    <vuln:published-datetime>1993-01-13T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>HP ypbind allows attackers with root privileges to modify NIS data.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0313">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4::s2mp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.4::s2mp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0313</vuln:cve-id>
    <vuln:published-datetime>1998-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/1441" xml:lang="en">sgi-disk-bandwidth(1441)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/214" xml:lang="en">214</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/213/exploit" xml:lang="en">http://www.securityfocus.com/bid/213/exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/936" xml:lang="en">936</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P" xml:lang="en">19980701-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0314">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0314</vuln:cve-id>
    <vuln:published-datetime>1998-07-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/1199" xml:lang="en">sgi-ioconfig(1199)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/213/exploit" xml:lang="en">http://www.securityfocus.com/bid/213/exploit</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/213" xml:lang="en">213</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6788" xml:lang="en">6788</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P" xml:lang="en">19980701-01-P</vuln:reference>
    </vuln:references>
    <vuln:summary>ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0315">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0315</vuln:cve-id>
    <vuln:published-datetime>1997-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/138" xml:lang="en">00138</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Solaris fdformat command gives root access to local users.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0316">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sam_lantinga:splitvt:1.6.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sam_lantinga:splitvt:1.6.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0316</vuln:cve-id>
    <vuln:published-datetime>1995-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in Linux splitvt command gives root access to local users.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0317">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0317</vuln:cve-id>
    <vuln:published-datetime>1999-11-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in Linux su command gives root access to local users.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0318">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:8.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:8.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:11</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:6.0</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0318</vuln:cve-id>
    <vuln:published-datetime>1997-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0319">
    <vuln:cve-id>CVE-1999-0319</vuln:cve-id>
    <vuln:published-datetime>1996-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:16.960-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0320">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.3u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos:4.1.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos:4.1.3u1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:sunos:4.1.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0320</vuln:cve-id>
    <vuln:published-datetime>1998-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0321">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0321</vuln:cve-id>
    <vuln:published-datetime>1998-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in Solaris kcms_configure command allows local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0322">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0322</vuln:cve-id>
    <vuln:published-datetime>1997-10-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6092" xml:lang="en">6092</vuln:reference>
    </vuln:references>
    <vuln:summary>The open() function in FreeBSD allows local attackers to write to arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0323">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:netbsd:netbsd:2.0.4</vuln:product>
      <vuln:product>cpe:/o:openbsd:openbsd:2.2</vuln:product>
      <vuln:product>cpe:/o:bsdi:bsd_os:3.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0323</vuln:cve-id>
    <vuln:published-datetime>1998-02-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NETBSD</vuln:source>
      <vuln:reference href="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1998-003.txt.asc" xml:lang="en">1998-003</vuln:reference>
    </vuln:references>
    <vuln:summary>FreeBSD mmap function allows users to modify append-only or immutable files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0324">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0324</vuln:cve-id>
    <vuln:published-datetime>1996-09-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-053" xml:lang="en">HPSBUX9702-053</vuln:reference>
    </vuln:references>
    <vuln:summary>ppl program in HP-UX allows local users to create root files through symlinks.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0325">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:8"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:8</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0325</vuln:cve-id>
    <vuln:published-datetime>1995-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9406-013" xml:lang="en">HPSBUX9406-013</vuln:reference>
    </vuln:references>
    <vuln:summary>vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0326">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.30"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10.30</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:9</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0326</vuln:cve-id>
    <vuln:published-datetime>1997-10-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9710-071" xml:lang="en">HPSBUX9710-071</vuln:reference>
    </vuln:references>
    <vuln:summary>Vulnerability in HP-UX mediainit program.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0327">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0327</vuln:cve-id>
    <vuln:published-datetime>1997-11-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX" xml:lang="en">19971103-01-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>SGI syserr program allows local users to corrupt files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0328">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3::xfs</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1::xfs</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0328</vuln:cve-id>
    <vuln:published-datetime>1997-11-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX" xml:lang="en">19971103-01-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>SGI permissions program allows local users to gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0329">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.0.1::xfs"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.0.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.1</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.0.1::xfs</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3::xfs</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0329</vuln:cve-id>
    <vuln:published-datetime>1998-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19980602-01-PX" xml:lang="en">19980602-01-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>SGI mediad program allows local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0330">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0330</vuln:cve-id>
    <vuln:published-datetime>1998-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Linux bdash game has a buffer overflow that allows local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0331">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:3.0.2"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:4.0.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:4.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:3.0.2</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:4.0.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0331</vuln:cve-id>
    <vuln:published-datetime>1998-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in Internet Explorer 4.0(1).</vuln:summary>
  </entry>
  <entry id="CVE-1999-0332">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:netmeeting:2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:netmeeting:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0332</vuln:cve-id>
    <vuln:published-datetime>1998-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:17.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q184346" xml:lang="en">Q184346</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in NetMeeting allows denial of service and remote command execution.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0333">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0333</vuln:cve-id>
    <vuln:published-datetime>1998-08-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0334">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0334</vuln:cve-id>
    <vuln:published-datetime>1993-12-16T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0335">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:bsdi:bsd_os:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:bsdi:bsd_os:2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0335</vuln:cve-id>
    <vuln:published-datetime>1996-08-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-1999-0032.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0336">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:10</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0336</vuln:cve-id>
    <vuln:published-datetime>1996-11-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in mstm in HP-UX allows local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0337">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:1.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:2.2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:2.2.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:1.3</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:1.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0337</vuln:cve-id>
    <vuln:published-datetime>1994-06-03T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0338">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:ibm:aix:3.2.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0338</vuln:cve-id>
    <vuln:published-datetime>1994-02-24T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>AIX Licensed Program Product performance tools allow local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0339">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::ppc"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::ppc</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0339</vuln:cve-id>
    <vuln:published-datetime>1998-08-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0340">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0340</vuln:cve-id>
    <vuln:published-datetime>1997-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in Linux Slackware crond program allows local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0341">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:slackware:slackware_linux:2.2</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:2.1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:1.3.1</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0341</vuln:cve-id>
    <vuln:published-datetime>1998-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in the Linux mail program "deliver" allows local users to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0342">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:pam:pam:0.64"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:pam:pam:0.64</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0342</vuln:cve-id>
    <vuln:published-datetime>1998-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Linux PAM modules allow local users to gain root access using temporary files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0343">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:palace:palace_client"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:palace:palace_client</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0343</vuln:cve-id>
    <vuln:published-datetime>1998-10-02T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>A malicious Palace server can force a client to execute arbitrary programs.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0344">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0344</vuln:cve-id>
    <vuln:published-datetime>1998-08-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.790-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q190288" xml:lang="en">Q190288</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms98-009.mspx" xml:lang="en">MS98-009</vuln:reference>
    </vuln:references>
    <vuln:summary>NT users can gain debug-level access on a system process using the Sechole exploit.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0345">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.1.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:ibm:aix:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:internet_faststart:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:open_desktop:3"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:sunos"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:ibm:sng:2.1"/>
        <cpe-lang:fact-ref name="cpe:/h:ibm:sng:2.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:sunos</vuln:product>
      <vuln:product>cpe:/o:sco:open_desktop:3</vuln:product>
      <vuln:product>cpe:/o:sco:internet_faststart:1.0</vuln:product>
      <vuln:product>cpe:/o:sco:internet_faststart:1.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.0</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5</vuln:product>
      <vuln:product>cpe:/h:ibm:sng:2.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:3.2</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.1</vuln:product>
      <vuln:product>cpe:/o:ibm:aix:4.2</vuln:product>
      <vuln:product>cpe:/h:ibm:sng:2.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.1.5.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0345</vuln:cve-id>
    <vuln:published-datetime>1997-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0346">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:php:php_fi"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:php:php_fi</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0346</vuln:cve-id>
    <vuln:published-datetime>1997-10-16T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:18.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/713" xml:lang="en">713</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3397" xml:lang="en">3397</vuln:reference>
    </vuln:references>
    <vuln:summary>CGI PHP mlog script allows an attacker to read any file on the target server.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0347">
    <vuln:cve-id>CVE-1999-0347</vuln:cve-id>
    <vuln:published-datetime>1999-01-26T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-11-02T00:00:00.000-05:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91756771207719&amp;w=2" xml:lang="en">19990126 Javascript ecurity bug in Internet Explorer</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91745430007021&amp;w=2" xml:lang="en">19990126 Javascript ecurity bug in Internet Explorer</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0348">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0348</vuln:cve-id>
    <vuln:published-datetime>1999-01-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:19.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q197003" xml:lang="en">Q197003</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/930" xml:lang="en">930</vuln:reference>
    </vuln:references>
    <vuln:summary>IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0349">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:3.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0349</vuln:cve-id>
    <vuln:published-datetime>1999-01-27T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:19.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EEYE</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/IIS%20Remote%20FTP%20Exploit/DoS%20Attack.html" xml:lang="en">IIS Remote FTP Exploit/DoS Attack</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q188348" xml:lang="en">Q188348</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms99-003.mspx" xml:lang="en">MS99-003</vuln:reference>
    </vuln:references>
    <vuln:summary>A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0350">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:rational_software:clearcase:3.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:rational_software:clearcase:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0350</vuln:cve-id>
    <vuln:published-datetime>1999-02-08T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:19.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0351">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ftp:ftp_pasv"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ftp:ftp_pasv</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0351</vuln:cve-id>
    <vuln:published-datetime>1999-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:17:03.967-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/xforce/xfdb/3389" xml:lang="en">pasv-pizza-thief-dos(3389)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MISC</vuln:source>
      <vuln:reference href="http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt" xml:lang="en">http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt</vuln:reference>
    </vuln:references>
    <vuln:summary>FTP PASV "Pizza Thief" denial of service and unauthorized data access.  Attackers can steal data by connecting to a port that was intended for use by a client.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0352">
    <vuln:cve-id>CVE-1999-0352</vuln:cve-id>
    <vuln:published-datetime>1999-01-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:24.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0353">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.10"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.10</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0353</vuln:cve-id>
    <vuln:published-datetime>1999-02-10T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:24.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>9.3</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>MEDIUM</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9902-091" xml:lang="en">HPSBUX9902-091</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/j-026.shtml" xml:lang="en">J-026</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5294" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5294" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0354">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:word:97"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:ie:4.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:word:97</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0354</vuln:cve-id>
    <vuln:published-datetime>1999-11-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:24.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms99-002.asp" xml:lang="en">MS99-002</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content.  Also applies to Outlook when the client views a malicious email message.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0355">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ca:controlit:4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ca:controlit:4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0355</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:24.557-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0356">
    <vuln:cve-id>CVE-1999-0356</vuln:cve-id>
    <vuln:published-datetime>1999-01-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:24.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0357">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0357</vuln:cve-id>
    <vuln:published-datetime>1999-01-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:24.697-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0358">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:digital:unix:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:unix:4.0a"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:unix:4.0b"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:unix:4.0c"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:unix:4.0d"/>
        <cpe-lang:fact-ref name="cpe:/o:digital:unix:4.0e"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:digital:unix:4.0c</vuln:product>
      <vuln:product>cpe:/o:digital:unix:4.0b</vuln:product>
      <vuln:product>cpe:/o:digital:unix:4.0a</vuln:product>
      <vuln:product>cpe:/o:digital:unix:4.0e</vuln:product>
      <vuln:product>cpe:/o:digital:unix:4.0</vuln:product>
      <vuln:product>cpe:/o:digital:unix:4.0d</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0358</vuln:cve-id>
    <vuln:published-datetime>1999-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:24.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/12121" xml:lang="en">19990125 Digital Unix 4.0 exploitable buffer overflows</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://www.ciac.org/ciac/bulletins/j-027.shtml" xml:lang="en">J-027</vuln:reference>
    </vuln:references>
    <vuln:summary>Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0359">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:marc_schaefer:ptylogin"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:marc_schaefer:ptylogin</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0359</vuln:cve-id>
    <vuln:published-datetime>2001-03-12T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:24.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>ptylogin in Unix systems allows users to perform a denial of service by locking out modems, dial out with that modem, or obtain passwords.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0360">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:site_server:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:site_server:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0360</vuln:cve-id>
    <vuln:published-datetime>1999-01-30T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:17:05.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91763097004101&amp;w=2" xml:lang="en">19990130 Security Advisory for Internet Information Server 4 with Site</vuln:reference>
    </vuln:references>
    <vuln:summary>MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0361">
    <vuln:cve-id>CVE-1999-0361</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0362">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ipswitch:ws_ftp_server:1.0.1eval"/>
        <cpe-lang:fact-ref name="cpe:/a:ipswitch:ws_ftp_server:1.0.2eval"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ipswitch:ws_ftp_server:1.0.2eval</vuln:product>
      <vuln:product>cpe:/a:ipswitch:ws_ftp_server:1.0.1eval</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0362</vuln:cve-id>
    <vuln:published-datetime>1999-02-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/217" xml:lang="en">217</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EEYE</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/AD02021999.html" xml:lang="en">AD02021999</vuln:reference>
    </vuln:references>
    <vuln:summary>WS_FTP server remote denial of service through cwd command.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0363">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:plp:line_printer_control"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:plp:line_printer_control</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0363</vuln:cve-id>
    <vuln:published-datetime>1999-02-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.103-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/328" xml:lang="en">328</vuln:reference>
    </vuln:references>
    <vuln:summary>SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0364">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:fms_inc.:total_vb_sourcebook:6.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:access:97"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:access:97</vuln:product>
      <vuln:product>cpe:/a:fms_inc.:total_vb_sourcebook:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0364</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:17:05.670-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91816470220259&amp;w=2" xml:lang="en">19990204 Microsoft Access 97 Stores Database Password as Plaintext</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0365">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:metainfo:metaip:3.1"/>
        <cpe-lang:fact-ref name="cpe:/a:metainfo:sendmail:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:metainfo:sendmail:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:metainfo:sendmail:2.5</vuln:product>
      <vuln:product>cpe:/a:metainfo:sendmail:2.0</vuln:product>
      <vuln:product>cpe:/a:metainfo:metaip:3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0365</vuln:cve-id>
    <vuln:published-datetime>1999-02-04T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0366">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0366</vuln:cve-id>
    <vuln:published-datetime>1999-02-08T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.307-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q214840" xml:lang="en">Q214840</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms99-004.mspx" xml:lang="en">MS99-004</vuln:reference>
    </vuln:references>
    <vuln:summary>In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0367">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:netbsd:netbsd:2.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0367</vuln:cve-id>
    <vuln:published-datetime>1999-02-09T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.367-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/7571" xml:lang="en">7571</vuln:reference>
    </vuln:references>
    <vuln:summary>NetBSD netstat command allows local users to access kernel memory.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0368">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:proftpd_project:proftpd:1.2_pre1"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18"/>
        <cpe-lang:fact-ref name="cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr9"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:unixware:7.0.1"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sco:openserver:5.0.5</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.5</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.1</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.6</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18_vr9</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.0</vuln:product>
      <vuln:product>cpe:/o:caldera:openlinux:1.3</vuln:product>
      <vuln:product>cpe:/o:sco:unixware:7.0.1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:2.0</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.4</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.0</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.2</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:5.0.4</vuln:product>
      <vuln:product>cpe:/a:proftpd_project:proftpd:1.2_pre1</vuln:product>
      <vuln:product>cpe:/a:washington_university:wu-ftpd:2.4.2_beta18</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0368</vuln:cve-id>
    <vuln:published-datetime>1999-02-09T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0369">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.1a"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.3:u1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.1.4::jl"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:1.1.1a</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1.3:u1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.2</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.3</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.1</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.1.4::jl</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0369</vuln:cve-id>
    <vuln:published-datetime>1997-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.507-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SUN</vuln:source>
      <vuln:reference href="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/183" xml:lang="en">00183</vuln:reference>
    </vuln:references>
    <vuln:summary>The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0370">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.4::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.4::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0370</vuln:cve-id>
    <vuln:published-datetime>1999-02-10T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/165" xml:lang="en">165</vuln:reference>
    </vuln:references>
    <vuln:summary>In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0371">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:university_of_kansas:lynx:2.7.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:university_of_kansas:lynx:2.7.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0371</vuln:cve-id>
    <vuln:published-datetime>1999-02-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Lynx allows a local user to overwrite sensitive files through /tmp symlinks.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0372">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:backoffice:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:backoffice:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0372</vuln:cve-id>
    <vuln:published-datetime>1999-02-12T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q217004" xml:lang="en">Q217004</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms99-005.mspx" xml:lang="en">MS99-005</vuln:reference>
    </vuln:references>
    <vuln:summary>The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0373">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0373</vuln:cve-id>
    <vuln:published-datetime>1999-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0374">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0374</vuln:cve-id>
    <vuln:published-datetime>1999-02-16T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.853-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Debian GNU/Linux cfengine package is susceptible to a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0375">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:network_flight_recorder:network_flight_recorder:2.0.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:network_flight_recorder:network_flight_recorder:2.0.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0375</vuln:cve-id>
    <vuln:published-datetime>1999-02-16T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0376">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0376</vuln:cve-id>
    <vuln:published-datetime>1999-02-20T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:25.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms99-006.mspx" xml:lang="en">MS99-006</vuln:reference>
    </vuln:references>
    <vuln:summary>Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0377">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:unix:unix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:unix:unix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0377</vuln:cve-id>
    <vuln:published-datetime>1999-02-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:26.057-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0378">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:trend_micro:interscan_viruswall"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:trend_micro:interscan_viruswall</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0378</vuln:cve-id>
    <vuln:published-datetime>1999-02-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:26.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6167" xml:lang="en">6167</vuln:reference>
    </vuln:references>
    <vuln:summary>InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0379">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:backoffice_resource_kit:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:backoffice_resource_kit:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0379</vuln:cve-id>
    <vuln:published-datetime>1999-02-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:26.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/498" xml:lang="en">498</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/1019" xml:lang="en">1019</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms99-007.mspx" xml:lang="en">MS99-007</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0380">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:seattle_lab_software:slmail:3.0.2421"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:seattle_lab_software:slmail:3.0.2421</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0380</vuln:cve-id>
    <vuln:published-datetime>1999-02-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:26.257-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>XF</vuln:source>
      <vuln:reference href="http://xforce.iss.net/static/5392.php" xml:lang="en">slmail-ras-ntfs-bypass(5392)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/497" xml:lang="en">497</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92110501504997&amp;w=2" xml:lang="en">SLmail 3.2 Build 3113 (Web Administration Security Fix)</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>NTBUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91999015212415&amp;w=2" xml:lang="en">199902225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91996412724720&amp;w=2" xml:lang="en">19990225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</vuln:reference>
    </vuln:references>
    <vuln:summary>SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0381">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0381</vuln:cve-id>
    <vuln:published-datetime>1999-02-26T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:26.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/342" xml:lang="en">342</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.990225011801.12757A-100000@eleet" xml:lang="en">19990225 SUPER buffer overflow</vuln:reference>
    </vuln:references>
    <vuln:summary>super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0382">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp5</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0382</vuln:cve-id>
    <vuln:published-datetime>1999-03-12T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:26.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms99-008.mspx" xml:lang="en">MS99-008</vuln:reference>
    </vuln:references>
    <vuln:summary>The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0383">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:acc:tigris:10.5.8"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:acc:tigris:10.5.8</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0383</vuln:cve-id>
    <vuln:published-datetime>1999-02-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:26.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/183" xml:lang="en">183</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/267" xml:lang="en">267</vuln:reference>
    </vuln:references>
    <vuln:summary>ACC Tigris allows public access without a login.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0384">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:office:98::mac"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:outlook:98"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:project:98"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:visual_basic:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/a:microsoft:office:98::mac</vuln:product>
      <vuln:product>cpe:/a:microsoft:visual_basic:5.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:project:98</vuln:product>
      <vuln:product>cpe:/a:microsoft:outlook:98</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0384</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:26.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms99-001.mspx" xml:lang="en">MS99-001</vuln:reference>
    </vuln:references>
    <vuln:summary>The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0385">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:exchange_server:5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:exchange_server:5.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0385</vuln:cve-id>
    <vuln:published-datetime>1998-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:26.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms99-009.mspx" xml:lang="en">MS99-009</vuln:reference>
    </vuln:references>
    <vuln:summary>The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0386">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:frontpage"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:personal_web_server:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:personal_web_server:4.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:frontpage</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0386</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:26.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/111" xml:lang="en">111</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms99-010.mspx" xml:lang="en">MS99-010</vuln:reference>
    </vuln:references>
    <vuln:summary>Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0387">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_95"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_95</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0387</vuln:cve-id>
    <vuln:published-datetime>1999-11-29T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-255"/>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/829" xml:lang="en">829</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms99-052.asp" xml:lang="en">MS99-052</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>MSKB</vuln:source>
      <vuln:reference href="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q168115" xml:lang="en">Q168115</vuln:reference>
    </vuln:references>
    <vuln:summary>A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0388">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:datalynx:suguard:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:datalynx:suguard:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0388</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:26.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3186" xml:lang="en">3186</vuln:reference>
    </vuln:references>
    <vuln:summary>DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0389">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:1.1"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:2.0</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:1.1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:1.3</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:1.3.1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0389</vuln:cve-id>
    <vuln:published-datetime>1999-01-03T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:26.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/324" xml:lang="en">324</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in the bootp server in the Debian Linux netstd package.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0390">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.2::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:redhat:linux:5.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.2</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.2::i386</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.1</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0390</vuln:cve-id>
    <vuln:published-datetime>1999-01-04T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:27.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/187" xml:lang="en">187</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CALDERA</vuln:source>
      <vuln:reference href="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-006.1.txt" xml:lang="en">CSSA-1999-006.1</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Dosemu Slang library in Linux.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0391">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:terminal_server"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_2000"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:3.5.1:sp5"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp1"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp2"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp3"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp4"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt:4.0:sp5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp5</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp4</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp3</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp5</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_2000</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp4</vuln:product>
      <vuln:product>cpe:/a:microsoft:terminal_server</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp1</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:4.0:sp2</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt:3.5.1:sp1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0391</vuln:cve-id>
    <vuln:published-datetime>1999-01-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:27.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0392">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:thomas_boutell:cgic_library:1.05"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:thomas_boutell:cgic_library:1.05</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0392</vuln:cve-id>
    <vuln:published-datetime>1999-01-10T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:27.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Buffer overflow in Thomas Boutell's cgic library version up to 1.05.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0393">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.8"/>
        <cpe-lang:fact-ref name="cpe:/a:eric_allman:sendmail:8.9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.8</vuln:product>
      <vuln:product>cpe:/a:eric_allman:sendmail:8.9.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0393</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:27.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91694391227372&amp;w=2" xml:lang="en">19990121 Sendmail 8.8.x/8.9.x bugware</vuln:reference>
    </vuln:references>
    <vuln:summary>Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0394">
    <vuln:cve-id>CVE-1999-0394</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0395">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:backweb_technologies:backweb_polite_agent_protocol"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:backweb_technologies:backweb_polite_agent_protocol</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0395</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:27.430-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.1</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>ISS</vuln:source>
      <vuln:reference href="http://xforce.iss.net/alerts/advise17.php" xml:lang="en">19990118 Vulnerability in the BackWeb Polite Agent Protocol</vuln:reference>
    </vuln:references>
    <vuln:summary>A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0396">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:2.0.4"/>
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:2.4</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:2.0.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0396</vuln:cve-id>
    <vuln:published-datetime>1999-02-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:27.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0397">
    <vuln:cve-id>CVE-1999-0397</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0398">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh:1.2.27"/>
        <cpe-lang:fact-ref name="cpe:/a:ssh:ssh2:2.0.11"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ssh:ssh2:2.0.11</vuln:product>
      <vuln:product>cpe:/a:ssh:ssh:1.2.27</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0398</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:27.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:summary>In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0399">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:khaled_mardam-bey:mirc:5.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:khaled_mardam-bey:mirc:5.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0399</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:27.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0400">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0400</vuln:cve-id>
    <vuln:published-datetime>1999-01-26T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:17:11.140-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/344" xml:lang="en">344</vuln:reference>
    </vuln:references>
    <vuln:summary>Denial of service in Linux 2.2.0 running the ldd command on a core file.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0401">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0401</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:27.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>3.7</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:summary>A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0402">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:gnu:wget:1.5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:gnu:wget:1.5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0402</vuln:cve-id>
    <vuln:published-datetime>1999-01-02T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:29.727-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0403">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cyrix:linux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cyrix:linux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0403</vuln:cve-id>
    <vuln:published-datetime>1999-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:29.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91821080015725&amp;w=2" xml:lang="en">19990204 Cyrix bug: freeze in hell, badboy</vuln:reference>
    </vuln:references>
    <vuln:summary>A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0404">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:smartmax_software:mailmax"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:smartmax_software:mailmax</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0404</vuln:cve-id>
    <vuln:published-datetime>1999-02-14T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:29.867-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0405">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.0.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.1.7.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.2"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.3"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.4"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:2.2.8"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:freebsd:freebsd:3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.2::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:4.2"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:4.3"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:4.4"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:4.4.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.7.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.6</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:4.3</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.4</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.2</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:4.4</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.3</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:4.2</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.8</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:2.0.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.6</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:3.0</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.2::i386</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.3</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.1</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:2.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:4.4.1</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.1.5</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.0</vuln:product>
      <vuln:product>cpe:/o:freebsd:freebsd:2.2.2</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.1</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0405</vuln:cve-id>
    <vuln:published-datetime>1999-02-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:29.930-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3163" xml:lang="en">3163</vuln:reference>
    </vuln:references>
    <vuln:summary>A buffer overflow in lsof allows local users to obtain root privilege.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0406">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:digital:unix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:digital:unix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0406</vuln:cve-id>
    <vuln:published-datetime>1999-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:30.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0407">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0407</vuln:cve-id>
    <vuln:published-datetime>1999-02-09T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:17:12.187-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92000623021036&amp;w=2" xml:lang="en">19990209 Re: IIS4 allows proxied password attacks over NetBIOS</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91983486431506&amp;w=2" xml:lang="en">19990209 ALERT: IIS4 allows proxied password attacks over NetBIOS</vuln:reference>
    </vuln:references>
    <vuln:summary>By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0408">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sun:cobalt_raq"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sun:cobalt_raq</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0408</vuln:cve-id>
    <vuln:published-datetime>1999-02-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:30.163-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/337" xml:lang="en">337</vuln:reference>
    </vuln:references>
    <vuln:summary>Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0409">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:suse:suse_linux:3.5</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0409</vuln:cve-id>
    <vuln:published-datetime>1999-03-04T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:30.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/319" xml:lang="en">319</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0410">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0410</vuln:cve-id>
    <vuln:published-datetime>1999-03-05T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:30.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/293" xml:lang="en">293</vuln:reference>
    </vuln:references>
    <vuln:summary>The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0411">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:3.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver:5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sco:openserver:5</vuln:product>
      <vuln:product>cpe:/o:sco:openserver:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0411</vuln:cve-id>
    <vuln:published-datetime>1999-03-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:30.383-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0412">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:3.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:2.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0412</vuln:cve-id>
    <vuln:published-datetime>1999-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:30.447-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/501" xml:lang="en">501</vuln:reference>
    </vuln:references>
    <vuln:summary>In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0413">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:5.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.2"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.3"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.4"/>
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix:6.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix:6.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.2</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:5.3</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.4</vuln:product>
      <vuln:product>cpe:/o:sgi:irix:6.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0413</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:30.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19990301-01-PX" xml:lang="en">19990301-01-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>A buffer overflow in the SGI X server allows local users to gain root access through the X server font path.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0414">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.30"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.35"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.36"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0.37"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.35</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.36</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.37</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0.30</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0414</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:30.587-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0415">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:cisco_7xx_routers:3.2"/>
        <cpe-lang:fact-ref name="cpe:/h:cisco:cisco_7xx_routers:4.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:cisco_7xx_routers:4.2</vuln:product>
      <vuln:product>cpe:/h:cisco:cisco_7xx_routers:3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0415</vuln:cve-id>
    <vuln:published-datetime>1999-03-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:30.647-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml" xml:lang="en">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml" xml:lang="en">J-034</vuln:reference>
    </vuln:references>
    <vuln:summary>The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0416">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:cisco_7xx_routers"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:cisco_7xx_routers</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0416</vuln:cve-id>
    <vuln:published-datetime>1999-03-11T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:30.743-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CISCO</vuln:source>
      <vuln:reference href="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml" xml:lang="en">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CIAC</vuln:source>
      <vuln:reference href="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml" xml:lang="en">J-034</vuln:reference>
    </vuln:references>
    <vuln:summary>Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0417">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0417</vuln:cve-id>
    <vuln:published-datetime>1999-03-09T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:30.807-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/448" xml:lang="en">448</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/1001" xml:lang="en">1001</vuln:reference>
    </vuln:references>
    <vuln:summary>64 bit Solaris 7 procfs allows local users to perform a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0418">
    <vuln:cve-id>CVE-1999-0418</vuln:cve-id>
    <vuln:published-datetime>1999-03-08T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92100018214316&amp;w=2" xml:lang="en">19990308 SMTP server account probing</vuln:reference>
    </vuln:references>
    <vuln:summary>Denial of service in SMTP applications such as Sendmail, when a remote attacker (e.g. spammer) uses many "RCPT TO" commands in the same connection.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0419">
    <vuln:cve-id>CVE-1999-0419</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:30.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0420">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netbsd:umapfs"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netbsd:umapfs</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0420</vuln:cve-id>
    <vuln:published-datetime>1999-03-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.007-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0421">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.6</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0421</vuln:cve-id>
    <vuln:published-datetime>1999-03-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.070-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/338" xml:lang="en">338</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/981" xml:lang="en">981</vuln:reference>
    </vuln:references>
    <vuln:summary>During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0422">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0422</vuln:cve-id>
    <vuln:published-datetime>1999-03-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the "noexec" flag set.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0423">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0423</vuln:cve-id>
    <vuln:published-datetime>1994-06-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.210-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-093" xml:lang="en">HPSBUX9903-093</vuln:reference>
    </vuln:references>
    <vuln:summary>Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0424">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:communicator:4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0424</vuln:cve-id>
    <vuln:published-datetime>1999-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0425">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:communicator:4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0425</vuln:cve-id>
    <vuln:published-datetime>1999-03-18T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>6.4</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0426">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:suse:suse_linux:6.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0426</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.413-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0427">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:eudora:4.2"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:eudora:4.3"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:eudora_light:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:qualcomm:eudora_pro:1.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qualcomm:eudora_light:3.0</vuln:product>
      <vuln:product>cpe:/a:qualcomm:eudora:4.3</vuln:product>
      <vuln:product>cpe:/a:qualcomm:eudora_pro:1.00</vuln:product>
      <vuln:product>cpe:/a:qualcomm:eudora:4.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0427</vuln:cve-id>
    <vuln:published-datetime>2000-05-01T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.477-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:summary>Eudora 4.1 allows remote attackers to perform a denial of service by sending attachments with long file names.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0428">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:openssl:openssl"/>
        <cpe-lang:fact-ref name="cpe:/a:ssleay:ssleay"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ssleay:ssleay</vuln:product>
      <vuln:product>cpe:/a:openssl:openssl</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0428</vuln:cve-id>
    <vuln:published-datetime>1999-03-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3936" xml:lang="en">3936</vuln:reference>
    </vuln:references>
    <vuln:summary>OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0429">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:ibm:lotus_notes:4.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:ibm:lotus_notes:4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0429</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.617-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92249282302994&amp;w=2" xml:lang="en">19990326 Re: Lotus Notes security advisory</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92246997917866&amp;w=2" xml:lang="en">19990326 Lotus Notes Encryption Bug</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92241547418689&amp;w=2" xml:lang="en">19990324 Re: LNotes encryption</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92221437025743&amp;w=2" xml:lang="en">19990323</vuln:reference>
    </vuln:references>
    <vuln:summary>The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0430">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:cisco:catalyst_12xx_supervisor_software:4.29"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:catalyst_29xx_supervisor_software:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:catalyst_29xx_supervisor_software:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:catalyst_29xx_supervisor_software:2.1.501"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:catalyst_29xx_supervisor_software:2.1.502"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:catalyst_5xxx_supervisor_software:1.0"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:catalyst_5xxx_supervisor_software:2.1.5"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:catalyst_5xxx_supervisor_software:2.1.501"/>
        <cpe-lang:fact-ref name="cpe:/a:cisco:catalyst_5xxx_supervisor_software:2.1.502"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:cisco:catalyst_5xxx_supervisor_software:2.1.502</vuln:product>
      <vuln:product>cpe:/a:cisco:catalyst_5xxx_supervisor_software:2.1.501</vuln:product>
      <vuln:product>cpe:/a:cisco:catalyst_29xx_supervisor_software:2.1.5</vuln:product>
      <vuln:product>cpe:/a:cisco:catalyst_5xxx_supervisor_software:2.1.5</vuln:product>
      <vuln:product>cpe:/a:cisco:catalyst_29xx_supervisor_software:2.1.501</vuln:product>
      <vuln:product>cpe:/a:cisco:catalyst_12xx_supervisor_software:4.29</vuln:product>
      <vuln:product>cpe:/a:cisco:catalyst_5xxx_supervisor_software:1.0</vuln:product>
      <vuln:product>cpe:/a:cisco:catalyst_29xx_supervisor_software:2.1.502</vuln:product>
      <vuln:product>cpe:/a:cisco:catalyst_29xx_supervisor_software:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0430</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/1103" xml:lang="en">1103</vuln:reference>
    </vuln:references>
    <vuln:summary>Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0431">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.1.89"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.10"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.12"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.13"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.14"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15:pre16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.15_pre20"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.16"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.16:pre6"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.15:pre16</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.3</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.14</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.15_pre20</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.12</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.10</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.16:pre6</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.15</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.13</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.1.89</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0431</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0432">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0432</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.820-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-094" xml:lang="en">HPSBUX9903-094</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5547" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5547" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>ftp on HP-UX 11.00 allows local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0433">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:xfree86_project:x11r6:3.3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.2::i386"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.4"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.5"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:3.6"/>
        <cpe-lang:fact-ref name="cpe:/o:slackware:slackware_linux:4.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.2"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.0"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:6.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.5</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.3</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.1</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.6</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.2::i386</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.2</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.3</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:3.4</vuln:product>
      <vuln:product>cpe:/a:xfree86_project:x11r6:3.3.3</vuln:product>
      <vuln:product>cpe:/o:slackware:slackware_linux:4.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:6.0</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.1</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0433</vuln:cve-id>
    <vuln:published-datetime>1999-03-21T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0434">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux:1.2"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.0:r5"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.3"/>
        <cpe-lang:fact-ref name="cpe:/o:redhat:linux:5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.3</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:2.0</vuln:product>
      <vuln:product>cpe:/o:caldera:openlinux:1.2</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:2.0:r5</vuln:product>
      <vuln:product>cpe:/o:redhat:linux:5.1</vuln:product>
      <vuln:product>cpe:/o:suse:suse_linux:5.3</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:2.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0434</vuln:cve-id>
    <vuln:published-datetime>1999-03-30T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:31.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/359" xml:lang="en">359</vuln:reference>
    </vuln:references>
    <vuln:summary>XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0435">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.00"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.01"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.00</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.01</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0435</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0436">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:hp:desms"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.20"/>
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:11.00"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:hp-ux:11.00</vuln:product>
      <vuln:product>cpe:/a:hp:desms</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.20</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0436</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.117-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-095" xml:lang="en">HPSBUX9903-095</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5227" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5227" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0437">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:ramp_networks:webramp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:ramp_networks:webramp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0437</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.180-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0438">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:ramp_networks:webramp_200i:1.0"/>
        <cpe-lang:fact-ref name="cpe:/h:ramp_networks:webramp_m3:1.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:ramp_networks:webramp_m3:1.0</vuln:product>
      <vuln:product>cpe:/h:ramp_networks:webramp_200i:1.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0438</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.243-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0439">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:procmail:procmail:3.12"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:caldera:openlinux"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:caldera:openlinux</vuln:product>
      <vuln:product>cpe:/a:procmail:procmail:3.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0439</vuln:cve-id>
    <vuln:published-datetime>1999-04-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.320-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:summary>Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0440">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netscape:communicator:4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:4.01"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:4.02"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:4.03"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:4.04"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:4.05"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:4.06"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:4.07"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:4.08"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:4.5"/>
        <cpe-lang:fact-ref name="cpe:/a:netscape:navigator:4.61"/>
        <cpe-lang:fact-ref name="cpe:/a:sun:java"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:navigator:4.03</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator:4.05</vuln:product>
      <vuln:product>cpe:/a:sun:java</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator:4.0</vuln:product>
      <vuln:product>cpe:/a:netscape:communicator:4.5</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator:4.02</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator:4.08</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator:4.04</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator:4.61</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator:4.01</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator:4.06</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator:4.07</vuln:product>
      <vuln:product>cpe:/a:netscape:navigator:4.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0440</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://java.sun.com/pr/1999/03/pr990329-01.html" xml:lang="en">http://java.sun.com/pr/1999/03/pr990329-01.html</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/1939" xml:lang="en">1939</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92333596624452&amp;w=2" xml:lang="en">19990405 Security Hole in Java 2 (and JDK 1.1.x)</vuln:reference>
    </vuln:references>
    <vuln:summary>The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0441">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:qbik:wingate:3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:qbik:wingate:3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0441</vuln:cve-id>
    <vuln:published-datetime>1999-02-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.460-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/509" xml:lang="en">509</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>EEYE</vuln:source>
      <vuln:reference href="http://www.eeye.com/html/Research/Advisories/AD02221999.html" xml:lang="en">AD02221999</vuln:reference>
    </vuln:references>
    <vuln:summary>Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0442">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5.1::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.5::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:2.6::x86"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0"/>
        <cpe-lang:fact-ref name="cpe:/o:sun:solaris:7.0::x86"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sun:solaris:2.5::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:7.0</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.6::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1::x86</vuln:product>
      <vuln:product>cpe:/o:sun:solaris:2.5.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0442</vuln:cve-id>
    <vuln:published-datetime>1999-01-07T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.523-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/327" xml:lang="en">327</vuln:reference>
    </vuln:references>
    <vuln:summary>Solaris ff.core allows local users to modify files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0443">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:bmc:patrol_agent:3.2.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:bmc:patrol_agent:3.2.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0443</vuln:cve-id>
    <vuln:published-datetime>1999-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/archive/1/13204" xml:lang="en">19990409 Patrol security bugs</vuln:reference>
    </vuln:references>
    <vuln:summary>Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0444">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_95"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_98::gold"/>
        <cpe-lang:fact-ref name="cpe:/o:microsoft:windows_nt"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:microsoft:windows_95</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_98::gold</vuln:product>
      <vuln:product>cpe:/o:microsoft:windows_nt</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0444</vuln:cve-id>
    <vuln:published-datetime>1999-04-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.663-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0445">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29w"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xa3"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xb"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%281%29xe"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xc"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xd"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xf"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0%282%29xg"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0db"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0s"/>
        <cpe-lang:fact-ref name="cpe:/o:cisco:ios:12.0t"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29w</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xd</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0s</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29xa3</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xc</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29xe</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0t</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xg</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0db</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%282%29xf</vuln:product>
      <vuln:product>cpe:/o:cisco:ios:12.0%281%29xb</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0445</vuln:cve-id>
    <vuln:published-datetime>1999-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.757-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/1104" xml:lang="en">1104</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5574" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5574" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0446">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0446</vuln:cve-id>
    <vuln:published-datetime>1999-04-12T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/7051" xml:lang="en">7051</vuln:reference>
    </vuln:references>
    <vuln:summary>Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0447">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:mpe_ix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:hp:mpe_ix</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0447</vuln:cve-id>
    <vuln:published-datetime>1999-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.897-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_USER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMP9904-006" xml:lang="en">HPSBMP9904-006</vuln:reference>
    </vuln:references>
    <vuln:summary>Local users can gain privileges using the debug utility in the MPE/iX operating system.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0448">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0448</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:32.977-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0449">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0449</vuln:cve-id>
    <vuln:published-datetime>1999-01-26T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:33.040-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.8</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/193" xml:lang="en">193</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/4" xml:lang="en">4</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/3" xml:lang="en">3</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/2" xml:lang="en">2</vuln:reference>
    </vuln:references>
    <vuln:summary>The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0450">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:4.0"/>
        <cpe-lang:fact-ref name="cpe:/a:microsoft:internet_information_server:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:internet_information_server:3.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:2.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:4.0</vuln:product>
      <vuln:product>cpe:/a:microsoft:internet_information_server:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0450</vuln:cve-id>
    <vuln:published-datetime>1999-01-26T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2009-06-24T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/194" xml:lang="en">194</vuln:reference>
    </vuln:references>
    <vuln:summary>In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).</vuln:summary>
  </entry>
  <entry id="CVE-1999-0451">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0451</vuln:cve-id>
    <vuln:published-datetime>1999-01-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:17:18.560-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/343" xml:lang="en">343</vuln:reference>
    </vuln:references>
    <vuln:summary>Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0452">
    <vuln:cve-id>CVE-1999-0452</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>A service or application has a backdoor password that was placed there by the developer.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0453">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:cisco:router"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:cisco:router</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0453</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:17:18.810-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics>
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector>NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:cwe id="CWE-200"/>
    <vuln:summary>An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).</vuln:summary>
  </entry>
  <entry id="CVE-1999-0454">
    <vuln:cve-id>CVE-1999-0454</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0455">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:allaire:coldfusion_server:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:allaire:coldfusion_server:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0455</vuln:cve-id>
    <vuln:published-datetime>1999-12-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:36.197-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/115" xml:lang="en">115</vuln:reference>
    </vuln:references>
    <vuln:summary>The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0457">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:debian:debian_linux:2.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:debian:debian_linux:2.0</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:1.3</vuln:product>
      <vuln:product>cpe:/o:debian:debian_linux:1.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0457</vuln:cve-id>
    <vuln:published-datetime>1999-01-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:36.273-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/317" xml:lang="en">317</vuln:reference>
    </vuln:references>
    <vuln:summary>Linux ftpwatch program allows local users to gain root privileges.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0458">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:l0pht:l0phtcrack:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:l0pht:l0phtcrack:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0458</vuln:cve-id>
    <vuln:published-datetime>1999-01-06T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:36.337-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/915" xml:lang="en">915</vuln:reference>
    </vuln:references>
    <vuln:summary>L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0459">
    <vuln:cve-id>CVE-1999-0459</vuln:cve-id>
    <vuln:published-datetime>1999-02-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:36.397-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>4.6</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:summary>Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0460">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.0"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.1"/>
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.3.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:linux:linux_kernel:2.1</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.0</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.3.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0460</vuln:cve-id>
    <vuln:published-datetime>1999-02-19T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:17:19.560-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/312" xml:lang="en">312</vuln:reference>
    </vuln:references>
    <vuln:summary>Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0461">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sgi:irix"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:linux:linux_kernel:2.6.20.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sgi:irix</vuln:product>
      <vuln:product>cpe:/o:linux:linux_kernel:2.6.20.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0461</vuln:cve-id>
    <vuln:published-datetime>1999-01-28T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:36.540-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0462">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:suse:suse_linux:5.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:suse:suse_linux:5.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0462</vuln:cve-id>
    <vuln:published-datetime>1999-03-17T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:36.603-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/339" xml:lang="en">339</vuln:reference>
    </vuln:references>
    <vuln:summary>suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0463">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:l0pht:l0phtcrack:2.5"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:l0pht:l0phtcrack:2.5</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0463</vuln:cve-id>
    <vuln:published-datetime>1998-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:36.680-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>SGI</vuln:source>
      <vuln:reference href="ftp://patches.sgi.com/support/free/security/advisories/19981201-01-PX" xml:lang="en">19981201-01-PX</vuln:reference>
    </vuln:references>
    <vuln:summary>Remote attackers can perform a denial of service using IRIX fcagent.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0464">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:tripwire:tripwire:1.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:tripwire:tripwire:1.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0464</vuln:cve-id>
    <vuln:published-datetime>1999-01-04T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:17:20.123-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>CONFIRM</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91592136122066&amp;w=2" xml:lang="en">http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91592136122066&amp;w=2</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/6609" xml:lang="en">6609</vuln:reference>
    </vuln:references>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BUGTRAQ</vuln:source>
      <vuln:reference href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91553066310826&amp;w=2" xml:lang="en">19990104 Tripwire mess..</vuln:reference>
    </vuln:references>
    <vuln:summary>Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0465">
    <vuln:cve-id>CVE-1999-0465</vuln:cve-id>
    <vuln:published-datetime>1999-01-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2005-10-20T00:00:00.000-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>10.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0466">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.1"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.2"/>
        <cpe-lang:fact-ref name="cpe:/o:netbsd:netbsd:1.3.3"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.3</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.1</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3.2</vuln:product>
      <vuln:product>cpe:/o:netbsd:netbsd:1.3</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0466</vuln:cve-id>
    <vuln:published-datetime>1999-04-21T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:36.883-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/905" xml:lang="en">905</vuln:reference>
    </vuln:references>
    <vuln:summary>The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0467">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:webcom:cgi_guestbook"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:webcom:cgi_guestbook</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0467</vuln:cve-id>
    <vuln:published-datetime>1999-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:36.947-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the "template" parameter.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0468">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0468</vuln:cve-id>
    <vuln:published-datetime>1999-04-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.023-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.6</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>MS</vuln:source>
      <vuln:reference href="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp" xml:lang="en">MS99-012</vuln:reference>
    </vuln:references>
    <vuln:summary>Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0469">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:microsoft:ie:5.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:microsoft:ie:5.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0469</vuln:cve-id>
    <vuln:published-datetime>1999-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.087-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0470">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:novell:netware:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:novell:netware:4.0</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0470</vuln:cve-id>
    <vuln:published-datetime>1999-04-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.147-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/482" xml:lang="en">482</vuln:reference>
    </vuln:references>
    <vuln:summary>A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0471">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:winroute:winroute"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:winroute:winroute</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0471</vuln:cve-id>
    <vuln:published-datetime>1999-04-09T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.227-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the "cancel" button.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0472">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:snmp:snmp"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/h:network_appliance:netcache"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/h:network_appliance:netcache</vuln:product>
      <vuln:product>cpe:/a:snmp:snmp</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0472</vuln:cve-id>
    <vuln:published-datetime>1999-04-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.290-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0473">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:andrew_tridgell:rsync:2.3.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:andrew_tridgell:rsync:2.3.1</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0473</vuln:cve-id>
    <vuln:published-datetime>1999-04-07T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.353-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/145" xml:lang="en">145</vuln:reference>
    </vuln:references>
    <vuln:summary>The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0474">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:mirabilis:icq:99a_2.13build1700"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:mirabilis:icq:99a_2.13build1700</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0474</vuln:cve-id>
    <vuln:published-datetime>1999-04-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.430-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0475">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:procmail:procmail"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:procmail:procmail</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0475</vuln:cve-id>
    <vuln:published-datetime>1999-04-05T00:00:00.000-04:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.493-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>1.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>HIGH</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>NONE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0476">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:sco:openserver"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:sco:openserver</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0476</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.570-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.2</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>COMPLETE</cvss:confidentiality-impact>
        <cvss:integrity-impact>COMPLETE</cvss:integrity-impact>
        <cvss:availability-impact>COMPLETE</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_ADMIN_ACCESS</vuln:security-protection>
    <vuln:summary>A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0477">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:allaire:coldfusion_server:2.0"/>
        <cpe-lang:fact-ref name="cpe:/a:allaire:coldfusion_server:3.0"/>
        <cpe-lang:fact-ref name="cpe:/a:allaire:coldfusion_server:3.01"/>
        <cpe-lang:fact-ref name="cpe:/a:allaire:coldfusion_server:3.11"/>
        <cpe-lang:fact-ref name="cpe:/a:allaire:coldfusion_server:3.12"/>
        <cpe-lang:fact-ref name="cpe:/a:allaire:coldfusion_server:4.0"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:allaire:coldfusion_server:4.0</vuln:product>
      <vuln:product>cpe:/a:allaire:coldfusion_server:2.0</vuln:product>
      <vuln:product>cpe:/a:allaire:coldfusion_server:3.01</vuln:product>
      <vuln:product>cpe:/a:allaire:coldfusion_server:3.0</vuln:product>
      <vuln:product>cpe:/a:allaire:coldfusion_server:3.11</vuln:product>
      <vuln:product>cpe:/a:allaire:coldfusion_server:3.12</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0477</vuln:cve-id>
    <vuln:published-datetime>1999-12-25T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-05T16:17:21.920-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>7.5</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>PARTIAL</cvss:confidentiality-impact>
        <cvss:integrity-impact>PARTIAL</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:security-protection>ALLOWS_OTHER_ACCESS</vuln:security-protection>
    <vuln:references xml:lang="en" reference_type="VENDOR_ADVISORY">
      <vuln:source>BID</vuln:source>
      <vuln:reference href="http://www.securityfocus.com/bid/115" xml:lang="en">115</vuln:reference>
    </vuln:references>
    <vuln:summary>The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0478">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:sendmail:sendmail:8.9.2"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:sendmail:sendmail:8.9.2</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0478</vuln:cve-id>
    <vuln:published-datetime>1998-12-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.710-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9904-097" xml:lang="en">HPSBUX9904-097</vuln:reference>
    </vuln:references>
    <vuln:scanner>
      <vuln:definition name="oval:org.mitre.oval:def:5819" href="http://oval.mitre.org/repository/data/DownloadDefinition?id=oval:org.mitre.oval:def:5819" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
    </vuln:scanner>
    <vuln:summary>Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0479">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:netscape:enterprise_server:3.6"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:hp:hp-ux:10.24"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:netscape:enterprise_server:3.6</vuln:product>
      <vuln:product>cpe:/o:hp:hp-ux:10.24</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0479</vuln:cve-id>
    <vuln:published-datetime>1999-03-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.773-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>HP</vuln:source>
      <vuln:reference href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-092" xml:lang="en">HPSBUX9903-092</vuln:reference>
    </vuln:references>
    <vuln:summary>Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0480">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/a:midnight_commander:midnight_commander:4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/a:midnight_commander:midnight_commander:4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0480</vuln:cve-id>
    <vuln:published-datetime>1999-04-01T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.837-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>2.1</cvss:score>
        <cvss:access-vector>LOCAL</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:summary>Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0481">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd:2.4"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd:2.4</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0481</vuln:cve-id>
    <vuln:published-datetime>1999-03-22T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.913-04:00</vuln:last-modified-datetime>
    <vuln:cvss>
      <cvss:base_metrics upgraded-from-version="1.0">
        <cvss:score>5.0</cvss:score>
        <cvss:access-vector approximated="true">NETWORK</cvss:access-vector>
        <cvss:access-complexity>LOW</cvss:access-complexity>
        <cvss:authentication>NONE</cvss:authentication>
        <cvss:confidentiality-impact>NONE</cvss:confidentiality-impact>
        <cvss:integrity-impact>NONE</cvss:integrity-impact>
        <cvss:availability-impact>PARTIAL</cvss:availability-impact>
        <cvss:source>http://nvd.nist.gov</cvss:source>
        <cvss:generated-on-datetime>2004-01-01T00:00:00.000-05:00</cvss:generated-on-datetime>
      </cvss:base_metrics>
    </vuln:cvss>
    <vuln:references xml:lang="en" reference_type="UNKNOWN">
      <vuln:source>OSVDB</vuln:source>
      <vuln:reference href="http://www.osvdb.org/7556" xml:lang="en">7556</vuln:reference>
    </vuln:references>
    <vuln:summary>Denial of service in "poll" in OpenBSD.</vuln:summary>
  </entry>
  <entry id="CVE-1999-0482">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test negate="false" operator="OR">
        <cpe-lang:fact-ref name="cpe:/o:openbsd:openbsd"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-software-list>
      <vuln:product>cpe:/o:openbsd:openbsd</vuln:product>
    </vuln:vulnerable-software-list>
    <vuln:cve-id>CVE-1999-0482</vuln:cve-id>
    <vuln:published-datetime>1999-03-21T00:00:00.000-05:00</vuln:published-datetime>
    <vuln:last-modified-datetime>2008-09-09T08:34:37.977-04:00</vuln:last-modified-datetime>
    <vuln:c